Report #9843 check_circle

  • Creation Date: April 7, 2020, 3:16 p.m.
  • Last Update: April 7, 2020, 3:25 p.m.
  • File: corona4.exe
  • Results:
Binary
DLL
False cancel
Size
750.50KB
trid
39.9% Win32 Executable MS Visual C++
35.3% Win64 Executable
8.4% Win32 Dynamic Link Library
5.7% Win32 Executable
2.6% Win16/32 Executable Delphi generic
type
PE
wordsize
32
Subsystem
Windows CLI
Hashes
md5
d1cc9f881592af9b3fc4217e64ef2357
sha1
3548daa29e71b237b0c44ef195db13f635a8b56b
crc32
0xf250ad05
sha224
a45b77ee6471b2b2bae236a21526601226f20fefe97293064a31f24e
sha256
d6eadba77e75b9d48e23583381caba3919938fd08088c1e3f2f2d9cc81b056bd
sha384
b14b2d132c3faa72bedfee6dc535b00b4415d0f3c1b8aa6ddeac2aef16083cf8167db2995b44ac47bcf0d8f548b61c92
sha512
cd831e2923f8c523fd8139c14d77797d81a1b2bfe5c2ca94241d5dc3abd5715b49a401358e5ceb17a74749f81e8de3f3138a209f2300fd1831d95708eb6436e7
ssdeep
12288:enCNT1iukC433mySvdl4Wl/toB/3mezW8QESyBOEdZoBl8y9ZDnHgRqF1nwAqDyB:enqT1f4mycHl/t2/37W8QE77mBJTDnAi
Community
Google
False cancel
HashLib
False cancel
YARA
Matches
RIPEMD160_Constants, PureBasic_4x_Neil_Hodgson, DebuggerException__SetConsoleCtrl, PureBasic4xNeilHodgson, contentis_base64, PureBasic_4x_Neil_Hodgson_additional, IP, SHA1_Constants, IsConsole, CRC32_table, IsPacked, Microsoft_Visual_Basic_v50, domain, CRC32_poly_Constant, MD5_Constants, IsPE32, win_files_operation, Big_Numbers1, PureBasic

Suspicious
True check_circle

Strings
List
C.St
f9.tD
RkB1.iD
d.As
H.Fi
2.Vn
W.ki
E.Np'
ntdll.dll
IeN,N,c8
=Nf))S
Ha%/
&oNlc*A
name="Microsoft.Windows.Common-Controls"
%G]W?rh
{o%E#
Division by zero
nfDA
GM%ua
Debugger breakpoint reached
_wcsnicmp
_wcsicmp
Downloads\
4EB6ED9C60B10649AFEA107DA5EA1291
publicKeyToken="6595b64144ccf1df"
BiSSh
GetProcAddress
c9.bo?_
ExitProcess
Division by zero (floating-point)
GetForegroundWindow
SshD
TerminateProcess
CreateProcessW
ShellExecuteExW
RemoveDirectoryW
CreateFileW
DeleteFileW
GetModuleHandleW
HeapCreate
CreateDirectoryW
WriteFile
FreeLibrary
LoadLibraryExW
LoadLibraryW
TerminateThread
SetFilePointer
PeekNamedPipe
LoadResource
GetModuleFileNameW
Exception handler tried to continue after non-continuable exception
Invalid floating-point operation
Floating-point stack overflow or underflow
Denormal floating-point operand
Inexact floating-point result
inflate 1.2.8 Copyright 1995-2013 Mark Adler
l%/0RuF
%/[@
Sleep
i^dFh
WH_E
too many length or distance symbols
version="1.0.0.0"
version="6.0.0.0"
COMCTL32.DLL
['6,E
>E9#]@
Kao.1i3DZ
Wp>a;TPc;
1.2.8
ru&o
>kndA7G2V
+21#Ig%N
_/cGfesN9A
0):\/eyD~
D$TPQRU
Privileged instruction
3AR\i.?Sj
WINMM.DLL
g#.$aroH
type="win32"
'(UPNr53
'3CN;m6E
Y]R/|SeDO
HiAI(&?~
"NouM/"[
.m/jO.EFH
4*/D8nO
<dependentAssembly>
|B?bnFiy0
Va:8Tp
GVerTeE]l
6d^^e.(
DA=rpefx
fi4*/Or
w#DCerWQI
E"S*vi0
<assemblyIdentity
<assemblyIdentity
-LaG//h

Foremost
Matches
0.exe, 750 KB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: False cancel
Allowed
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

URLs
Allowed
hasURLs: False cancel
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

Files
Allowed: ntdll.dll, Shell32.DLL, Kernel32.DLL, GDI32.DLL, MSVCRT.dll, OLE32.DLL, COMCTL32.DLL, USER32.DLL, SHLWAPI.DLL, WINMM.DLL
hasFiles: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Binary
Sizes
RVA
RVA: 16
Suspicious: False cancel
Code
Size: 699904
Suspicious: False cancel
Image
Address: 4194304
Suspicious: False cancel
Stack
Stack: 4096
Suspicious: False cancel
Headers
Headers: 1024
Suspicious: False cancel
Suspicious: False cancel

Symbols
Number
Number: 0
Suspicious: True check_circle
Pointer
Pointer: 0
Suspicious: True check_circle
Directories
Number: 16
Suspicious: False cancel

Checksum
Value: 0
Suspicous: True check_circle

Sections
Allowed: .code, .text, .rdata, .data, .rsrc
Suspicious
hasAllowed: True check_circle
hasSections: True check_circle
hasSuspicious: False cancel

Versions
OS
Version: 4
Suspicious: False cancel
Image
Version: True check_circle
Suspicious: 4
Linker
Version: 2.50
Suspicious: False cancel
Subsystem
Version: 4.0
Suspicious: False cancel
Suspicious: False cancel

EntryPoint
Address: 4096
Suspicious: False cancel

Anomalies
Anomalies: The header checksum and the calculated checksum do not match.
hasAnomalies: True check_circle

Libraries
Allowed: ntdll.dll, shell32.dll, kernel32.dll, gdi32.dll, msvcrt.dll, ole32.dll, comctl32.dll, user32.dll, shlwapi.dll, winmm.dll
hasLibs: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Timestamp
Past: False cancel
Valid: True check_circle
Value: 2018-02-01 18:46:15
Future: False cancel

Compilation
Packed: False cancel
Missing: True check_circle
Packers
Compiled: False cancel
Compilers
MainPacker: PureBasic 4.x -> Neil Hodgson

Obfuscation
XOR: False cancel
Fuzzing: False cancel

PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
True check_circle
Tricks
pushret
.rsrc: 348
.rdata: 6

pushpopmath
.code: 1
.rsrc: 165
.text: 3
.rdata: 5

ss register
.data: 1
.rsrc: 10

garbagebytes
.rsrc: 139
.rdata: 3

hookdetection
.rsrc: 11

software breakpoint
.rsrc: 11

fakeconditionaljumps
.rsrc: 16

programcontrolflowchange
.rsrc: 125
.rdata: 3

cpuinstructionsresultscomparison
.rsrc: 1
.rdata: 4

AVclass
ursu
1
VirusTotal
md5
d1cc9f881592af9b3fc4217e64ef2357
sha1
3548daa29e71b237b0c44ef195db13f635a8b56b
SCANS (DETECTION RATE = 56.34%)
AVG
update: 20200407
version: 18.4.3895.0
detected: False cancel

CMC
update: 20190321
version: 1.1.0.977
detected: False cancel

MAX
result: malware (ai score=83)
update: 20200407
version: 2019.9.16.1
detected: True check_circle

APEX
result: Malicious
update: 20200407
version: 6.9
detected: True check_circle

Bkav
result: W32.AIDetectVM.malware2
update: 20200407
version: 1.3.0.9899
detected: True check_circle

K7GW
result: Riskware ( 0040eff71 )
update: 20200407
version: 11.102.33709
detected: True check_circle

ALYac
result: Gen:Variant.Ursu.199780
update: 20200407
version: 1.1.1.5
detected: True check_circle

Avast
update: 20200407
version: 18.4.3895.0
detected: False cancel

Avira
update: 20200407
version: 8.3.3.8
detected: False cancel

Baidu
update: 20190318
version: 1.0.0.2
detected: False cancel

Cyren
result: W32/Agentwdcr.ACEU-7177
update: 20200407
version: 6.2.2.2
detected: True check_circle

DrWeb
update: 20200407
version: 7.0.46.3050
detected: False cancel

GData
result: Gen:Variant.Ursu.199780
update: 20200407
version: A:25.25357B:26.18288
detected: True check_circle

Panda
result: Trj/Genetic.gen
update: 20200407
version: 4.6.4.2
detected: True check_circle

VBA32
result: Worm.VBS.Dinihou
update: 20200407
version: 4.3.0
detected: True check_circle

VIPRE
update: 20200407
version: 82812
detected: False cancel

Zoner
update: 20200407
version: 0.0.0.0
detected: False cancel

ClamAV
result: Win.Worm.Sagent-6972912-0
update: 20200407
version: 0.102.2.0
detected: True check_circle

Comodo
update: 20200407
version: 32296
detected: False cancel

F-Prot
result: W32/Agentwdcr.AY
update: 20200407
version: 4.7.1.166
detected: True check_circle

Ikarus
result: Backdoor.MSIL.Bladabindi
update: 20200407
version: 0.1.5.2
detected: True check_circle

McAfee
update: 20200407
version: 6.0.6.653
detected: False cancel

Rising
result: Malware.Heuristic!ET#100% (RDMK:cmRtazqPutHYxrgz1YsOD3N7kfK6)
update: 20200407
version: 25.0.0.24
detected: True check_circle

Sophos
result: Troj/VBDrop-CE
update: 20200407
version: 4.98.0
detected: True check_circle

Yandex
update: 20200407
version: 5.5.2.24
detected: False cancel

Zillya
result: Trojan.Agent.Win32.880519
update: 20200407
version: 2.0.0.4062
detected: True check_circle

Acronis
result: suspicious
update: 20200315
version: 1.1.1.73
detected: True check_circle

Alibaba
update: 20190527
version: 0.3.0.5
detected: False cancel

Arcabit
result: Trojan.Ursu.D30C64
update: 20200407
version: 1.0.0.870
detected: True check_circle

Cylance
result: Unsafe
update: 20200407
version: 2.3.1.101
detected: True check_circle

Endgame
result: malicious (high confidence)
update: 20200226
version: 3.0.17
detected: True check_circle

FireEye
result: Generic.mg.d1cc9f881592af9b
update: 20200316
version: 32.31.0.0
detected: True check_circle

TACHYON
update: 20200407
version: 2020-04-07.03
detected: False cancel

Tencent
result: Malware.Win32.Gencirc.10b3bb85
update: 20200407
version: 1.0.0.1
detected: True check_circle

ViRobot
update: 20200407
version: 2014.3.20.0
detected: False cancel

Webroot
update: 20200407
version: 1.0.0.403
detected: False cancel

eGambit
result: Unsafe.AI_Score_99%
update: 20200407
detected: True check_circle

Ad-Aware
result: Gen:Variant.Ursu.199780
update: 20200407
version: 3.0.5.370
detected: True check_circle

AegisLab
update: 20200407
version: 4.2
detected: False cancel

Emsisoft
result: Gen:Variant.Ursu.199780 (B)
update: 20200407
version: 2018.12.0.1641
detected: True check_circle

F-Secure
update: 20200407
version: 12.0.86.52
detected: False cancel

Fortinet
update: 20200407
version: 6.2.142.0
detected: False cancel

Invincea
result: heuristic
update: 20200407
version: 6.3.6.26157
detected: True check_circle

Jiangmin
result: TrojanDownloader.Script.gjh
update: 20200406
version: 16.0.100
detected: True check_circle

Kingsoft
update: 20200407
version: 2013.8.14.323
detected: False cancel

Paloalto
update: 20200407
version: 1.0
detected: False cancel

Symantec
result: ML.Attribute.HighConfidence
update: 20200407
version: 1.11.0.0
detected: True check_circle

Trapmine
result: malicious.high.ml.score
update: 20200123
version: 3.2.22.914
detected: True check_circle

AhnLab-V3
update: 20200407
version: 3.17.4.26996
detected: False cancel

Antiy-AVL
result: Worm/VBS.Agent
update: 20200407
version: 3.0.0.1
detected: True check_circle

Kaspersky
result: Trojan-Dropper.VBS.Agent.ns
update: 20200407
version: 15.0.1.13
detected: True check_circle

MaxSecure
update: 20200404
version: 1.0.0.1
detected: False cancel

Microsoft
result: Trojan:Win32/Wacatac.D!ml
update: 20200407
version: 1.1.16900.4
detected: True check_circle

Qihoo-360
update: 20200407
version: 1.0.0.1120
detected: False cancel

ZoneAlarm
result: Trojan-Dropper.VBS.Agent.ns
update: 20200407
version: 1.0
detected: True check_circle

ESET-NOD32
result: VBS/TrojanDropper.Agent.OEI
update: 20200407
version: 21126
detected: True check_circle

TrendMicro
update: 20200407
version: 11.0.0.1006
detected: False cancel

BitDefender
result: Gen:Variant.Ursu.199780
update: 20200407
version: 7.2
detected: True check_circle

CrowdStrike
result: win/malicious_confidence_80% (D)
update: 20190702
version: 1.0
detected: True check_circle

K7AntiVirus
result: Riskware ( 0040eff71 )
update: 20200407
version: 11.102.33708
detected: True check_circle

SentinelOne
update: 20200406
version: 2.1.0.89
detected: False cancel

Avast-Mobile
update: 20200407
version: 200407-00
detected: False cancel

Malwarebytes
update: 20200407
version: 3.6.4.335
detected: False cancel

TotalDefense
update: 20200407
version: 37.1.62.1
detected: False cancel

CAT-QuickHeal
update: 20200407
version: 14.00
detected: False cancel

NANO-Antivirus
result: Trojan.Win32.Ursu.exfdyc
update: 20200407
version: 1.0.134.25032
detected: True check_circle

BitDefenderTheta
result: Gen:NN.ZexaF.34106.UuW@aC1sQPg
update: 20200407
version: 7.2.37796.0
detected: True check_circle

MicroWorld-eScan
result: Gen:Variant.Ursu.199780
update: 20200407
version: 14.0.409.0
detected: True check_circle

SUPERAntiSpyware
update: 20200404
version: 5.6.0.1032
detected: False cancel

McAfee-GW-Edition
result: BehavesLike.Win32.Dropper.bc
update: 20200407
version: v2017.3010
detected: True check_circle

TrendMicro-HouseCall
update: 20200407
version: 10.0.0.1040
detected: False cancel

total
71
sha256
d6eadba77e75b9d48e23583381caba3919938fd08088c1e3f2f2d9cc81b056bd
scan_id
d6eadba77e75b9d48e23583381caba3919938fd08088c1e3f2f2d9cc81b056bd-1586277478
resource
d1cc9f881592af9b3fc4217e64ef2357
positives
40
scan_date
2020-04-07 16:37:58
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
7/4/2020 - 14:45:42.778Open1480C:\malware.exeC:\malware.exe
7/4/2020 - 14:45:42.778Unknown1480C:\malware.exeC:\malware.exe
7/4/2020 - 14:45:42.778Open1480C:\malware.exeC:\Windows\System32\cscript
7/4/2020 - 14:45:42.778Open1480C:\malware.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:42.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:42.778Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:42.778Open1480C:\malware.exeC:\
7/4/2020 - 14:45:42.778Unknown1480C:\malware.exeC:\
7/4/2020 - 14:45:42.778Open1480C:\malware.exeC:\Users
7/4/2020 - 14:45:42.778Unknown1480C:\malware.exeC:\Users
7/4/2020 - 14:45:42.778Open1480C:\malware.exeC:\Users\Behemot
7/4/2020 - 14:45:42.778Unknown1480C:\malware.exeC:\Users\Behemot
7/4/2020 - 14:45:42.778Open1480C:\malware.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:42.778Unknown1480C:\malware.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:42.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:42.778Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:42.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:42.778Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:42.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:42.793Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:42.793Open1480C:\malware.exeC:\Monitor\Files\DeletedFiles
7/4/2020 - 14:45:42.793Delete1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:42.793Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:42.793Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:42.793Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:42.793Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:42.793Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:42.793Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:42.793Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:42.793Open1480C:\malware.exeC:\Monitor\Files\DeletedFiles
7/4/2020 - 14:45:42.793Delete1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:42.793Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:42.793Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:42.793Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:42.793Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:42.793Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:42.793Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.tmp
7/4/2020 - 14:45:42.793Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.tmp
7/4/2020 - 14:45:42.793Open1480C:\malware.exeC:\Monitor\Files\DeletedFiles
7/4/2020 - 14:45:42.793Delete1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.tmp
7/4/2020 - 14:45:42.793Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.tmp
7/4/2020 - 14:45:42.793Open1480C:\malware.exeC:\Monitor
7/4/2020 - 14:45:42.793Unknown1480C:\malware.exeC:\Monitor
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:42.825Write1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:42.825Write1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:42.825Write1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:42.825Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Monitor
7/4/2020 - 14:45:42.825Unknown1480C:\malware.exeC:\Monitor
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Windows\System32\cscript
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Windows\SysWOW64\apphelp.dll
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Windows\SysWOW64\apphelp.dll
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Windows\AppPatch\AppPatch64\sysmain.sdb
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Windows\System32
7/4/2020 - 14:45:42.825Unknown1480C:\malware.exeC:\Windows\System32
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\
7/4/2020 - 14:45:42.825Unknown1480C:\malware.exeC:\
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Windows\System32
7/4/2020 - 14:45:42.825Unknown1480C:\malware.exeC:\Windows\System32
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:42.825Open1480C:\malware.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:42.920Open1488C:\Windows\System32\cscript.exeC:\Windows\Prefetch\CSCRIPT.EXE-D1EF4768.pf
7/4/2020 - 14:45:42.921Open1488C:\Windows\System32\cscript.exeC:\Monitor
7/4/2020 - 14:45:42.922Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:42.927Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:42.929Open1488C:\Windows\System32\cscript.exeC:\Windows\sysnative\VERSION.dll
7/4/2020 - 14:45:42.929Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\version.dll
7/4/2020 - 14:45:42.930Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\version.dll
7/4/2020 - 14:45:42.930Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\sechost.dll
7/4/2020 - 14:45:42.930Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\sechost.dll
7/4/2020 - 14:45:42.931Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\imm32.dll
7/4/2020 - 14:45:42.931Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\imm32.dll
7/4/2020 - 14:45:42.932Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\imm32.dll
7/4/2020 - 14:45:42.932Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\imm32.dll
7/4/2020 - 14:45:42.932Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\imm32.dll
7/4/2020 - 14:45:42.932Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\imm32.dll
7/4/2020 - 14:45:42.933Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:42.934Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:42.935Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:42.935Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:42.936Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rpcss.dll
7/4/2020 - 14:45:42.937Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rpcss.dll
7/4/2020 - 14:45:42.937Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rpcss.dll
7/4/2020 - 14:45:42.937Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rpcss.dll
7/4/2020 - 14:45:42.937Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\cryptbase.dll
7/4/2020 - 14:45:42.937Unknown1488C:\Windows\System32\cscript.exeC:\Windows\System32\cryptbase.dllcryptbase.dll
7/4/2020 - 14:45:42.937Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\cryptbase.dll
7/4/2020 - 14:45:42.938Unknown1488C:\Windows\System32\cscript.exeC:\Windows\System32\cryptbase.dllcryptbase.dll
7/4/2020 - 14:45:42.938Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\uxtheme.dll
7/4/2020 - 14:45:42.938Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\uxtheme.dll
7/4/2020 - 14:45:43.101Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.102Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.102Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.102Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.103Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.103Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.103Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.103Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.103Open1488C:\Windows\System32\cscript.exeC:\Windows\Globalization\Sorting\SortDefault.nls
7/4/2020 - 14:45:43.103Unknown1488C:\Windows\System32\cscript.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
7/4/2020 - 14:45:43.104Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.104Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.104Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.104Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.104Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.104Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.104Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.104Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.104Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.104Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.104Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.104Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.105Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.105Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.105Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.105Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.105Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.105Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\sxs.dll
7/4/2020 - 14:45:43.106Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\sxs.dll
7/4/2020 - 14:45:43.142Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\dwmapi.dll
7/4/2020 - 14:45:43.142Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\dwmapi.dll
7/4/2020 - 14:45:43.144Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\vbscript.dll
7/4/2020 - 14:45:43.144Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\vbscript.dll
7/4/2020 - 14:45:43.150Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.150Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe
7/4/2020 - 14:45:43.152Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.153Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.153Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.153Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.153Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.153Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.154Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.154Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.154Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.154Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:43.154Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:43.154Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:43.154Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:43.154Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:43.154Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:43.155Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:43.155Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:43.155Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:43.155Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:43.155Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:43.155Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:43.155Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:43.155Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:43.155Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:43.155Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:43.156Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:43.156Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:43.156Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:43.156Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:43.156Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:43.156Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:43.156Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:43.156Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:43.156Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:43.156Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:43.157Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:43.157Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:43.157Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:43.157Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:43.157Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:43.157Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:43.157Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:43.157Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:43.157Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:43.157Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:43.157Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:43.158Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:43.158Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:43.158Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:43.158Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:43.158Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:43.158Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:43.158Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:43.158Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:43.158Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot
7/4/2020 - 14:45:43.159Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot
7/4/2020 - 14:45:43.159Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot
7/4/2020 - 14:45:43.159Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot
7/4/2020 - 14:45:43.159Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot
7/4/2020 - 14:45:43.159Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot
7/4/2020 - 14:45:43.159Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot
7/4/2020 - 14:45:43.159Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot
7/4/2020 - 14:45:43.159Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot
7/4/2020 - 14:45:43.159Open1488C:\Windows\System32\cscript.exeC:\Users
7/4/2020 - 14:45:43.159Open1488C:\Windows\System32\cscript.exeC:\Users
7/4/2020 - 14:45:43.160Unknown1488C:\Windows\System32\cscript.exeC:\Users
7/4/2020 - 14:45:43.160Open1488C:\Windows\System32\cscript.exeC:\Users
7/4/2020 - 14:45:43.160Unknown1488C:\Windows\System32\cscript.exeC:\Users
7/4/2020 - 14:45:43.160Open1488C:\Windows\System32\cscript.exeC:\Users
7/4/2020 - 14:45:43.160Unknown1488C:\Windows\System32\cscript.exeC:\Users
7/4/2020 - 14:45:43.160Open1488C:\Windows\System32\cscript.exeC:\Users
7/4/2020 - 14:45:43.160Unknown1488C:\Windows\System32\cscript.exeC:\Users
7/4/2020 - 14:45:43.160Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.161Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.161Open1488C:\Windows\System32\cscript.exeC:\
7/4/2020 - 14:45:43.161Unknown1488C:\Windows\System32\cscript.exeC:\
7/4/2020 - 14:45:43.161Open1488C:\Windows\System32\cscript.exeC:\Users
7/4/2020 - 14:45:43.161Unknown1488C:\Windows\System32\cscript.exeC:\Users
7/4/2020 - 14:45:43.161Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot
7/4/2020 - 14:45:43.161Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot
7/4/2020 - 14:45:43.161Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:43.161Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:43.161Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:43.162Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:43.162Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:43.162Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:43.162Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:43.162Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:43.162Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:43.162Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:43.163Read1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.164Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\cryptsp.dll
7/4/2020 - 14:45:43.164Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\cryptsp.dll
7/4/2020 - 14:45:43.164Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:43.165Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:43.165Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:43.165Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:43.166Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:43.166Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:43.166Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:43.166Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:43.166Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:43.166Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:43.170Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:43.170Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:43.171Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\msisip.dll
7/4/2020 - 14:45:43.172Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\msisip.dll
7/4/2020 - 14:45:43.172Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.173Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.173Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.173Read1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.173Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.173Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshext.dll
7/4/2020 - 14:45:43.173Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshext.dll
7/4/2020 - 14:45:43.174Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe.Local
7/4/2020 - 14:45:43.174Open1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6
7/4/2020 - 14:45:43.174Unknown1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6
7/4/2020 - 14:45:43.174Open1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6
7/4/2020 - 14:45:43.175Open1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
7/4/2020 - 14:45:43.175Unknown1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
7/4/2020 - 14:45:43.175Open1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
7/4/2020 - 14:45:43.175Unknown1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
7/4/2020 - 14:45:43.222Read1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.223Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrobj.dll
7/4/2020 - 14:45:43.257Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrobj.dll
7/4/2020 - 14:45:43.561Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\mlang.dll
7/4/2020 - 14:45:43.562Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\mlang.dll
7/4/2020 - 14:45:43.667Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:43.897Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:43.930Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.102Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\mpr.dll
7/4/2020 - 14:45:44.102Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\mpr.dll
7/4/2020 - 14:45:44.103Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.103Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.338Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.338Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.338Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.339Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.339Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.339Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.339Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.339Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.339Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.339Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.339Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.339Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.340Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.340Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.340Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.340Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.340Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.340Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.340Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.340Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.340Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.340Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.340Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.341Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.341Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\scrrun.dll
7/4/2020 - 14:45:44.342Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.342Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.342Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.342Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.342Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.343Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.343Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.343Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.343Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.343Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.343Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.343Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.343Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.343Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.343Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.344Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.344Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.344Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.344Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.344Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.344Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.344Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.344Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.344Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.344Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.345Read1488C:\Windows\System32\cscript.exeC:\Windows\System32\wshom.ocx
7/4/2020 - 14:45:44.347Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\ieframe.dll
7/4/2020 - 14:45:44.347Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\ieframe.dll
7/4/2020 - 14:45:44.348Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
7/4/2020 - 14:45:44.349Unknown1488C:\Windows\System32\cscript.exeC:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dllapi-ms-win-downlevel-shell32-l1-1-0.dll
7/4/2020 - 14:45:44.349Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
7/4/2020 - 14:45:44.349Unknown1488C:\Windows\System32\cscript.exeC:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dllapi-ms-win-downlevel-shell32-l1-1-0.dll
7/4/2020 - 14:45:44.351Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\ieframe.dll
7/4/2020 - 14:45:44.351Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\cscript.exe.Local
7/4/2020 - 14:45:44.351Open1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
7/4/2020 - 14:45:44.352Unknown1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
7/4/2020 - 14:45:44.352Open1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
7/4/2020 - 14:45:44.352Open1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
7/4/2020 - 14:45:44.352Unknown1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
7/4/2020 - 14:45:44.352Open1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
7/4/2020 - 14:45:44.352Unknown1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
7/4/2020 - 14:45:44.353Open1488C:\Windows\System32\cscript.exeC:\Windows\WindowsShell.Manifest
7/4/2020 - 14:45:44.353Unknown1488C:\Windows\System32\cscript.exeC:\Windows\WindowsShell.ManifestWindowsShell.Manifest
7/4/2020 - 14:45:44.392Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
7/4/2020 - 14:45:44.392Unknown1488C:\Windows\System32\cscript.exeC:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dllapi-ms-win-downlevel-shlwapi-l2-1-0.dll
7/4/2020 - 14:45:44.392Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
7/4/2020 - 14:45:44.393Unknown1488C:\Windows\System32\cscript.exeC:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dllapi-ms-win-downlevel-shlwapi-l2-1-0.dll
7/4/2020 - 14:45:44.393Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\Google.url
7/4/2020 - 14:45:44.394Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\Google.url
7/4/2020 - 14:45:44.394Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\propsys.dll
7/4/2020 - 14:45:44.394Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\propsys.dll
7/4/2020 - 14:45:44.396Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\Google.url
7/4/2020 - 14:45:44.463Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\Google.url
7/4/2020 - 14:45:44.463Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\msxml3.dll
7/4/2020 - 14:45:44.464Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\msxml3.dll
7/4/2020 - 14:45:44.464Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\bcrypt.dll
7/4/2020 - 14:45:44.464Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\bcrypt.dll
7/4/2020 - 14:45:44.466Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\pt-BR\KernelBase.dll.mui
7/4/2020 - 14:45:44.466Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\msxml3r.dll
7/4/2020 - 14:45:44.467Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\msxml3r.dll
7/4/2020 - 14:45:44.513Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\RpcRtRemote.dll
7/4/2020 - 14:45:44.513Unknown1488C:\Windows\System32\cscript.exeC:\Windows\System32\RpcRtRemote.dllRpcRtRemote.dll
7/4/2020 - 14:45:44.513Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\RpcRtRemote.dll
7/4/2020 - 14:45:44.513Unknown1488C:\Windows\System32\cscript.exeC:\Windows\System32\RpcRtRemote.dllRpcRtRemote.dll
7/4/2020 - 14:45:44.760Open1488C:\Windows\System32\cscript.exeC:\Program Files\Common Files\System\ado\msado15.dll
7/4/2020 - 14:45:44.794Open1488C:\Windows\System32\cscript.exeC:\Program Files\Common Files\System\ado\msado15.dll
7/4/2020 - 14:45:44.961Open1488C:\Windows\System32\cscript.exeC:\Program Files\Common Files\System\ado\MSDART.DLL
7/4/2020 - 14:45:44.961Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\msdart.dll
7/4/2020 - 14:45:44.996Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\msdart.dll
7/4/2020 - 14:45:46.0Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.0Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.0Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.0Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.0Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.0Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.0Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.0Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.0Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.1Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.2Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.2Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.2Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.2Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.2Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.2Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.2Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.2Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.3Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.3Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.3Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.3Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.3Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.3Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.3Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.43Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.43Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.43Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.43Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.43Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.43Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.43Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.43Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.43Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.44Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.44Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.44Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.44Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.44Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.44Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.44Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.44Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.44Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.44Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.44Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.45Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.45Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.45Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.45Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.45Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.45Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.45Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.45Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.45Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.45Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.45Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.46Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.46Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.46Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.46Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.46Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.46Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.46Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.46Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.46Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.46Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.47Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.47Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.47Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.47Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.47Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.47Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.47Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.47Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.47Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.47Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.47Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.48Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.48Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.48Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.48Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.48Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.48Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.48Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.48Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.48Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.49Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.49Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.49Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.49Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.49Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.49Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.49Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.49Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.49Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.49Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.50Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.50Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.50Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.50Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.50Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.50Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.50Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.50Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.50Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.50Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.51Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.51Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.51Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.51Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.51Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.51Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.51Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.51Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.51Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.51Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.52Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.52Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.52Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.52Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.52Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.52Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.52Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.52Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.52Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.52Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.53Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.53Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.53Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.53Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.53Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.53Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.53Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.53Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.53Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.53Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.54Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.54Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.54Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.54Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.54Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.54Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.54Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.55Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.102Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.102Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.102Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.102Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.102Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.103Write1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.237Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.238Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\apphelp.dll
7/4/2020 - 14:45:46.238Open1488C:\Windows\System32\cscript.exeC:\Windows\System32\apphelp.dll
7/4/2020 - 14:45:46.239Open1488C:\Windows\System32\cscript.exeC:\Windows\AppPatch\sysmain.sdb
7/4/2020 - 14:45:46.239Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:46.239Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:46.239Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.239Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.239Open1488C:\Windows\System32\cscript.exeC:\
7/4/2020 - 14:45:46.239Unknown1488C:\Windows\System32\cscript.exeC:\
7/4/2020 - 14:45:46.240Open1488C:\Windows\System32\cscript.exeC:\Users
7/4/2020 - 14:45:46.240Unknown1488C:\Windows\System32\cscript.exeC:\Users
7/4/2020 - 14:45:46.240Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot
7/4/2020 - 14:45:46.240Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot
7/4/2020 - 14:45:46.240Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:46.240Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:46.240Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:46.240Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:46.240Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:46.241Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:46.241Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:46.241Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp
7/4/2020 - 14:45:46.241Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.241Read1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.243Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\ui\SwDRM.dll
7/4/2020 - 14:45:46.245Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.245Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.246Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.246Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.246Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.246Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.246Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\pt-BR\qeSw.exe.mui
7/4/2020 - 14:45:46.246Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\pt\qeSw.exe.mui
7/4/2020 - 14:45:46.246Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\en-US\qeSw.exe.mui
7/4/2020 - 14:45:46.246Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\en\qeSw.exe.mui
7/4/2020 - 14:45:46.246Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.246Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.247Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.247Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.247Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.247Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.247Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.247Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.247Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.247Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.247Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.247Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.248Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.248Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.248Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.248Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.248Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.248Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.248Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.248Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.248Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.248Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.249Open1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.249Unknown1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.249Read1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.249Read1488C:\Windows\System32\cscript.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.291Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\Prefetch\QESW.EXE-5AFC9D55.pf
7/4/2020 - 14:45:46.291Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows
7/4/2020 - 14:45:46.291Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\wow64.dll
7/4/2020 - 14:45:46.291Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\wow64.dll
7/4/2020 - 14:45:46.291Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\wow64win.dll
7/4/2020 - 14:45:46.291Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\wow64win.dll
7/4/2020 - 14:45:46.292Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\wow64cpu.dll
7/4/2020 - 14:45:46.292Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\wow64cpu.dll
7/4/2020 - 14:45:46.292Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\wow64log.dll
7/4/2020 - 14:45:46.293Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows
7/4/2020 - 14:45:46.293Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows
7/4/2020 - 14:45:46.294Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor
7/4/2020 - 14:45:46.296Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\sechost.dll
7/4/2020 - 14:45:46.296Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\sechost.dll
7/4/2020 - 14:45:46.298Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe.Local
7/4/2020 - 14:45:46.298Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
7/4/2020 - 14:45:46.299Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
7/4/2020 - 14:45:46.299Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
7/4/2020 - 14:45:46.299Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
7/4/2020 - 14:45:46.299Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
7/4/2020 - 14:45:46.305Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\imm32.dll
7/4/2020 - 14:45:46.305Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\imm32.dll
7/4/2020 - 14:45:46.306Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\imm32.dll
7/4/2020 - 14:45:46.306Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\imm32.dll
7/4/2020 - 14:45:46.307Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\imm32.dll
7/4/2020 - 14:45:46.307Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\imm32.dll
7/4/2020 - 14:45:46.310Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Temp\pt-BR\qeSw.exe.mui
7/4/2020 - 14:45:46.310Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Temp\pt\qeSw.exe.mui
7/4/2020 - 14:45:46.311Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Temp\en-US\qeSw.exe.mui
7/4/2020 - 14:45:46.311Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Temp\en\qeSw.exe.mui
7/4/2020 - 14:45:46.311Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.311Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Temp\qeSw.exe
7/4/2020 - 14:45:46.314Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\Fonts\OQFTnxGWSt
7/4/2020 - 14:45:46.314Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Temp\OQFTnxGWSt
7/4/2020 - 14:45:46.314Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\OQFTnxGWSt
7/4/2020 - 14:45:46.315Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\OQFTnxGWSt
7/4/2020 - 14:45:46.315Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\system\OQFTnxGWSt
7/4/2020 - 14:45:46.315Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\OQFTnxGWSt
7/4/2020 - 14:45:46.315Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\OQFTnxGWSt
7/4/2020 - 14:45:46.316Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\OQFTnxGWSt
7/4/2020 - 14:45:46.316Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\wbem\OQFTnxGWSt
7/4/2020 - 14:45:46.317Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\WindowsPowerShell\v1.0\OQFTnxGWSt
7/4/2020 - 14:45:46.371Unknown1488C:\Windows\System32\cscript.exeC:\Monitor
7/4/2020 - 14:45:46.371Unknown1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6
7/4/2020 - 14:45:46.371Unknown1488C:\Windows\System32\cscript.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
7/4/2020 - 14:45:46.371Unknown1488C:\Windows\System32\cscript.exeC:\Windows\System32\pt-BR\KernelBase.dll.muiKernelBase.dll.mui
7/4/2020 - 14:45:46.375Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:46.375Open1480C:\malware.exeC:\Monitor\Files\DeletedFiles
7/4/2020 - 14:45:46.375Delete1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:46.376Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:46.376Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp\DA.vbs
7/4/2020 - 14:45:46.376Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:46.376Open1480C:\malware.exeC:\Monitor\Files\DeletedFiles
7/4/2020 - 14:45:46.376Delete1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:46.376Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp\D9.tmp
7/4/2020 - 14:45:46.376Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:46.377Open1480C:\malware.exeC:\Monitor\Files\DeletedFiles
7/4/2020 - 14:45:46.377Delete1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:46.377Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\C8.tmp
7/4/2020 - 14:45:46.380Unknown1480C:\malware.exeC:\Windows
7/4/2020 - 14:45:46.380Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
7/4/2020 - 14:45:46.380Unknown1480C:\malware.exeC:\Monitor
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\f
7/4/2020 - 14:45:46.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\t
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Temp\mpr.dll
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\mpr.dll
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\mpr.dll
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Temp\netapi32.dll
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\netapi32.dll
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\netapi32.dll
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Temp\netutils.dll
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\netutils.dll
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\netutils.dll
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Temp\srvcli.dll
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\srvcli.dll
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\srvcli.dll
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Temp\wkscli.dll
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\wkscli.dll
7/4/2020 - 14:45:46.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\wkscli.dll
7/4/2020 - 14:45:46.709Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\config\SOFTWARE.LOG1
7/4/2020 - 14:45:46.756Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\config\SOFTWARE.LOG1
7/4/2020 - 14:45:46.803Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\config\SOFTWARE.LOG1
7/4/2020 - 14:45:46.803Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\config\SOFTWARE.LOG1
7/4/2020 - 14:45:46.803Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\config\SOFTWARE.LOG1
7/4/2020 - 14:45:46.850Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\config\SOFTWARE.LOG1
7/4/2020 - 14:45:46.897Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\config\SOFTWARE
7/4/2020 - 14:45:46.991Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\config\SOFTWARE
7/4/2020 - 14:45:46.991Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\config\SOFTWARE
7/4/2020 - 14:45:46.991Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\config\SOFTWARE
7/4/2020 - 14:45:46.991Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\config\SOFTWARE
7/4/2020 - 14:45:47.84Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\config\SOFTWARE
7/4/2020 - 14:45:47.272Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\ntuser.dat.LOG1
7/4/2020 - 14:45:47.319Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\ntuser.dat.LOG1
7/4/2020 - 14:45:47.319Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\ntuser.dat.LOG1
7/4/2020 - 14:45:47.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\ntuser.dat.LOG1
7/4/2020 - 14:45:47.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\ntuser.dat.LOG1
7/4/2020 - 14:45:47.413Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\ntuser.dat.LOG1
7/4/2020 - 14:45:47.413Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\ntuser.dat.LOG1
7/4/2020 - 14:45:47.413Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\ntuser.dat.LOG1
7/4/2020 - 14:45:47.459Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\NTUSER.DAT
7/4/2020 - 14:45:47.553Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\NTUSER.DAT
7/4/2020 - 14:45:47.553Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\NTUSER.DAT
7/4/2020 - 14:45:47.553Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\NTUSER.DAT
7/4/2020 - 14:45:47.553Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\NTUSER.DAT
7/4/2020 - 14:45:47.553Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\NTUSER.DAT
7/4/2020 - 14:45:47.553Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\NTUSER.DAT
7/4/2020 - 14:45:47.741Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\NTUSER.DAT
7/4/2020 - 14:45:47.928Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\rpcss.dll
7/4/2020 - 14:45:47.928Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\rpcss.dll
7/4/2020 - 14:45:47.928Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\vssadmin.exe
7/4/2020 - 14:45:48.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\taskschd.dll
7/4/2020 - 14:45:48.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\taskschd.dll
7/4/2020 - 14:45:48.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\apphelp.dll
7/4/2020 - 14:45:48.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\apphelp.dll
7/4/2020 - 14:45:48.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\AppPatch\AppPatch64\sysmain.sdb
7/4/2020 - 14:45:48.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32
7/4/2020 - 14:45:48.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32
7/4/2020 - 14:45:48.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32\vssadmin.exe
7/4/2020 - 14:45:48.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\
7/4/2020 - 14:45:48.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\
7/4/2020 - 14:45:48.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows
7/4/2020 - 14:45:48.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows
7/4/2020 - 14:45:48.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32
7/4/2020 - 14:45:48.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\System32
7/4/2020 - 14:45:48.209Open2196C:\Windows\System32\vssadmin.exeC:\Windows\Prefetch\VSSADMIN.EXE-9FF2C6A1.pf
7/4/2020 - 14:45:48.209Open2196C:\Windows\System32\vssadmin.exeC:\Monitor
7/4/2020 - 14:45:48.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Temp\XmlLite.dll
7/4/2020 - 14:45:48.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\xmllite.dll
7/4/2020 - 14:45:48.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Windows\SysWOW64\xmllite.dll
7/4/2020 - 14:45:48.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\
7/4/2020 - 14:45:48.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\
7/4/2020 - 14:45:48.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\$Recycle.Bin
7/4/2020 - 14:45:48.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\$Recycle.Bin
7/4/2020 - 14:45:48.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Arquivos de Programas
7/4/2020 - 14:45:48.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Arquivos de Programas
7/4/2020 - 14:45:48.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Documents and Settings
7/4/2020 - 14:45:48.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Documents and Settings
7/4/2020 - 14:45:48.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor
7/4/2020 - 14:45:48.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor
7/4/2020 - 14:45:48.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files
7/4/2020 - 14:45:48.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files
7/4/2020 - 14:45:48.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)
7/4/2020 - 14:45:48.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)
7/4/2020 - 14:45:48.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData
7/4/2020 - 14:45:48.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData
7/4/2020 - 14:45:48.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery
7/4/2020 - 14:45:48.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery
7/4/2020 - 14:45:48.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users
7/4/2020 - 14:45:48.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users
7/4/2020 - 14:45:48.694Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\sechost.dll
7/4/2020 - 14:45:48.694Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\sechost.dll
7/4/2020 - 14:45:48.694Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\atl.dll
7/4/2020 - 14:45:48.694Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\atl.dll
7/4/2020 - 14:45:48.694Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\vsstrace.dll
7/4/2020 - 14:45:48.694Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\vsstrace.dll
7/4/2020 - 14:45:48.694Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\vssapi.dll
7/4/2020 - 14:45:48.694Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\vssapi.dll
7/4/2020 - 14:45:48.694Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\imm32.dll
7/4/2020 - 14:45:48.694Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\imm32.dll
7/4/2020 - 14:45:48.694Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\imm32.dll
7/4/2020 - 14:45:48.694Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\imm32.dll
7/4/2020 - 14:45:48.694Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\imm32.dll
7/4/2020 - 14:45:48.709Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\imm32.dll
7/4/2020 - 14:45:48.709Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\pt-BR\vssadmin.exe.mui
7/4/2020 - 14:45:48.709Read2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\pt-BR\vssadmin.exe.muivssadmin.exe.mui
7/4/2020 - 14:45:48.709Read2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\pt-BR\vssadmin.exe.muivssadmin.exe.mui
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\$Recycle.Bin\S-1-5-21-2148495166-3420019059-1286093062-1001
7/4/2020 - 14:45:48.709Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rpcss.dll
7/4/2020 - 14:45:48.709Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rpcss.dll
7/4/2020 - 14:45:48.709Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rpcss.dll
7/4/2020 - 14:45:48.709Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rpcss.dll
7/4/2020 - 14:45:48.709Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\cryptbase.dll
7/4/2020 - 14:45:48.709Unknown2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\cryptbase.dllcryptbase.dll
7/4/2020 - 14:45:48.709Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\cryptbase.dll
7/4/2020 - 14:45:48.709Unknown2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\cryptbase.dllcryptbase.dll
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\$Recycle.Bin\S-1-5-21-2148495166-3420019059-1286093062-1001
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Malware
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Malware
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Arquivos Comuns
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Arquivos Comuns
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Uninstall Information
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Uninstall Information
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Mail
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Mail
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Mail
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Uninstall Information
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Uninstall Information
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Windows Mail
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Windows Mail
7/4/2020 - 14:45:48.709Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Windows Mail
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Application Data
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Application Data
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Dados de aplicativos
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Dados de aplicativos
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Desktop
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Desktop
7/4/2020 - 14:45:48.709Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documentos
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documentos
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documents
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documents
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favorites
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favorites
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favoritos
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favoritos
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Menu Iniciar
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Menu Iniciar
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft
7/4/2020 - 14:45:48.725Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Modelos
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Modelos
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache
7/4/2020 - 14:45:48.725Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Start Menu
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Start Menu
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Templates
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Templates
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
7/4/2020 - 14:45:48.725Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\All Users
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData
7/4/2020 - 14:45:48.725Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot
7/4/2020 - 14:45:48.725Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default
7/4/2020 - 14:45:48.725Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default User
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default User
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public
7/4/2020 - 14:45:48.725Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Todos os Usurios
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData
7/4/2020 - 14:45:48.725Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Usurio Padro
7/4/2020 - 14:45:48.725Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Usurio Padro
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\DeletedFiles
7/4/2020 - 14:45:48.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\DeletedFiles
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs
7/4/2020 - 14:45:48.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
7/4/2020 - 14:45:48.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
7/4/2020 - 14:45:48.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:48.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
7/4/2020 - 14:45:48.788Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:48.788Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:48.788Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:48.788Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:48.788Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:48.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:48.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:48.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:48.788Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:48.788Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:48.788Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:48.788Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:48.788Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\Services
7/4/2020 - 14:45:48.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\Services
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\Sistema
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\Sistema
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\SpeechEngines
7/4/2020 - 14:45:48.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\SpeechEngines
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft
7/4/2020 - 14:45:48.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft
7/4/2020 - 14:45:48.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\pt-BR
7/4/2020 - 14:45:48.788Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\pt-BR
7/4/2020 - 14:45:48.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates
7/4/2020 - 14:45:48.803Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Mail
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Mail\pt-BR
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Mail\pt-BR
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\Services
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\Services
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Windows Mail
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Windows Mail\pt-BR
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Windows Mail\pt-BR
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DeviceSync
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030
7/4/2020 - 14:45:48.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Application Data
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Application Data
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Application Data
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Application Data
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Dados de aplicativos
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Dados de aplicativos
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Dados de aplicativos
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Dados de aplicativos
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Desktop
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Desktop
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Desktop
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Desktop
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documentos
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documentos
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documentos
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documentos
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documents
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documents
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documents
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documents
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favorites
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favorites
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favorites
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favorites
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favoritos
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favoritos
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favoritos
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favoritos
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Menu Iniciar
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Menu Iniciar
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Menu Iniciar
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Menu Iniciar
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Modelos
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Modelos
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Modelos
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Modelos
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache
7/4/2020 - 14:45:48.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Start Menu
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Start Menu
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Start Menu
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Start Menu
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Templates
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Templates
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Templates
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Templates
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Ambiente de impresso
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Ambiente de impresso
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Ambiente de rede
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Ambiente de rede
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:48.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Configuraes locais
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Configuraes locais
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts
7/4/2020 - 14:45:48.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Cookies
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Cookies
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Dados de aplicativos
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Dados de aplicativos
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Desktop
7/4/2020 - 14:45:48.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Desktop
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Documents
7/4/2020 - 14:45:48.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Documents
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads
7/4/2020 - 14:45:48.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites
7/4/2020 - 14:45:48.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites
7/4/2020 - 14:45:48.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Links
7/4/2020 - 14:45:48.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Links
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Menu Iniciar
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Menu Iniciar
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Meus documentos
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Meus documentos
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Modelos
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Modelos
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Music
7/4/2020 - 14:45:48.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Music
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Pictures
7/4/2020 - 14:45:48.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Pictures
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Recent
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Recent
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Saved Games
7/4/2020 - 14:45:48.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Saved Games
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches
7/4/2020 - 14:45:48.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\SendTo
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\SendTo
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Videos
7/4/2020 - 14:45:48.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Videos
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Ambiente de impresso
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Ambiente de impresso
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Ambiente de rede
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Ambiente de rede
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData
7/4/2020 - 14:45:48.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Application Data
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Application Data
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Configuraes locais
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Configuraes locais
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Cookies
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Cookies
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Dados de aplicativos
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Dados de aplicativos
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Desktop
7/4/2020 - 14:45:48.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Desktop
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:48.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:48.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Downloads
7/4/2020 - 14:45:48.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Downloads
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Favorites
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Desktop
7/4/2020 - 14:45:48.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Desktop
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Documents
7/4/2020 - 14:45:48.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Documents
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Downloads
7/4/2020 - 14:45:48.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Downloads
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Favorites
7/4/2020 - 14:45:48.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Favorites
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries
7/4/2020 - 14:45:48.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music
7/4/2020 - 14:45:48.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures
7/4/2020 - 14:45:48.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV
7/4/2020 - 14:45:48.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos
7/4/2020 - 14:45:48.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Application Data
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Application Data
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Application Data
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Application Data
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Dados de aplicativos
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Dados de aplicativos
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Dados de aplicativos
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Dados de aplicativos
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Desktop
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Desktop
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Desktop
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Desktop
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documentos
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documentos
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documentos
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documentos
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documents
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documents
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documents
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Documents
7/4/2020 - 14:45:48.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favorites
7/4/2020 - 14:45:48.881Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favorites
7/4/2020 - 14:45:48.881Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favorites
7/4/2020 - 14:45:48.881Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favorites
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favoritos
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favoritos
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favoritos
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Favoritos
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Menu Iniciar
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Menu Iniciar
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Menu Iniciar
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Menu Iniciar
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Modelos
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Modelos
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Modelos
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Modelos
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache
7/4/2020 - 14:45:48.897Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Start Menu
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Start Menu
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Start Menu
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Start Menu
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Templates
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Templates
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Templates
7/4/2020 - 14:45:48.897Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Templates
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\File.log
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\File.log
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\File.log
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\File.log
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\File.log
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\File.log
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\File.log
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\File.log
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\File.log
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Process.log
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Process.log
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Process.log
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Process.log
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Process.log
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Process.log
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Process.log
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Process.log
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Registry.log
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Registry.log
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Registry.log
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Registry.log
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Registry.log
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Registry.log
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Registry.log
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\Files\Logs\Registry.log
7/4/2020 - 14:45:48.959Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:48.959Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:48.959Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\Services\verisign.bmp
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\SpeechEngines\Microsoft
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\SpeechEngines\Microsoft
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework
7/4/2020 - 14:45:48.959Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:48.959Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:48.959Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\pt-BR
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\Services\verisign.bmp
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device
7/4/2020 - 14:45:48.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task
7/4/2020 - 14:45:48.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DeviceSync
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:48.975Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:48.975Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:48.975Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:48.975Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:48.975Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:48.975Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:48.975Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:48.975Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:48.975Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:48.975Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030
7/4/2020 - 14:45:48.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:48.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\LocalLow
7/4/2020 - 14:45:48.991Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\LocalLow
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Roaming
7/4/2020 - 14:45:48.991Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Roaming
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contact
7/4/2020 - 14:45:48.991Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contact
7/4/2020 - 14:45:48.991Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/4/2020 - 14:45:48.991Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contact
7/4/2020 - 14:45:48.991Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/4/2020 - 14:45:48.991Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/4/2020 - 14:45:48.991Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/4/2020 - 14:45:48.991Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/4/2020 - 14:45:48.991Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/4/2020 - 14:45:48.991Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Documents\Meus vdeos
7/4/2020 - 14:45:48.991Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Documents\Meus vdeos
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Documents\Minhas imagens
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Documents\Minhas imagens
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Documents\Minhas msicas
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Documents\Minhas msicas
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor
7/4/2020 - 14:45:48.991Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:48.991Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:48.991Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:48.991Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:48.991Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:48.991Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:48.991Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:48.991Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:48.991Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links
7/4/2020 - 14:45:48.991Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil
7/4/2020 - 14:45:48.991Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-ms
7/4/2020 - 14:45:48.991Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/4/2020 - 14:45:48.991Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-ms
7/4/2020 - 14:45:48.991Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-ms
7/4/2020 - 14:45:49.6Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/4/2020 - 14:45:49.6Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/4/2020 - 14:45:49.6Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/4/2020 - 14:45:49.6Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/4/2020 - 14:45:49.6Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/4/2020 - 14:45:49.6Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Roaming
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Roaming
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents\Meus vdeos
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents\Meus vdeos
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents\Minhas imagens
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents\Minhas imagens
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents\Minhas msicas
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents\Minhas msicas
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents\My Music
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents\My Music
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents\My Pictures
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents\My Pictures
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents\My Videos
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents\My Videos
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Documents
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Videos
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Videos
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Favorites
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Documents\Meus vdeos
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Documents\Meus vdeos
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Documents\Minhas imagens
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Documents\Minhas imagens
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Documents\Minhas msicas
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Documents\Minhas msicas
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Documents\My Music
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Documents\My Music
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Documents\My Pictures
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Documents\My Pictures
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Documents\My Videos
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Documents\My Videos
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-ms
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/4/2020 - 14:45:49.6Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-ms
7/4/2020 - 14:45:49.6Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/4/2020 - 14:45:49.22Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-ms
7/4/2020 - 14:45:49.22Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/4/2020 - 14:45:49.22Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/4/2020 - 14:45:49.22Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/4/2020 - 14:45:49.22Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/4/2020 - 14:45:49.22Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music
7/4/2020 - 14:45:49.22Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures
7/4/2020 - 14:45:49.22Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media
7/4/2020 - 14:45:49.22Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media
7/4/2020 - 14:45:49.22Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos
7/4/2020 - 14:45:49.22Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}
7/4/2020 - 14:45:49.22Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030
7/4/2020 - 14:45:49.22Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/4/2020 - 14:45:49.22Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030
7/4/2020 - 14:45:49.22Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/4/2020 - 14:45:49.22Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030
7/4/2020 - 14:45:49.22Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030
7/4/2020 - 14:45:49.22Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}
7/4/2020 - 14:45:49.22Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030
7/4/2020 - 14:45:49.22Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030
7/4/2020 - 14:45:49.22Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries
7/4/2020 - 14:45:49.22Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
7/4/2020 - 14:45:49.38Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries
7/4/2020 - 14:45:49.38Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\RecordedTV.library-ms.cb5649
7/4/2020 - 14:45:49.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\CB5649-Readme.txt
7/4/2020 - 14:45:49.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\CB5649-Readme.txt
7/4/2020 - 14:45:49.38Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.38Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Libraries\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\cryptsp.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\cryptsp.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\rsaenh.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\Globalization\Sorting\SortDefault.nls
7/4/2020 - 14:45:49.116Unknown2196C:\Windows\System32\vssadmin.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\RpcRtRemote.dll
7/4/2020 - 14:45:49.116Unknown2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\RpcRtRemote.dllRpcRtRemote.dll
7/4/2020 - 14:45:49.116Open2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\RpcRtRemote.dll
7/4/2020 - 14:45:49.116Unknown2196C:\Windows\System32\vssadmin.exeC:\Windows\System32\RpcRtRemote.dllRpcRtRemote.dll
7/4/2020 - 14:45:49.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/4/2020 - 14:45:49.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:49.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/4/2020 - 14:45:49.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat.cb5649
7/4/2020 - 14:45:49.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\Services\verisign.bmp
7/4/2020 - 14:45:49.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\Services\verisign.bmp
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\Services\verisign.bmp
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\SpeechEngines\Microsoft\TTS20
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\SpeechEngines\Microsoft\TTS20
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.5
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.5
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5
7/4/2020 - 14:45:49.131Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf.cb5649
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\blank.jtp
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\Services\verisign.bmp
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\Services\verisign.bmp
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\Services\verisign.bmp
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.5
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.5
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5
7/4/2020 - 14:45:49.131Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS\MachineKeys
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS\MachineKeys
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628cea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628cea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628cea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.131Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628cea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.131Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628cea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.147Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628cea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.147Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628cea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.147Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628cea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
7/4/2020 - 14:45:49.147Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628cea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
7/4/2020 - 14:45:49.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
7/4/2020 - 14:45:49.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}
7/4/2020 - 14:45:49.147Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}
7/4/2020 - 14:45:49.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}
7/4/2020 - 14:45:49.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}
7/4/2020 - 14:45:49.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IdentityCRL
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IdentityCRL
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Vault
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Vault
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT
7/4/2020 - 14:45:48.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft
7/4/2020 - 14:45:49.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance
7/4/2020 - 14:45:49.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance
7/4/2020 - 14:45:49.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto
7/4/2020 - 14:45:49.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto
7/4/2020 - 14:45:49.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto
7/4/2020 - 14:45:49.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage
7/4/2020 - 14:45:49.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DeviceSync
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DeviceSync
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DeviceSync
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IdentityCRL
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IdentityCRL
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IdentityCRL
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Vault
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Vault
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Vault
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages\vcRuntimeAdditional_x86
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages\vcRuntimeAdditional_x86
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages\vcRuntimeMinimum_x86
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages\vcRuntimeMinimum_x86
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages\vcRuntimeMinimum_amd64
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages\vcRuntimeMinimum_amd64
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages
7/4/2020 - 14:45:49.163Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.163Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.163Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:49.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:49.178Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:49.178Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:49.178Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:49.178Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:49.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:49.178Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:49.178Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:49.178Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:49.178Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:49.178Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:49.178Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:49.178Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:49.178Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:49.178Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:49.178Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages
7/4/2020 - 14:45:49.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages
7/4/2020 - 14:45:49.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages
7/4/2020 - 14:45:49.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Dados de aplicativos
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Dados de aplicativos
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Histrico
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\Histrico
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\VirtualStore
7/4/2020 - 14:45:49.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Local\VirtualStore
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Roaming\Adobe
7/4/2020 - 14:45:49.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Roaming\Adobe
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Roaming\Identities
7/4/2020 - 14:45:49.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Roaming\Identities
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Roaming\Media Center Programs
7/4/2020 - 14:45:49.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Roaming\Media Center Programs
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor
7/4/2020 - 14:45:49.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.url
7/4/2020 - 14:45:49.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.url
7/4/2020 - 14:45:49.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/4/2020 - 14:45:49.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/4/2020 - 14:45:49.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.url
7/4/2020 - 14:45:49.194Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/4/2020 - 14:45:49.194Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/4/2020 - 14:45:49.194Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.url
7/4/2020 - 14:45:49.194Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/4/2020 - 14:45:49.194Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.url
7/4/2020 - 14:45:49.194Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/4/2020 - 14:45:49.194Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/4/2020 - 14:45:49.194Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.url
7/4/2020 - 14:45:49.194Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/4/2020 - 14:45:49.194Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/4/2020 - 14:45:49.194Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/4/2020 - 14:45:49.194Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.url
7/4/2020 - 14:45:49.194Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/4/2020 - 14:45:49.194Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.url
7/4/2020 - 14:45:49.194Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/4/2020 - 14:45:49.194Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/4/2020 - 14:45:49.194Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.url
7/4/2020 - 14:45:49.194Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/4/2020 - 14:45:49.194Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/4/2020 - 14:45:49.194Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.url
7/4/2020 - 14:45:49.194Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/4/2020 - 14:45:49.194Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.url
7/4/2020 - 14:45:49.194Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/4/2020 - 14:45:49.194Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/4/2020 - 14:45:49.194Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.url
7/4/2020 - 14:45:49.194Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/4/2020 - 14:45:49.194Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/4/2020 - 14:45:49.194Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.url
7/4/2020 - 14:45:49.194Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/4/2020 - 14:45:49.194Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.url
7/4/2020 - 14:45:49.194Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/4/2020 - 14:45:49.194Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:49.194Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:49.194Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local\Application Data
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local\Application Data
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local\Dados de aplicativos
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local\Dados de aplicativos
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local\History
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local\History
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local\Histrico
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local\Histrico
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Local
7/4/2020 - 14:45:49.209Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/4/2020 - 14:45:49.209Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/4/2020 - 14:45:49.209Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Roaming\Media Center Programs
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\AppData\Roaming\Media Center Programs
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Links
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Links
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Local Settings
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Local Settings
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Menu Iniciar
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Menu Iniciar
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Meus documentos
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Meus documentos
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Modelos
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Modelos
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Music
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Music
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\My Documents
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\My Documents
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\NetHood
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\NetHood
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Pictures
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Pictures
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\PrintHood
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\PrintHood
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Recent
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Recent
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Saved Games
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Saved Games
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\SendTo
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\SendTo
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Start Menu
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Start Menu
7/4/2020 - 14:45:48.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Templates
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Default\Templates
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:49.209Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:49.209Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:49.209Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:49.209Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:49.209Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:49.209Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:49.209Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:49.209Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:49.225Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:49.225Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:49.225Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:49.225Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:49.225Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:49.225Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:49.225Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:49.225Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:49.225Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:49.225Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3
7/4/2020 - 14:45:49.225Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:49.225Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3
7/4/2020 - 14:45:49.225Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:49.225Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3
7/4/2020 - 14:45:49.225Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:49.225Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:49.225Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:49.225Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:49.225Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:49.225Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
7/4/2020 - 14:45:49.225Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:49.225Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
7/4/2020 - 14:45:49.225Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:49.225Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
7/4/2020 - 14:45:49.225Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:49.225Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:49.225Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:49.225Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:49.225Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:49.225Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/4/2020 - 14:45:49.225Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:49.241Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages
7/4/2020 - 14:45:49.241Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages
7/4/2020 - 14:45:49.241Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages
7/4/2020 - 14:45:49.241Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages
7/4/2020 - 14:45:49.241Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages
7/4/2020 - 14:45:49.241Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages
7/4/2020 - 14:45:49.241Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages
7/4/2020 - 14:45:49.241Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages
7/4/2020 - 14:45:49.241Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages
7/4/2020 - 14:45:49.241Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.241Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.241Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages
7/4/2020 - 14:45:49.241Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages
7/4/2020 - 14:45:49.241Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages
7/4/2020 - 14:45:49.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\CB5649-Readme.txt
7/4/2020 - 14:45:49.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\CB5649-Readme.txt
7/4/2020 - 14:45:49.319Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\SpeechEngines\Microsoft\TTS20\en-US
7/4/2020 - 14:45:49.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\SpeechEngines\Microsoft\TTS20\en-US
7/4/2020 - 14:45:49.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets
7/4/2020 - 14:45:49.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.Targets
7/4/2020 - 14:45:49.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0
7/4/2020 - 14:45:49.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\pt-BR
7/4/2020 - 14:45:49.319Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\pt-BR
7/4/2020 - 14:45:49.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList
7/4/2020 - 14:45:49.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList
7/4/2020 - 14:45:49.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml
7/4/2020 - 14:45:49.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml
7/4/2020 - 14:45:49.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml
7/4/2020 - 14:45:49.319Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.319Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.319Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.319Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.319Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.334Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\To_Do_List.jtp
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\blank.jtp
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\blank.jtp
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\blank.jtp
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.Targets
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\pt-BR
7/4/2020 - 14:45:49.334Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\pt-BR
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\SubsetList
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\SubsetList
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml
7/4/2020 - 14:45:49.334Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.334Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.334Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.334Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.334Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.334Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR
7/4/2020 - 14:45:49.334Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US
7/4/2020 - 14:45:49.334Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM\Server
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM\Server
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome\logs
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome\logs
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.366Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.366Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.366Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\imcrcache.xml
7/4/2020 - 14:45:49.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\imcrcache.xmlimcrcache.xml
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\imcrcache.xml
7/4/2020 - 14:45:49.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\imcrcache.xmlimcrcache.xml
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.366Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.366Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.366Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.366Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.366Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.366Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.366Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.366Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Connections
7/4/2020 - 14:45:49.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Connections
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader
7/4/2020 - 14:45:49.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\Outbound
7/4/2020 - 14:45:49.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\Outbound
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData
7/4/2020 - 14:45:49.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData
7/4/2020 - 14:45:49.366Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\Temp
7/4/2020 - 14:45:49.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\Temp
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data
7/4/2020 - 14:45:49.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.dat
7/4/2020 - 14:45:49.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.datAdministrator.dat
7/4/2020 - 14:45:49.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.dat
7/4/2020 - 14:45:49.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.datAdministrator.dat
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.datAdministrator.dat
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.dat
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures
7/4/2020 - 14:45:49.381Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\AIT
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\AIT
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\GameExplorer
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\GameExplorer
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones
7/4/2020 - 14:45:49.381Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Templates
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Templates
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc\Profiles
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc\Profiles
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DeviceSync
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DeviceSync
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DeviceSync
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome
7/4/2020 - 14:45:49.381Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IdentityCRL
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IdentityCRL
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IdentityCRL
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Vault
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Vault
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Vault
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM\Server
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM\Server
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM\Server
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome\logs
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome\logs
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome\logs
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\imcrcache.xml
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\imcrcache.xml
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Connections
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Connections
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Connections
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\Outbound
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\Outbound
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\Outbound
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData
7/4/2020 - 14:45:49.397Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData
7/4/2020 - 14:45:49.397Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\AIT
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\AIT
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\AIT
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\GameExplorer
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\GameExplorer
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\GameExplorer
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Templates
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Templates
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Templates
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc\Profiles
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc\Profiles
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc\Profiles
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages\vcRuntimeAdditional_x86
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages\vcRuntimeAdditional_x86
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages\vcRuntimeAdditional_x86
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages\vcRuntimeMinimum_x86
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages\vcRuntimeMinimum_x86
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages\vcRuntimeMinimum_x86
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages\vcRuntimeMinimum_amd64
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages\vcRuntimeMinimum_amd64
7/4/2020 - 14:45:49.413Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages\vcRuntimeMinimum_amd64
7/4/2020 - 14:45:49.428Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Roaming\Adobe\Flash Player
7/4/2020 - 14:45:49.428Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Roaming\Adobe\Flash Player
7/4/2020 - 14:45:49.428Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Roaming\Identities\{5F13A065-9132-4C6F-A394-1C4D0DE64D1F}
7/4/2020 - 14:45:49.428Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Roaming\Identities\{5F13A065-9132-4C6F-A394-1C4D0DE64D1F}
7/4/2020 - 14:45:49.428Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files
7/4/2020 - 14:45:49.428Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files
7/4/2020 - 14:45:49.428Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware
7/4/2020 - 14:45:49.428Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware
7/4/2020 - 14:45:49.428Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/4/2020 - 14:45:49.428Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/4/2020 - 14:45:49.428Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/4/2020 - 14:45:49.428Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/4/2020 - 14:45:49.428Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/4/2020 - 14:45:49.428Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/4/2020 - 14:45:49.428Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/4/2020 - 14:45:49.428Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:49.428Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:49.428Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:49.428Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:49.428Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:49.428Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches
7/4/2020 - 14:45:49.428Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/4/2020 - 14:45:49.428Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/4/2020 - 14:45:49.428Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/4/2020 - 14:45:49.428Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/4/2020 - 14:45:49.428Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/4/2020 - 14:45:49.428Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/4/2020 - 14:45:49.428Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/4/2020 - 14:45:49.428Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/4/2020 - 14:45:49.428Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/4/2020 - 14:45:49.428Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/4/2020 - 14:45:49.428Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/4/2020 - 14:45:49.428Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/4/2020 - 14:45:49.428Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/4/2020 - 14:45:49.428Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/4/2020 - 14:45:49.428Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/4/2020 - 14:45:49.428Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/4/2020 - 14:45:49.428Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/4/2020 - 14:45:49.428Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/4/2020 - 14:45:49.428Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/4/2020 - 14:45:49.428Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/4/2020 - 14:45:49.428Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/4/2020 - 14:45:49.428Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:49.428Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:49.428Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:49.428Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:49.428Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:49.428Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:49.428Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:49.444Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:49.444Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:49.444Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:49.444Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:49.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/4/2020 - 14:45:49.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/4/2020 - 14:45:49.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/4/2020 - 14:45:49.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/4/2020 - 14:45:49.444Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/4/2020 - 14:45:49.444Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/4/2020 - 14:45:49.444Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/4/2020 - 14:45:49.444Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/4/2020 - 14:45:49.444Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/4/2020 - 14:45:49.444Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/4/2020 - 14:45:49.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64
7/4/2020 - 14:45:49.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64
7/4/2020 - 14:45:49.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64
7/4/2020 - 14:45:49.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages\vcRuntimeAdditional_x86
7/4/2020 - 14:45:49.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages\vcRuntimeAdditional_x86
7/4/2020 - 14:45:49.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages\vcRuntimeAdditional_x86
7/4/2020 - 14:45:49.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages\vcRuntimeMinimum_x86
7/4/2020 - 14:45:49.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages\vcRuntimeMinimum_x86
7/4/2020 - 14:45:49.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages\vcRuntimeMinimum_x86
7/4/2020 - 14:45:49.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages\vcRuntimeMinimum_amd64
7/4/2020 - 14:45:49.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages\vcRuntimeMinimum_amd64
7/4/2020 - 14:45:49.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages\vcRuntimeMinimum_amd64
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk
7/4/2020 - 14:45:49.522Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk
7/4/2020 - 14:45:49.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets
7/4/2020 - 14:45:49.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.VisualBasic.Targets
7/4/2020 - 14:45:49.522Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets
7/4/2020 - 14:45:49.522Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.522Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets
7/4/2020 - 14:45:49.522Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.522Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.522Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.VisualBasic.Targets
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.VisualBasic.Targets
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.VisualBasic.Targets
7/4/2020 - 14:45:49.522Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.522Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.522Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.522Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.522Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.Targets
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.Targets
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.Targets
7/4/2020 - 14:45:49.522Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\pt-BR
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xml
7/4/2020 - 14:45:49.522Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\pt-BR
7/4/2020 - 14:45:49.522Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\pt-BR
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList
7/4/2020 - 14:45:49.522Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Dotted_Line.jtp
7/4/2020 - 14:45:49.522Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Dotted_Line.jtpDotted_Line.jtp
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Dotted_Line.jtp
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Dotted_Line.jtp
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Dotted_Line.jtp
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Genko_1.jtp
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Genko_1.jtp
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Genko_1.jtp
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Genko_1.jtp
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Genko_2.jtp
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk
7/4/2020 - 14:45:49.522Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets
7/4/2020 - 14:45:49.522Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets
7/4/2020 - 14:45:49.522Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.522Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.522Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets
7/4/2020 - 14:45:49.522Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.522Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.538Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.538Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.538Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.538Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.538Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets
7/4/2020 - 14:45:49.538Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.538Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets
7/4/2020 - 14:45:49.538Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.538Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.VisualBasic.Targets
7/4/2020 - 14:45:49.538Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.VisualBasic.Targets
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.VisualBasic.Targets
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.VisualBasic.Targets
7/4/2020 - 14:45:49.538Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.538Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.538Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.538Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.538Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.Targets
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.Targets
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.Targets
7/4/2020 - 14:45:49.538Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\pt-BR
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xml
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\SubsetList\Client.xml
7/4/2020 - 14:45:49.538Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\pt-BR
7/4/2020 - 14:45:49.538Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\pt-BR
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\RedistList
7/4/2020 - 14:45:49.538Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\RedistList
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\SubsetList
7/4/2020 - 14:45:49.538Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\SubsetList
7/4/2020 - 14:45:49.538Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:49.538Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR
7/4/2020 - 14:45:49.538Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US
7/4/2020 - 14:45:49.538Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.538Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.538Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:49.538Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.538Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:49.538Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.pngbackground.png
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:49.553Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:49.553Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdf
7/4/2020 - 14:45:49.553Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdfRacWmiDatabase.sdf
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdf
7/4/2020 - 14:45:49.553Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdfRacWmiDatabase.sdf
7/4/2020 - 14:45:49.553Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData
7/4/2020 - 14:45:49.553Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications
7/4/2020 - 14:45:49.553Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Temp
7/4/2020 - 14:45:49.553Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Temp
7/4/2020 - 14:45:49.553Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.553Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.553Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.553Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.553Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.553Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.553Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:49.553Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:49.553Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:49.553Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:49.553Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:49.553Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:49.553Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:49.553Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:49.553Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US
7/4/2020 - 14:45:49.553Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US
7/4/2020 - 14:45:49.553Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\Cache
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\Cache
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Manifest
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Manifest
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Sessions
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Sessions
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Upload
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Upload
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programas
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programas
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\ActivityLog
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\ActivityLog
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Inbox
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Inbox
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Queue
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Queue
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\SentItems
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\SentItems
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpgWelcomeScan.jpg
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task
7/4/2020 - 14:45:49.569Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM\Server
7/4/2020 - 14:45:49.569Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM\Server
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\DRM\Server
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome\logs
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome\logs
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\eHome\logs
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\imcrcache.xml
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\imcrcache.xml
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Connections
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Connections
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Connections
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\Outbound
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\Outbound
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\Outbound
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\AIT
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\AIT
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\AIT
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\GameExplorer
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\GameExplorer
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\GameExplorer
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Templates
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Templates
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Templates
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc\Profiles
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc\Profiles
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\WwanSvc\Profiles
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0
7/4/2020 - 14:45:49.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS\MachineKeys
7/4/2020 - 14:45:49.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS\MachineKeys
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS\MachineKeys
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdf
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdf
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\Cache
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\Cache
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\Cache
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Manifest
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Manifest
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Manifest
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Sessions
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Sessions
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Sessions
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Upload
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Upload
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Upload
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programas
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programas
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programas
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programas
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\ActivityLog
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\ActivityLog
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\ActivityLog
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Inbox
7/4/2020 - 14:45:49.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Inbox
7/4/2020 - 14:45:49.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Inbox
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Queue
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Queue
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Queue
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\SentItems
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\SentItems
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\SentItems
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpgWelcomeScan.jpg
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Roaming\Adobe\Flash Player\NativeCache
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\AppData\Roaming\Adobe\Flash Player\NativeCache
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
7/4/2020 - 14:45:49.616Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:49.616Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:49.616Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:49.616Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.616Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.616Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.616Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.616Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.616Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links
7/4/2020 - 14:45:49.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
7/4/2020 - 14:45:49.647Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:49.647Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:49.647Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:49.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
7/4/2020 - 14:45:49.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/4/2020 - 14:45:49.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
7/4/2020 - 14:45:49.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/4/2020 - 14:45:49.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/4/2020 - 14:45:49.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
7/4/2020 - 14:45:49.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/4/2020 - 14:45:49.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/4/2020 - 14:45:49.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/4/2020 - 14:45:49.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
7/4/2020 - 14:45:49.647Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/4/2020 - 14:45:49.647Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/4/2020 - 14:45:49.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/4/2020 - 14:45:49.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
7/4/2020 - 14:45:49.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/4/2020 - 14:45:49.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/4/2020 - 14:45:49.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
7/4/2020 - 14:45:49.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/4/2020 - 14:45:49.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/4/2020 - 14:45:49.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/4/2020 - 14:45:49.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/4/2020 - 14:45:49.647Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/4/2020 - 14:45:49.647Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/4/2020 - 14:45:49.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/4/2020 - 14:45:49.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/4/2020 - 14:45:49.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/4/2020 - 14:45:49.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/4/2020 - 14:45:49.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/4/2020 - 14:45:49.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/4/2020 - 14:45:49.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/4/2020 - 14:45:49.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
7/4/2020 - 14:45:49.663Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/4/2020 - 14:45:49.663Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/4/2020 - 14:45:49.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/4/2020 - 14:45:49.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
7/4/2020 - 14:45:49.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/4/2020 - 14:45:49.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/4/2020 - 14:45:49.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
7/4/2020 - 14:45:49.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/4/2020 - 14:45:49.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/4/2020 - 14:45:49.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/4/2020 - 14:45:49.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/4/2020 - 14:45:49.225Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/4/2020 - 14:45:49.663Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/4/2020 - 14:45:49.663Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/4/2020 - 14:45:49.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/4/2020 - 14:45:49.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/4/2020 - 14:45:49.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/4/2020 - 14:45:49.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/4/2020 - 14:45:49.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/4/2020 - 14:45:49.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/4/2020 - 14:45:49.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/4/2020 - 14:45:49.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/4/2020 - 14:45:49.663Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/4/2020 - 14:45:49.663Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/4/2020 - 14:45:49.756Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.datAdministrator.dat
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.dat
7/4/2020 - 14:45:49.756Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.datAdministrator.dat
7/4/2020 - 14:45:49.756Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:49.756Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:49.756Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets
7/4/2020 - 14:45:49.756Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.756Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets
7/4/2020 - 14:45:49.756Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.756Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.756Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.756Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.756Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.756Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.756Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xml
7/4/2020 - 14:45:49.756Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.756Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xml
7/4/2020 - 14:45:49.756Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.756Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.756Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.756Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.756Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\pt-BR
7/4/2020 - 14:45:49.756Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.756Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xml
7/4/2020 - 14:45:49.756Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xml
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xml
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xml
7/4/2020 - 14:45:49.756Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\To_Do_List.jtpTo_Do_List.jtp
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\To_Do_List.jtp
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\To_Do_List.jtp
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\To_Do_List.jtp
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Genko_2.jtp
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Genko_2.jtp
7/4/2020 - 14:45:49.756Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Genko_2.jtp
7/4/2020 - 14:45:49.756Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xml
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xml
7/4/2020 - 14:45:49.772Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.772Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.772Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.772Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.772Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.772Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\SubsetList\Client.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\SubsetList\Client.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\SubsetList\Client.xml
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\pt-BR
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\SubsetList\Client.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\SubsetList\Client.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\SubsetList\Client.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\SubsetList\Client.xml
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.Lck
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_AssetId.H1WHelp_MKWD_AssetId.H1W
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_AssetId.H1WHelp_MKWD_AssetId.H1W
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_CValidator.H1D
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_CValidator.H1DHelp_CValidator.H1D
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_CValidator.H1D
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_CValidator.H1DHelp_CValidator.H1D
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_CValidator.H1D
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_CValidator.H1DHelp_CValidator.H1D
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_CValidator.H1D
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_CValidator.H1DHelp_CValidator.H1D
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.pngbackground.png
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:49.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.pngwatermark.png
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat
7/4/2020 - 14:45:49.772Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.datRacMetaData.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat
7/4/2020 - 14:45:49.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.datRacMetaData.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:49.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:49.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:49.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:49.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows
7/4/2020 - 14:45:49.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc
7/4/2020 - 14:45:49.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc
7/4/2020 - 14:45:49.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp
7/4/2020 - 14:45:49.381Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.788Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.dat
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures
7/4/2020 - 14:45:49.413Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wma
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wma
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS\MachineKeys
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS\MachineKeys
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\DSS\MachineKeys
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
7/4/2020 - 14:45:49.803Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
7/4/2020 - 14:45:49.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}
7/4/2020 - 14:45:49.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}
7/4/2020 - 14:45:49.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}
7/4/2020 - 14:45:49.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}
7/4/2020 - 14:45:49.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdf
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdf
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications
7/4/2020 - 14:45:49.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\Cache
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\Cache
7/4/2020 - 14:45:49.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\Cache
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Manifest
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Manifest
7/4/2020 - 14:45:49.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Manifest
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Sessions
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Sessions
7/4/2020 - 14:45:49.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Sessions
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Upload
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Upload
7/4/2020 - 14:45:49.819Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Sqm\Upload
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programas
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programas
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programas
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programas
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
7/4/2020 - 14:45:49.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive
7/4/2020 - 14:45:49.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\ActivityLog
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\ActivityLog
7/4/2020 - 14:45:49.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\ActivityLog
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages
7/4/2020 - 14:45:49.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Inbox
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Inbox
7/4/2020 - 14:45:49.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Inbox
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Queue
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Queue
7/4/2020 - 14:45:49.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Queue
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\SentItems
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\SentItems
7/4/2020 - 14:45:49.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\SentItems
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox
7/4/2020 - 14:45:49.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpgWelcomeScan.jpg
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US
7/4/2020 - 14:45:49.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.834Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:49.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.pngbackground.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:49.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.pngwatermark.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR
7/4/2020 - 14:45:49.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR
7/4/2020 - 14:45:49.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows
7/4/2020 - 14:45:49.850Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
7/4/2020 - 14:45:49.866Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
7/4/2020 - 14:45:49.866Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
7/4/2020 - 14:45:49.866Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
7/4/2020 - 14:45:49.866Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
7/4/2020 - 14:45:49.866Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
7/4/2020 - 14:45:49.866Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR
7/4/2020 - 14:45:49.866Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR
7/4/2020 - 14:45:49.866Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR
7/4/2020 - 14:45:49.866Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.866Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.866Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.866Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.866Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}
7/4/2020 - 14:45:49.866Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:49.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
7/4/2020 - 14:45:49.881Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/4/2020 - 14:45:49.881Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/4/2020 - 14:45:49.881Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/4/2020 - 14:45:49.881Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/4/2020 - 14:45:49.881Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches
7/4/2020 - 14:45:49.881Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Everywhere.search-ms.cb5649
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.928Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.928Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.928Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.928Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.928Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
7/4/2020 - 14:45:49.928Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.928Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links
7/4/2020 - 14:45:49.928Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.url.cb5649
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
7/4/2020 - 14:45:49.944Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\CB5649-Readme.txt
7/4/2020 - 14:45:49.944Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Monitor\WindowsKernelCaptureDriver Package\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.944Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:49.944Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.944Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
7/4/2020 - 14:45:49.928Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
7/4/2020 - 14:45:49.944Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links
7/4/2020 - 14:45:49.944Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
7/4/2020 - 14:45:49.944Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}
7/4/2020 - 14:45:49.944Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm.cb5649
7/4/2020 - 14:45:49.944Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
7/4/2020 - 14:45:49.944Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/4/2020 - 14:45:49.944Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
7/4/2020 - 14:45:49.944Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/4/2020 - 14:45:49.944Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links
7/4/2020 - 14:45:49.944Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.url.cb5649
7/4/2020 - 14:45:49.944Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
7/4/2020 - 14:45:49.944Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\CB5649-Readme.txt
7/4/2020 - 14:45:49.944Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\CB5649-Readme.txt
7/4/2020 - 14:45:49.944Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/4/2020 - 14:45:49.944Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
7/4/2020 - 14:45:49.944Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c.cb5649
7/4/2020 - 14:45:49.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/4/2020 - 14:45:49.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
7/4/2020 - 14:45:49.959Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat.cb5649
7/4/2020 - 14:45:49.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf.cb5649
7/4/2020 - 14:45:49.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\CB5649-Readme.txt
7/4/2020 - 14:45:49.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\CB5649-Readme.txt
7/4/2020 - 14:45:49.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\CB5649-Readme.txt
7/4/2020 - 14:45:49.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\CB5649-Readme.txt
7/4/2020 - 14:45:49.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\CB5649-Readme.txt
7/4/2020 - 14:45:49.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\CB5649-Readme.txt
7/4/2020 - 14:45:49.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.959Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\CB5649-Readme.txt
7/4/2020 - 14:45:49.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\CB5649-Readme.txt
7/4/2020 - 14:45:49.959Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\CB5649-Readme.txt
7/4/2020 - 14:45:49.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.959Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.959Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.944Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads
7/4/2020 - 14:45:49.959Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip
7/4/2020 - 14:45:49.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\CB5649-Readme.txt
7/4/2020 - 14:45:49.959Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\CB5649-Readme.txt
7/4/2020 - 14:45:49.959Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/4/2020 - 14:45:49.959Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/4/2020 - 14:45:49.975Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/4/2020 - 14:45:49.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches
7/4/2020 - 14:45:49.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads
7/4/2020 - 14:45:49.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\Monitor.zip.cb5649
7/4/2020 - 14:45:49.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
7/4/2020 - 14:45:49.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches
7/4/2020 - 14:45:49.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms.cb5649
7/4/2020 - 14:45:49.975Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\CB5649-Readme.txt
7/4/2020 - 14:45:49.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\CB5649-Readme.txt
7/4/2020 - 14:45:49.975Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Downloads\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.975Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\CB5649-Readme.txt
7/4/2020 - 14:45:49.975Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Searches\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Graph.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Graph.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Graph.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Graph.jtp
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Memo.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Memo.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Memo.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Memo.jtp
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Month_Calendar.jtp
7/4/2020 - 14:45:50.38Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Month_Calendar.jtpMonth_Calendar.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Month_Calendar.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Month_Calendar.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Month_Calendar.jtp
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Music.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Music.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Music.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Music.jtp
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Seyes.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Seyes.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Seyes.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Seyes.jtp
7/4/2020 - 14:45:49.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Shorthand.jtp
7/4/2020 - 14:45:50.38Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Shorthand.jtpShorthand.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Shorthand.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Shorthand.jtp
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Windows Journal\Templates\Shorthand.jtp
7/4/2020 - 14:45:50.38Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.APL
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.APL
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.APL
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.APL
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.CRT
7/4/2020 - 14:45:50.38Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xmlFrameworkList.xml
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xml
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xml
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xml
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.38Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1WHelp_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.38Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1WHelp_MKWD_BestBet.H1W
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.38Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR
7/4/2020 - 14:45:50.38Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_AssetId.H1WHelp_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.38Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_AssetId.H1WHelp_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.38Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US
7/4/2020 - 14:45:50.38Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_AssetId.H1WHelp_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_AssetId.H1WHelp_MKWD_AssetId.H1W
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Config
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Config
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00003.log
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00003.log
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00003.log
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00001.jrs
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00001.jrsMSSres00001.jrs
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00001.jrs
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00001.jrsMSSres00001.jrs
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00002.jrs
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00002.jrsMSSres00002.jrs
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00002.jrs
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00002.jrsMSSres00002.jrs
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile10.bmpusertile10.bmp
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.dat
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.dat
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures
7/4/2020 - 14:45:50.53Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\user.bmp
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.69Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.69Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:49.819Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wma
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wma
7/4/2020 - 14:45:50.69Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wmaRingtone 01.wma
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wma
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wma
7/4/2020 - 14:45:50.69Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wmaRingtone 01.wma
7/4/2020 - 14:45:50.69Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wmaRingtone 01.wma
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wma
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wma
7/4/2020 - 14:45:50.69Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wmaRingtone 01.wma
7/4/2020 - 14:45:50.69Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wmaRingtone 01.wma
7/4/2020 - 14:45:50.69Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wmaRingtone 01.wma
7/4/2020 - 14:45:50.69Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wmaRingtone 01.wma
7/4/2020 - 14:45:50.69Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wmaRingtone 01.wma
7/4/2020 - 14:45:50.69Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wmaRingtone 01.wma
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
7/4/2020 - 14:45:50.69Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
7/4/2020 - 14:45:50.69Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC
7/4/2020 - 14:45:50.69Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/4/2020 - 14:45:50.69Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f\Report.wer
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f\Report.wer
7/4/2020 - 14:45:50.69Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f\Report.wer
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671
7/4/2020 - 14:45:50.69Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.69Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.covconfident.cov
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR
7/4/2020 - 14:45:50.84Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US
7/4/2020 - 14:45:50.84Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\036633b0500d6344ff31cb25528737c8_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2120371a32f41a1da6c1688b6daff881_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c2e06c7c0bc7a9e74e7e0309e2c0b97_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6141f515b5ca1957233abdb43966b6b2_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8072febeee5d08c9943a7f8c79a3a602_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9940599c2180f4cec0665b6cf492f0c1_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4ECCD106F69E31C1B12304E5463BB71D_FA25E266-6D0F-4DE2-813A-BF4374E0628C
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4ECCD106F69E31C1B12304E5463BB71D_FA25E266-6D0F-4DE2-813A-BF4374E0628C
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4ECCD106F69E31C1B12304E5463BB71D_FA25E266-6D0F-4DE2-813A-BF4374E0628C
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4ECCD106F69E31C1B12304E5463BB71D_FA25E266-6D0F-4DE2-813A-BF4374E0628C
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:50.100Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.pngbackground.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:50.100Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.pngwatermark.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR
7/4/2020 - 14:45:50.100Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR
7/4/2020 - 14:45:50.100Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows
7/4/2020 - 14:45:50.100Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
7/4/2020 - 14:45:50.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
7/4/2020 - 14:45:50.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
7/4/2020 - 14:45:50.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
7/4/2020 - 14:45:50.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
7/4/2020 - 14:45:50.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
7/4/2020 - 14:45:50.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Config
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Config
7/4/2020 - 14:45:50.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Config
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs
7/4/2020 - 14:45:50.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00003.log
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00003.log
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00001.jrs
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00001.jrs
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00002.jrs
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00002.jrs
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects
7/4/2020 - 14:45:50.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
7/4/2020 - 14:45:50.116Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
7/4/2020 - 14:45:50.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC
7/4/2020 - 14:45:50.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/4/2020 - 14:45:50.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/4/2020 - 14:45:50.131Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\STATE.RSM
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\STATE.RSM
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\STATE.RSM
7/4/2020 - 14:45:50.131Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/4/2020 - 14:45:50.131Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/4/2020 - 14:45:50.131Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
7/4/2020 - 14:45:50.131Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:50.131Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:50.147Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:50.147Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:50.147Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdfRacWmiDatabase.sdf
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdf
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.datAdministrator.dat
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.dat
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.dat
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.datAdministrator.dat
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.datAdministrator.dat
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.dat
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.dat
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.datAdministrator.dat
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.147Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.147Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.datAdministrator.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.datAdministrator.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Administrator.datAdministrator.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Behemot.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:50.163Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.163Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.163Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.163Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.datRacMetaData.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.datRacMetaData.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.datRacMetaData.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat
7/4/2020 - 14:45:50.163Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.datRacMetaData.dat
7/4/2020 - 14:45:50.163Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.datRacMetaData.dat
7/4/2020 - 14:45:50.163Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.datRacMetaData.dat
7/4/2020 - 14:45:50.163Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.datRacMetaData.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:50.163Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.163Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.163Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.163Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.163Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.163Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
7/4/2020 - 14:45:50.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:50.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:50.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:50.178Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:50.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.178Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.WIH
7/4/2020 - 14:45:50.256Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.CRT
7/4/2020 - 14:45:50.256Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.CRT
7/4/2020 - 14:45:50.256Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.CRT
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.256Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_BestBet.H1WHelp_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.256Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.256Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_BestBet.H1WHelp_MKWD_BestBet.H1W
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MTOC_help.H1H
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.256Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_BestBet.H1WHelp_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.256Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.256Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_BestBet.H1WHelp_MKWD_BestBet.H1W
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex
7/4/2020 - 14:45:50.272Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex
7/4/2020 - 14:45:50.272Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp
7/4/2020 - 14:45:50.272Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile11.bmpusertile11.bmp
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp
7/4/2020 - 14:45:50.272Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile12.bmpusertile12.bmp
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp
7/4/2020 - 14:45:50.272Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile13.bmpusertile13.bmp
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.303Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.303Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US
7/4/2020 - 14:45:49.850Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.303Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wma
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wma
7/4/2020 - 14:45:50.303Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wmaRingtone 02.wma
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wma
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wma
7/4/2020 - 14:45:50.303Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wmaRingtone 02.wma
7/4/2020 - 14:45:50.303Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wmaRingtone 02.wma
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wma
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wma
7/4/2020 - 14:45:50.303Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wmaRingtone 02.wma
7/4/2020 - 14:45:50.303Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wmaRingtone 02.wma
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wma
7/4/2020 - 14:45:50.303Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wmaRingtone 02.wma
7/4/2020 - 14:45:50.303Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wmaRingtone 02.wma
7/4/2020 - 14:45:50.303Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wmaRingtone 02.wma
7/4/2020 - 14:45:50.303Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wmaRingtone 02.wma
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wma
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671
7/4/2020 - 14:45:50.303Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f
7/4/2020 - 14:45:50.303Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f
7/4/2020 - 14:45:49.866Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289
7/4/2020 - 14:45:50.303Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289
7/4/2020 - 14:45:50.303Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671
7/4/2020 - 14:45:50.303Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\DMIA26A.tmp.log.xml
7/4/2020 - 14:45:50.303Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\DMIA26A.tmp.log.xmlDMIA26A.tmp.log.xml
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\DMIA26A.tmp.log.xml
7/4/2020 - 14:45:50.303Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\DMIA26A.tmp.log.xmlDMIA26A.tmp.log.xml
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\Report.wer
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\Report.wer
7/4/2020 - 14:45:50.303Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\Report.wer
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tifWelcomeFax.tif
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tifWelcomeFax.tif
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.319Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pt-BR\resource.xml
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\pt-BR\resource.xml
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Config
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Config
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Config
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00003.log
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00003.log
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00001.jrs
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00001.jrs
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00002.jrs
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSSres00002.jrs
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.334Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.334Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.334Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:50.334Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:50.334Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:50.334Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:50.334Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628cea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:50.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:50.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
7/4/2020 - 14:45:50.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
7/4/2020 - 14:45:50.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:50.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
7/4/2020 - 14:45:50.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:50.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:50.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:50.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:50.350Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:50.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:50.350Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:50.350Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.350Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:50.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:50.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
7/4/2020 - 14:45:50.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:50.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:50.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
7/4/2020 - 14:45:50.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:50.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:50.366Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat
7/4/2020 - 14:45:50.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.366Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.366Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.366Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.366Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.38Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.CSD
7/4/2020 - 14:45:50.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1WHelp_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.444Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1WHelp_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.444Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1WHelp_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.444Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1WHelp_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.444Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1WHelp_MKWD_BestBet.H1W
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.H1D
7/4/2020 - 14:45:50.444Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1WHelp_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.444Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1WHelp_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.H1DHelp_MValidator.H1D
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.H1D
7/4/2020 - 14:45:50.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.H1DHelp_MValidator.H1D
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help{A25A5CCD-80F4-4E02-AADD-7F39CC55E737}.H1Q
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help{A25A5CCD-80F4-4E02-AADD-7F39CC55E737}.H1Q
7/4/2020 - 14:45:50.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help{A25A5CCD-80F4-4E02-AADD-7F39CC55E737}.H1QHelp{A25A5CCD-80F4-4E02-AADD-7F39CC55E737}.H1Q
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help{A25A5CCD-80F4-4E02-AADD-7F39CC55E737}.H1Q
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help{A25A5CCD-80F4-4E02-AADD-7F39CC55E737}.H1Q
7/4/2020 - 14:45:50.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help{A25A5CCD-80F4-4E02-AADD-7F39CC55E737}.H1QHelp{A25A5CCD-80F4-4E02-AADD-7F39CC55E737}.H1Q
7/4/2020 - 14:45:50.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MTOC_help.H1HHelp_MTOC_help.H1H
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MTOC_help.H1HHelp_MTOC_help.H1H
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.Lck
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.Lck
7/4/2020 - 14:45:50.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.LckHelp_MValidator.Lck
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.Lck
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.Lck
7/4/2020 - 14:45:50.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.LckHelp_MValidator.Lck
7/4/2020 - 14:45:50.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MTOC_help.H1HHelp_MTOC_help.H1H
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MTOC_help.H1HHelp_MTOC_help.H1H
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:49.538Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.444Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.pngbackground.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.53Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.444Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.459Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.pngbackground.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml
7/4/2020 - 14:45:50.84Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
7/4/2020 - 14:45:50.100Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl
7/4/2020 - 14:45:50.459Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.CrwlSystemIndex.1.Crwl
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl
7/4/2020 - 14:45:50.459Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.CrwlSystemIndex.1.Crwl
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr
7/4/2020 - 14:45:50.459Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthrSystemIndex.1.gthr
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr
7/4/2020 - 14:45:50.459Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthrSystemIndex.1.gthr
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer
7/4/2020 - 14:45:50.459Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap
7/4/2020 - 14:45:50.459Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore
7/4/2020 - 14:45:50.459Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore
7/4/2020 - 14:45:50.303Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp
7/4/2020 - 14:45:50.459Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile44.bmpusertile44.bmp
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp
7/4/2020 - 14:45:50.459Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile14.bmpusertile14.bmp
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp
7/4/2020 - 14:45:50.459Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.475Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.475Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms
7/4/2020 - 14:45:50.475Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wmaRingtone 10.wma
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wma
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wma
7/4/2020 - 14:45:50.475Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wmaRingtone 10.wma
7/4/2020 - 14:45:50.475Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wmaRingtone 10.wma
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wma
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wma
7/4/2020 - 14:45:50.475Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wmaRingtone 10.wma
7/4/2020 - 14:45:50.475Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wmaRingtone 10.wma
7/4/2020 - 14:45:50.475Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wmaRingtone 10.wma
7/4/2020 - 14:45:50.475Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wmaRingtone 10.wma
7/4/2020 - 14:45:50.475Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wmaRingtone 03.wma
7/4/2020 - 14:45:50.475Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wmaRingtone 10.wma
7/4/2020 - 14:45:50.475Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wmaRingtone 10.wma
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wma
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wma
7/4/2020 - 14:45:50.475Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wmaRingtone 03.wma
7/4/2020 - 14:45:50.475Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wmaRingtone 03.wma
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wma
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wma
7/4/2020 - 14:45:50.475Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wmaRingtone 03.wma
7/4/2020 - 14:45:50.475Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wmaRingtone 03.wma
7/4/2020 - 14:45:50.475Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wmaRingtone 03.wma
7/4/2020 - 14:45:50.475Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wmaRingtone 03.wma
7/4/2020 - 14:45:50.475Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wmaRingtone 03.wma
7/4/2020 - 14:45:50.475Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wmaRingtone 03.wma
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f
7/4/2020 - 14:45:50.475Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289
7/4/2020 - 14:45:50.475Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671
7/4/2020 - 14:45:50.475Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f\Report.wer
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f\Report.wer
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\DMIA26A.tmp.log.xml
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\DMIA26A.tmp.log.xml
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\Report.wer
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\Report.wer
7/4/2020 - 14:45:50.475Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\DMIA661.tmp.log.xml
7/4/2020 - 14:45:50.491Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\DMIA661.tmp.log.xmlDMIA661.tmp.log.xml
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\DMIA661.tmp.log.xml
7/4/2020 - 14:45:50.491Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\DMIA661.tmp.log.xmlDMIA661.tmp.log.xml
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\Report.wer
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\Report.wer
7/4/2020 - 14:45:50.491Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\Report.wer
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\DMIA661.tmp.log.xml
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\DMIA661.tmp.log.xml
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\Report.wer
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\Report.wer
7/4/2020 - 14:45:50.69Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.491Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.491Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.covconfident.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.131Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.491Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR
7/4/2020 - 14:45:50.491Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdfRacWmiDatabase.sdf
7/4/2020 - 14:45:50.491Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
7/4/2020 - 14:45:50.491Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
7/4/2020 - 14:45:50.491Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
7/4/2020 - 14:45:50.491Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex
7/4/2020 - 14:45:50.491Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex
7/4/2020 - 14:45:50.491Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer
7/4/2020 - 14:45:50.491Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap
7/4/2020 - 14:45:50.491Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore
7/4/2020 - 14:45:50.491Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.491Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.491Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.491Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/4/2020 - 14:45:50.506Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.url
7/4/2020 - 14:45:50.506Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/4/2020 - 14:45:50.506Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/4/2020 - 14:45:50.506Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/4/2020 - 14:45:50.506Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/4/2020 - 14:45:50.506Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628cea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.506Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:50.506Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:50.506Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:50.506Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:50.506Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:50.506Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:50.506Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:50.506Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:50.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.WIH
7/4/2020 - 14:45:50.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.WIH
7/4/2020 - 14:45:50.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.WIH
7/4/2020 - 14:45:50.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.CSD
7/4/2020 - 14:45:50.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.CSD
7/4/2020 - 14:45:50.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk\M1033DSK.CSD
7/4/2020 - 14:45:50.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.LckHelp_MValidator.Lck
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
7/4/2020 - 14:45:50.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.Lck
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacMetaData.datRacMetaData.dat
7/4/2020 - 14:45:50.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
7/4/2020 - 14:45:50.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5d91c0b736f4f8dbdd317cf8a037fced_fa25e266-6d0f-4de2-813a-bf4374e0628c.cb5649
7/4/2020 - 14:45:50.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.LckHelp_MValidator.Lck
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wmaRingtone 02.wma
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\IlsCache\ilrcache.xml
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/4/2020 - 14:45:50.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil
7/4/2020 - 14:45:50.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
7/4/2020 - 14:45:50.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdfRacDatabase.sdf
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.datRacWmiDataBookmarks.dat
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1WHelp_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.584Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.584Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.datRacWmiEventData.dat
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wmaRingtone 10.wma
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wmaRingtone 03.wma
7/4/2020 - 14:45:50.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}
7/4/2020 - 14:45:50.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
7/4/2020 - 14:45:50.584Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/4/2020 - 14:45:50.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0
7/4/2020 - 14:45:50.584Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:50.600Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/4/2020 - 14:45:50.600Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/4/2020 - 14:45:50.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xmlWinFXList.xml
7/4/2020 - 14:45:50.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:50.584Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.TargetsWorkflow.Targets
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MTOC_help.H1HHelp_MTOC_help.H1H
7/4/2020 - 14:45:50.600Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wmaRingtone 01.wma
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml.cb5649
7/4/2020 - 14:45:50.600Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml.cb5649
7/4/2020 - 14:45:50.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets.cb5649
7/4/2020 - 14:45:50.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets.cb5649
7/4/2020 - 14:45:50.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\CB5649-Readme.txt
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.url.cb5649
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\CB5649-Readme.txt
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\CB5649-Readme.txt
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.url.cb5649
7/4/2020 - 14:45:50.600Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.url.cb5649
7/4/2020 - 14:45:50.600Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MTOC_help.H1HHelp_MTOC_help.H1H
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.H1D
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.H1D
7/4/2020 - 14:45:50.116Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.Lck
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.Lck
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.H1D
7/4/2020 - 14:45:50.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.H1DHelp_MValidator.H1D
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\CB5649-Readme.txt
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\CB5649-Readme.txt
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.H1D
7/4/2020 - 14:45:50.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.H1DHelp_MValidator.H1D
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.Lck
7/4/2020 - 14:45:50.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.LckHelp_MValidator.Lck
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.Lck
7/4/2020 - 14:45:50.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.LckHelp_MValidator.Lck
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help{A25A5CCD-80F4-4E02-AADD-7F39CC55E737}.H1Q
7/4/2020 - 14:45:50.256Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_CValidator.H1D
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\CB5649-Readme.txt
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\CB5649-Readme.txt
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_CValidator.H1D
7/4/2020 - 14:45:50.256Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\CB5649-Readme.txt
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\CB5649-Readme.txt
7/4/2020 - 14:45:50.616Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:50.616Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:50.616Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:50.616Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\CB5649-Readme.txt
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\CB5649-Readme.txt
7/4/2020 - 14:45:50.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:50.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:50.616Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:50.631Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:50.631Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:50.631Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\CB5649-Readme.txt
7/4/2020 - 14:45:50.631Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\CB5649-Readme.txt
7/4/2020 - 14:45:50.631Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Behemot\Favorites\Links for Brasil\CB5649-Readme.txtCB5649-Readme.txt
7/4/2020 - 14:45:50.616Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.256Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.256Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.256Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.H1D
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.H1D
7/4/2020 - 14:45:50.256Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.Lck
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.Lck
7/4/2020 - 14:45:50.256Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help{A25A5CCD-80F4-4E02-AADD-7F39CC55E737}.H1Q
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help{A25A5CCD-80F4-4E02-AADD-7F39CC55E737}.H1Q
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_CValidator.H1D
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_CValidator.H1D
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.H1D
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.H1D
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.Lck
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR\Help_MValidator.Lck
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1D
7/4/2020 - 14:45:50.631Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1DHelp_MValidator.H1D
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1D
7/4/2020 - 14:45:50.631Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1DHelp_MValidator.H1D
7/4/2020 - 14:45:50.631Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1DHelp_MValidator.H1D
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1D
7/4/2020 - 14:45:50.631Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1DHelp_MValidator.H1D
7/4/2020 - 14:45:50.631Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1DHelp_MValidator.H1D
7/4/2020 - 14:45:50.631Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1DHelp_MValidator.H1D
7/4/2020 - 14:45:50.631Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1DHelp_MValidator.H1D
7/4/2020 - 14:45:50.631Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1DHelp_MValidator.H1D
7/4/2020 - 14:45:50.631Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1DHelp_MValidator.H1D
7/4/2020 - 14:45:50.631Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1DHelp_MValidator.H1D
7/4/2020 - 14:45:49.772Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.Lck
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_CValidator.H1D
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_CValidator.H1D
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1D
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1D
7/4/2020 - 14:45:50.272Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.Lck
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.Lck
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_CValidator.H1D
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_CValidator.H1D
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_AssetId.H1W
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MKWD_BestBet.H1W
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MTOC_help.H1H
7/4/2020 - 14:45:50.319Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1D
7/4/2020 - 14:45:50.631Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Assistance\Client\1.0\pt-BR_en-US\Help_MValidator.H1D
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles
7/4/2020 - 14:45:50.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
7/4/2020 - 14:45:50.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
7/4/2020 - 14:45:50.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
7/4/2020 - 14:45:50.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
7/4/2020 - 14:45:50.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001
7/4/2020 - 14:45:50.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001
7/4/2020 - 14:45:50.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001
7/4/2020 - 14:45:50.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001
7/4/2020 - 14:45:50.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001
7/4/2020 - 14:45:50.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001
7/4/2020 - 14:45:50.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002
7/4/2020 - 14:45:50.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002
7/4/2020 - 14:45:50.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002
7/4/2020 - 14:45:50.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002
7/4/2020 - 14:45:50.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002
7/4/2020 - 14:45:50.647Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002
7/4/2020 - 14:45:50.647Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002
7/4/2020 - 14:45:50.647Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000
7/4/2020 - 14:45:50.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.001
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.001
7/4/2020 - 14:45:50.647Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.001
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.002
7/4/2020 - 14:45:50.647Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.002
7/4/2020 - 14:45:50.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.002
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp
7/4/2020 - 14:45:50.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile15.bmpusertile15.bmp
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp
7/4/2020 - 14:45:50.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile16.bmpusertile16.bmp
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp
7/4/2020 - 14:45:50.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile17.bmpusertile17.bmp
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp
7/4/2020 - 14:45:49.788Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wma
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wma
7/4/2020 - 14:45:50.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wmaRingtone 04.wma
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wma
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wma
7/4/2020 - 14:45:50.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wmaRingtone 04.wma
7/4/2020 - 14:45:50.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wmaRingtone 04.wma
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wma
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wma
7/4/2020 - 14:45:50.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wmaRingtone 04.wma
7/4/2020 - 14:45:50.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wmaRingtone 04.wma
7/4/2020 - 14:45:49.803Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 05.wma
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 05.wma
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f\Report.wer
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_17ef534f3f8c542d26cbacf2c3cc6157e70c6c8_cab_0564ae8f\Report.wer
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\DMIA26A.tmp.log.xml
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\DMIA26A.tmp.log.xml
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\Report.wer
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_06c0a289\Report.wer
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\DMIA661.tmp.log.xml
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\DMIA661.tmp.log.xml
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\Report.wer
7/4/2020 - 14:45:50.663Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001
7/4/2020 - 14:45:50.663Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001
7/4/2020 - 14:45:50.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wmaRingtone 04.wma
7/4/2020 - 14:45:50.663Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wmaRingtone 04.wma
7/4/2020 - 14:45:50.663Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wmaRingtone 04.wma
7/4/2020 - 14:45:50.663Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wmaRingtone 04.wma
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_f41138ce89dcf347fa17318e894380b255473673_cab_07cca671\Report.wer
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.663Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.covconfident.cov
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\confident.cov
7/4/2020 - 14:45:50.663Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\fyi.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\generic.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\pt-BR\urgent.cov
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.678Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tifWelcomeFax.tif
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\pt-BR\WelcomeFax.tif
7/4/2020 - 14:45:50.678Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdfRacWmiDatabase.sdf
7/4/2020 - 14:45:50.678Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdfRacWmiDatabase.sdf
7/4/2020 - 14:45:50.678Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdfRacWmiDatabase.sdf
7/4/2020 - 14:45:50.678Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdfRacWmiDatabase.sdf
7/4/2020 - 14:45:50.678Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
7/4/2020 - 14:45:50.678Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
7/4/2020 - 14:45:50.678Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
7/4/2020 - 14:45:50.678Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
7/4/2020 - 14:45:50.678Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
7/4/2020 - 14:45:50.678Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
7/4/2020 - 14:45:50.678Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
7/4/2020 - 14:45:50.678Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
7/4/2020 - 14:45:50.678Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
7/4/2020 - 14:45:50.678Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
7/4/2020 - 14:45:50.678Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
7/4/2020 - 14:45:50.678Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
7/4/2020 - 14:45:50.678Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
7/4/2020 - 14:45:50.678Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
7/4/2020 - 14:45:50.678Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer
7/4/2020 - 14:45:50.678Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer
7/4/2020 - 14:45:50.678Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap
7/4/2020 - 14:45:50.694Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore
7/4/2020 - 14:45:50.694Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles
7/4/2020 - 14:45:50.694Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
7/4/2020 - 14:45:50.694Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
7/4/2020 - 14:45:50.694Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.001
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.001
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.002
7/4/2020 - 14:45:50.694Open1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.002
7/4/2020 - 14:45:50.694Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628cea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.694Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628cea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.694Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\Crypto\Keys\ea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628cea6ae2d06434f60d05b4f9bdaf4f95ef_fa25e266-6d0f-4de2-813a-bf4374e0628c
7/4/2020 - 14:45:50.694Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Active.GRL
7/4/2020 - 14:45:50.694Unknown1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\ProgramData\Microsoft\MF\Pending.GRL
7/4/2020 - 14:45:50.694Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/4/2020 - 14:45:50.694Read1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
7/4/2020 - 14:45:50.694Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.exeC:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.TargetsWorkflow.VisualBasic.Targets
7/4/2020 - 14:45:50.694Write1928C:\Users\Behemot\AppData\Local\Temp\qeSw.ex