diff --git a/NIST_Data_Leakage_Case/NIST_Answers/lab_generated_file/Registry.zip b/NIST_Data_Leakage_Case/NIST_Answers/lab_generated_file/Registry.zip new file mode 100644 index 0000000..f4186e2 Binary files /dev/null and b/NIST_Data_Leakage_Case/NIST_Answers/lab_generated_file/Registry.zip differ diff --git a/NIST_Data_Leakage_Case/NIST_Data_Leakage_00_Env_Setting.pptx b/NIST_Data_Leakage_Case/NIST_Data_Leakage_00_Env_Setting.pptx index 47120dd..9a69d5a 100644 Binary files a/NIST_Data_Leakage_Case/NIST_Data_Leakage_00_Env_Setting.pptx and b/NIST_Data_Leakage_Case/NIST_Data_Leakage_00_Env_Setting.pptx differ diff --git a/NIST_Data_Leakage_Case/NIST_Data_Leakage_01_Registry.pptx b/NIST_Data_Leakage_Case/NIST_Data_Leakage_01_Registry.pptx index 0f14917..4f30e4d 100644 Binary files a/NIST_Data_Leakage_Case/NIST_Data_Leakage_01_Registry.pptx and b/NIST_Data_Leakage_Case/NIST_Data_Leakage_01_Registry.pptx differ diff --git a/NIST_Data_Leakage_Case/NIST_Data_Leakage_02._WinEvt_XML_Python.pptx b/NIST_Data_Leakage_Case/NIST_Data_Leakage_02._WinEvt_XML_Python.pptx new file mode 100644 index 0000000..22fbba2 Binary files /dev/null and b/NIST_Data_Leakage_Case/NIST_Data_Leakage_02._WinEvt_XML_Python.pptx differ diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/SecurityEvt.xml b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/SecurityEvt.xml new file mode 100644 index 0000000..23d89ea --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/SecurityEvt.xml @@ -0,0 +1,36684 @@ + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +1 + + +Security +37L4247F27-25 + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +2 + + +Security +37L4247F27-25 + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +3 + + +Security +37L4247F27-25 + + +0 +0x0000000000035ce9 + + + + +4731 +0 +0 +13826 +0 +0x8020000000000000 + +4 + + +Security +37L4247F27-25 + + +Backup Operators +Builtin +S-1-5-32-551 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +Backup Operators +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +5 + + +Security +37L4247F27-25 + + +Backup Operators +Builtin +S-1-5-32-551 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4731 +0 +0 +13826 +0 +0x8020000000000000 + +6 + + +Security +37L4247F27-25 + + +Replicator +Builtin +S-1-5-32-552 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +Replicator +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +7 + + +Security +37L4247F27-25 + + +Replicator +Builtin +S-1-5-32-552 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4731 +0 +0 +13826 +0 +0x8020000000000000 + +8 + + +Security +37L4247F27-25 + + +Remote Desktop Users +Builtin +S-1-5-32-555 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +Remote Desktop Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +9 + + +Security +37L4247F27-25 + + +Remote Desktop Users +Builtin +S-1-5-32-555 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4731 +0 +0 +13826 +0 +0x8020000000000000 + +10 + + +Security +37L4247F27-25 + + +Network Configuration Operators +Builtin +S-1-5-32-556 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +Network Configuration Operators +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +11 + + +Security +37L4247F27-25 + + +Network Configuration Operators +Builtin +S-1-5-32-556 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4731 +0 +0 +13826 +0 +0x8020000000000000 + +12 + + +Security +37L4247F27-25 + + +Power Users +Builtin +S-1-5-32-547 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +Power Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +13 + + +Security +37L4247F27-25 + + +Power Users +Builtin +S-1-5-32-547 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4731 +0 +0 +13826 +0 +0x8020000000000000 + +14 + + +Security +37L4247F27-25 + + +Cryptographic Operators +Builtin +S-1-5-32-569 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +Cryptographic Operators +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +15 + + +Security +37L4247F27-25 + + +Cryptographic Operators +Builtin +S-1-5-32-569 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +16 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +17 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +18 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +19 + + +Security +37L4247F27-25 + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +20 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +21 + + +Security +37L4247F27-25 + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +22 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +23 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +24 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +25 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +26 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +27 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +28 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +29 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +30 + + +Security +37L4247F27-25 + + + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +31 + + +Security +37L4247F27-25 + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +32 + + +Security +37L4247F27-25 + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x00000000000454a7 +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +33 + + +Security +37L4247F27-25 + + +- +Administrator +37L4247F27-25 +S-1-5-21-2425377081-3129163575-2985601102-500 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +- +- +- +- +- +- +- +- +- +- +- +- +0x211 +0x211 +- +- +- +- + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +34 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +35 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +36 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +37 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +38 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +39 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +40 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +41 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +42 + + +Security +37L4247F27-25 + + + + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +43 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +44 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +45 + + +Security +informant-PC + + +0 +0x000000000000d031 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +46 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +47 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +48 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +49 + + +Security +informant-PC + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +50 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +51 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +52 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +53 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +54 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +55 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +56 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +57 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +58 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +59 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +60 + + +Security +informant-PC + + + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +61 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +62 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x0000000000028c63 +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +63 + + +Security +informant-PC + + +Administrators +Builtin +S-1-5-32-544 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +64 + + +Security +informant-PC + + +Administrators +Administrators +Builtin +S-1-5-32-544 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +65 + + +Security +informant-PC + + +Administrators +Builtin +S-1-5-32-544 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Administrators +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +66 + + +Security +informant-PC + + +Users +Builtin +S-1-5-32-545 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +67 + + +Security +informant-PC + + +Users +Users +Builtin +S-1-5-32-545 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +68 + + +Security +informant-PC + + +Users +Builtin +S-1-5-32-545 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +69 + + +Security +informant-PC + + +Guests +Builtin +S-1-5-32-546 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +70 + + +Security +informant-PC + + +Guests +Guests +Builtin +S-1-5-32-546 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +71 + + +Security +informant-PC + + +Guests +Builtin +S-1-5-32-546 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Guests +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +72 + + +Security +informant-PC + + +Backup Operators +Builtin +S-1-5-32-551 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +73 + + +Security +informant-PC + + +Backup Operators +Backup Operators +Builtin +S-1-5-32-551 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +74 + + +Security +informant-PC + + +Backup Operators +Builtin +S-1-5-32-551 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Backup Operators +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +75 + + +Security +informant-PC + + +Replicator +Builtin +S-1-5-32-552 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +76 + + +Security +informant-PC + + +Replicator +Replicator +Builtin +S-1-5-32-552 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +77 + + +Security +informant-PC + + +Replicator +Builtin +S-1-5-32-552 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Replicator +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +78 + + +Security +informant-PC + + +Remote Desktop Users +Builtin +S-1-5-32-555 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +79 + + +Security +informant-PC + + +Remote Desktop Users +Remote Desktop Users +Builtin +S-1-5-32-555 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +80 + + +Security +informant-PC + + +Remote Desktop Users +Builtin +S-1-5-32-555 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Remote Desktop Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +81 + + +Security +informant-PC + + +Network Configuration Operators +Builtin +S-1-5-32-556 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +82 + + +Security +informant-PC + + +Network Configuration Operators +Network Configuration Operators +Builtin +S-1-5-32-556 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +83 + + +Security +informant-PC + + +Network Configuration Operators +Builtin +S-1-5-32-556 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Network Configuration Operators +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +84 + + +Security +informant-PC + + +Power Users +Builtin +S-1-5-32-547 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +85 + + +Security +informant-PC + + +Power Users +Power Users +Builtin +S-1-5-32-547 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +86 + + +Security +informant-PC + + +Power Users +Builtin +S-1-5-32-547 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Power Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +87 + + +Security +informant-PC + + +Performance Monitor Users +Builtin +S-1-5-32-558 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +88 + + +Security +informant-PC + + +Performance Monitor Users +Performance Monitor Users +Builtin +S-1-5-32-558 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +89 + + +Security +informant-PC + + +Performance Monitor Users +Builtin +S-1-5-32-558 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Performance Monitor Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +90 + + +Security +informant-PC + + +Performance Log Users +Builtin +S-1-5-32-559 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +91 + + +Security +informant-PC + + +Performance Log Users +Performance Log Users +Builtin +S-1-5-32-559 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +92 + + +Security +informant-PC + + +Performance Log Users +Builtin +S-1-5-32-559 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Performance Log Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +93 + + +Security +informant-PC + + +Distributed COM Users +Builtin +S-1-5-32-562 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +94 + + +Security +informant-PC + + +Distributed COM Users +Distributed COM Users +Builtin +S-1-5-32-562 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +95 + + +Security +informant-PC + + +Distributed COM Users +Builtin +S-1-5-32-562 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Distributed COM Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +96 + + +Security +informant-PC + + +IIS_IUSRS +Builtin +S-1-5-32-568 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +97 + + +Security +informant-PC + + +IIS_IUSRS +IIS_IUSRS +Builtin +S-1-5-32-568 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +98 + + +Security +informant-PC + + +IIS_IUSRS +Builtin +S-1-5-32-568 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +IIS_IUSRS +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +99 + + +Security +informant-PC + + +Cryptographic Operators +Builtin +S-1-5-32-569 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +100 + + +Security +informant-PC + + +Cryptographic Operators +Cryptographic Operators +Builtin +S-1-5-32-569 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +101 + + +Security +informant-PC + + +Cryptographic Operators +Builtin +S-1-5-32-569 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Cryptographic Operators +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +102 + + +Security +informant-PC + + +Event Log Readers +Builtin +S-1-5-32-573 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +103 + + +Security +informant-PC + + +Event Log Readers +Event Log Readers +Builtin +S-1-5-32-573 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +104 + + +Security +informant-PC + + +Event Log Readers +Builtin +S-1-5-32-573 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Event Log Readers +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +105 + + +Security +informant-PC + + +- +Administrator +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-500 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Administrator +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +11/20/2010 8:57:24 PM +%%1794 +513 +- +0x211 +0x211 +- +%%1793 +- +%%1797 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +106 + + +Security +informant-PC + + +- +Administrator +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-500 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Administrator +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +11/20/2010 8:57:24 PM +%%1794 +513 +- +0x211 +0x211 +- +%%1793 +- +%%1797 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +107 + + +Security +informant-PC + + +- +Guest +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-501 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Guest +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x215 +0x215 +- +%%1793 +- +%%1797 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +108 + + +Security +informant-PC + + +- +Guest +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-501 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Guest +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x215 +0x215 +- +%%1793 +- +%%1797 + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +109 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +2015-03-25 10:34:25.685648 +2015-03-22 14:33:53.237000 +0x0000000000000340 +C:\Windows\System32\oobe\msoobe.exe + + + + +4728 +0 +0 +13826 +0 +0x8020000000000000 + +110 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1000 +None +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-513 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4720 +0 +0 +13824 +0 +0x8020000000000000 + +111 + + +Security +informant-PC + + +informant +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1000 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +informant +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x0 +0x15 + + %%2080 + %%2082 + %%2084 +%%1793 +- +%%1797 + + + + +4732 +0 +0 +13826 +0 +0x8020000000000000 + +112 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1000 +Users +Builtin +S-1-5-32-545 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4722 +0 +0 +13824 +0 +0x8020000000000000 + +113 + + +Security +informant-PC + + +informant +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1000 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +114 + + +Security +informant-PC + + +- +informant +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1000 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +informant +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x15 +0x14 + + %%2048 +%%1793 +- +%%1797 + + + + +4732 +0 +0 +13826 +0 +0x8020000000000000 + +115 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1000 +Administrators +Builtin +S-1-5-32-544 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4733 +0 +0 +13826 +0 +0x8020000000000000 + +116 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1000 +Users +Builtin +S-1-5-32-545 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +117 + + +Security +informant-PC + + +- +informant +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1000 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +informant +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +3/22/2015 10:33:54 AM +%%1794 +513 +- +0x14 +0x214 + + %%2089 +- +- +%%1797 + + + + +4724 +0 +0 +13824 +0 +0x8020000000000000 + +118 + + +Security +informant-PC + + +informant +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1000 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +119 + + +Security +informant-PC + + +- +informant +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1000 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +120 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +121 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +122 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +123 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000003be29 +2 +User32 +Negotiate +WIN-D9RGPJQ68G8 +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +124 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000003db0a +2 +User32 +Negotiate +WIN-D9RGPJQ68G8 +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +125 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000003be29 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +126 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +127 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +128 + + +Security +informant-PC + + + + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +129 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000003db0a + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +130 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +131 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +132 + + +Security +informant-PC + + +0 +0x000000000000b8dc + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +133 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +134 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +135 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +136 + + +Security +informant-PC + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +137 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +138 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +139 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +140 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +141 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +142 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +143 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +144 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +145 + + +Security +informant-PC + + + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +146 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +147 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x000000000001a667 +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +148 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +149 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +150 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +151 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +152 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x0000000000000184 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +153 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000026923 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000184 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +154 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000026951 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000184 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +155 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000026923 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +156 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +157 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +158 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +159 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +160 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +161 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4904 +0 +0 +13568 +0 +0x8020000000000000 + +162 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x0000000000069adb +0x0000000000000bc0 +C:\Windows\System32\VSSVC.exe + + + + +4905 +0 +0 +13568 +0 +0x8020000000000000 + +163 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x0000000000069adb +0x0000000000000bc0 +C:\Windows\System32\VSSVC.exe + + + + +4904 +0 +0 +13568 +0 +0x8020000000000000 + +164 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000000835e3 +0x0000000000000bc0 +C:\Windows\System32\VSSVC.exe + + + + +4905 +0 +0 +13568 +0 +0x8020000000000000 + +165 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000000835e3 +0x0000000000000bc0 +C:\Windows\System32\VSSVC.exe + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +166 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +167 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +168 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +169 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +170 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +171 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +172 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +173 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4904 +0 +0 +13568 +0 +0x8020000000000000 + +174 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000001fa262 +0x0000000000000e6c +C:\Windows\System32\VSSVC.exe + + + + +4905 +0 +0 +13568 +0 +0x8020000000000000 + +175 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000001fa262 +0x0000000000000e6c +C:\Windows\System32\VSSVC.exe + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +176 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +177 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +178 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\winsxs\Temp\PendingRenames\a86dcf49b364d00184220000f80e440b.install.ins +0x00000000000086e8 + +S:ARAI +0x0000000000000ef8 +C:\Windows\servicing\TrustedInstaller.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +179 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\winsxs\Temp\PendingRenames\08cfd149b364d00185220000f80e440b.install.ins +0x00000000000088b0 + +S:ARAI +0x0000000000000ef8 +C:\Windows\servicing\TrustedInstaller.exe + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +180 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000026951 + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +181 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\DWrite.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +182 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d2d1.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +183 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\msmpeg2vdec.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +184 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +185 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d3d10core.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +186 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +187 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +188 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\XpsGdiConverter.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +189 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +190 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d3d10warp.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +191 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +192 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\dxgi.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +193 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\WMPhoto.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +194 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\FntCache.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +195 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +196 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d3d10_1.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +197 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\WindowsCodecsExt.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +198 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +199 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d3d10level9.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +200 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\UIAnimation.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +201 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +202 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d3d10_1core.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +203 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\XpsPrint.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +204 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +205 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d3d10.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +206 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\WindowsCodecs.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +207 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d3d11.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +208 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +209 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +210 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +211 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +212 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +213 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\da-DK\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +214 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\da-DK\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +215 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\da-DK\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +216 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\da-DK\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +217 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nb-NO\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +218 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nb-NO\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +219 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nb-NO\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +220 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nb-NO\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +221 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\spp\tokens\ppdlic\msmpeg2vdec-ppdlic.xrm-ms +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +222 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ru-RU\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +223 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ru-RU\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +224 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ru-RU\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +225 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ru-RU\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +226 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ja-JP\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +227 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ja-JP\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +228 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ja-JP\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +229 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ja-JP\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +230 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ja-JP\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +231 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-CN\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +232 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-CN\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +233 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-CN\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +234 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-CN\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +235 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\cs-CZ\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +236 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\cs-CZ\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +237 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\cs-CZ\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +238 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\cs-CZ\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +239 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\de-DE\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +240 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\de-DE\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +241 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\de-DE\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +242 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\de-DE\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +243 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\de-DE\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +244 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-TW\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +245 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-TW\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +246 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-TW\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +247 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-TW\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +248 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\es-ES\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +249 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\es-ES\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +250 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\es-ES\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +251 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\es-ES\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +252 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\es-ES\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +253 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\sv-SE\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +254 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\sv-SE\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +255 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\sv-SE\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +256 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\sv-SE\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +257 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\tr-TR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +258 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\tr-TR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +259 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\tr-TR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +260 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\tr-TR\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +261 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fi-FI\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +262 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fi-FI\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +263 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fi-FI\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +264 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fi-FI\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +265 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fr-FR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +266 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fr-FR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +267 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fr-FR\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +268 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fr-FR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +269 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fr-FR\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +270 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nl-NL\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +271 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nl-NL\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +272 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nl-NL\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +273 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nl-NL\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +274 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nl-NL\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +275 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\el-GR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +276 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\el-GR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +277 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\el-GR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +278 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\el-GR\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +279 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-HK\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +280 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-HK\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +281 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-HK\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +282 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-HK\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +283 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\hu-HU\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +284 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\hu-HU\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +285 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\hu-HU\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +286 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\hu-HU\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +287 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ko-KR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +288 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ko-KR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +289 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ko-KR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +290 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ko-KR\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +291 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pl-PL\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +292 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pl-PL\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +293 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pl-PL\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +294 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pl-PL\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +295 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-PT\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +296 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-PT\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +297 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-PT\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +298 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-PT\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +299 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\it-IT\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +300 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\it-IT\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +301 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\it-IT\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +302 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\it-IT\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +303 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\it-IT\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +304 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-BR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +305 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-BR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +306 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-BR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +307 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-BR\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +308 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\DWrite.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +309 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d2d1.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +310 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\msmpeg2vdec.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +311 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +312 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d3d10core.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +313 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +314 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +315 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\XpsGdiConverter.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +316 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +317 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d3d10warp.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +318 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\dxgi.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +319 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +320 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\WMPhoto.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +321 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +322 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d3d10_1.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +323 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d3d10level9.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +324 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\WindowsCodecsExt.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +325 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +326 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +327 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\UIAnimation.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +328 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d3d10_1core.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +329 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\XpsPrint.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +330 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +331 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d3d10.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +332 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\WindowsCodecs.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +333 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d3d11.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +334 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +335 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +336 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +337 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +338 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\da-DK\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +339 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\da-DK\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +340 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\da-DK\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +341 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\nb-NO\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +342 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\nb-NO\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +343 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\nb-NO\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +344 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\spp\tokens\ppdlic\msmpeg2vdec-ppdlic.xrm-ms +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +345 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ru-RU\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +346 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ru-RU\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +347 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ru-RU\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +348 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ja-JP\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +349 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ja-JP\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +350 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ja-JP\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +351 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ja-JP\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +352 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-CN\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +353 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-CN\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +354 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-CN\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +355 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\cs-CZ\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +356 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\cs-CZ\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +357 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\cs-CZ\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +358 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\de-DE\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +359 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\de-DE\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +360 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\de-DE\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +361 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\de-DE\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +362 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-TW\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +363 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-TW\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +364 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-TW\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +365 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\es-ES\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +366 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\es-ES\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +367 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\es-ES\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +368 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\es-ES\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +369 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\sv-SE\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +370 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\sv-SE\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +371 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\sv-SE\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +372 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\tr-TR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +373 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\tr-TR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +374 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\tr-TR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +375 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\fi-FI\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +376 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\fi-FI\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +377 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\fi-FI\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +378 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\fr-FR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +379 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\fr-FR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +380 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\fr-FR\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +381 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\fr-FR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +382 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\nl-NL\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +383 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\nl-NL\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +384 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\nl-NL\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +385 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\nl-NL\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +386 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\el-GR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +387 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\el-GR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +388 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\el-GR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +389 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-HK\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +390 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-HK\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +391 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-HK\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +392 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\hu-HU\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +393 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\hu-HU\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +394 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\hu-HU\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +395 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ko-KR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +396 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ko-KR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +397 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ko-KR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +398 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pl-PL\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +399 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pl-PL\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +400 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pl-PL\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +401 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pt-PT\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +402 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pt-PT\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +403 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pt-PT\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +404 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\it-IT\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +405 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\it-IT\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +406 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\it-IT\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +407 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\it-IT\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +408 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pt-BR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +409 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pt-BR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +410 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pt-BR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +411 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ntoskrnl.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +412 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntoskrnl.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +413 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntkrnlpa.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +414 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\AppPatch\acwow64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +415 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +416 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +417 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +418 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +419 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +420 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64cpu.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +421 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +422 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +423 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +424 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +425 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +426 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +427 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +428 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ntvdm64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +429 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +430 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +431 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +432 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +433 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +434 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +435 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\conhost.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +436 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +437 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +438 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +439 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64win.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +440 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +441 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\kernel32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +442 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\KernelBase.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +443 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +444 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +445 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +446 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +447 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\winsrv.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +448 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +449 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +450 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +451 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +452 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +453 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\setup16.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +454 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\user.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +455 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +456 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntvdm64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +457 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +458 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +459 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +460 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +461 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +462 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +463 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +464 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +465 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +466 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\instnm.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +467 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +468 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +469 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +470 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +471 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +472 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +473 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\kernel32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +474 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +475 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +476 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +477 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +478 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +479 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\KernelBase.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +480 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +481 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +482 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +483 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +484 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +485 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\wow32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +486 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\AppPatch\acwow64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +487 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +488 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +489 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +490 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +491 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +492 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64cpu.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +493 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +494 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +495 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +496 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +497 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +498 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +499 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +500 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ntvdm64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +501 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +502 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +503 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +504 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +505 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +506 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +507 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\conhost.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +508 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +509 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +510 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +511 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64win.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +512 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +513 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\kernel32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +514 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\KernelBase.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +515 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +516 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +517 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +518 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +519 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\winsrv.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +520 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +521 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +522 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +523 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\KernelBase.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +524 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\instnm.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +525 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +526 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +527 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +528 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +529 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\user.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +530 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +531 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +532 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +533 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +534 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +535 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +536 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +537 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntvdm64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +538 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +539 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +540 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +541 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +542 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +543 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +544 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\wow32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +545 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +546 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +547 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +548 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +549 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\kernel32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +550 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\KernelBase.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +551 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +552 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +553 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +554 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +555 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +556 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\setup16.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +557 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +558 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +559 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\KernelBase.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +560 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Fonts\seguisym.ttf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +561 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Fonts\segoeui.ttf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +562 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Fonts\segoeuiz.ttf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +563 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Fonts\segoeuib.ttf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +564 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Fonts\segoeuii.ttf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +565 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\taskhost.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +566 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\drivers\afd.sys +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +567 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\drivers\FWPKCLNT.SYS +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +568 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\drivers\tcpip.sys +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +569 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\drivers\netio.sys +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +570 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\mswsock.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +571 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\mswsock.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +572 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\smss.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +573 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\csrsrv.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +574 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ntdll.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +575 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ntoskrnl.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +576 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\apisetschema.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +577 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntdll.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +578 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntoskrnl.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +579 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntkrnlpa.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +580 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\AppPatch\acwow64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +581 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\tdh.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +582 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +583 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +584 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +585 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +586 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +587 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64cpu.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +588 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +589 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +590 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +591 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +592 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +593 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +594 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +595 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ntvdm64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +596 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +597 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +598 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +599 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +600 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +601 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +602 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\conhost.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +603 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +604 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\advapi32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +605 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +606 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +607 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64win.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +608 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +609 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\kernel32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +610 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\KernelBase.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +611 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +612 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +613 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +614 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +615 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\winsrv.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +616 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +617 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +618 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +619 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\instnm.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +620 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\tdh.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +621 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +622 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +623 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +624 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +625 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\user.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +626 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +627 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +628 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +629 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +630 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +631 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +632 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +633 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntvdm64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +634 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +635 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +636 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +637 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +638 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +639 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +640 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\wow32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +641 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +642 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\advapi32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +643 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +644 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +645 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +646 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\KernelBase.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +647 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\kernel32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +648 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +649 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +650 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +651 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +652 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +653 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\setup16.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +654 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +655 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +656 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Common Files\microsoft shared\VGX\VGX.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +657 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\D3DCompiler_47.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +658 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\iexplore.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +659 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\ie9props.propdesc +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +660 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\JSProfilerCore.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +661 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\jsprofilerui.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +662 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\pdm.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +663 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\pdmproxy100.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +664 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\DiagnosticsTap.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +665 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\ExtExport.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +666 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\sqmapi.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +667 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\jsdebuggeride.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +668 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\jsdbgui.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +669 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\msdbg2.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +670 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\networkinspection.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +671 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\iedvtool.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +672 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\ielowutil.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +673 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\ieproxy.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +674 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\ieinstal.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +675 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\F12Tools.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +676 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\IEShims.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +677 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\SIGNUP\install.ins +0x000000000000001c +S:AI + +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +678 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\F12Tools.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +679 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\jsprofilerui.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +680 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\jsdbgui.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +681 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\iedvtool.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +682 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\DiagnosticsTap.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +683 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\ieinstal.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +684 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\eula.rtf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +685 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\networkinspection.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +686 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +687 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +688 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\iexplore.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +689 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\Timeline_is.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +690 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\pdm.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +691 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\msdbg2.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +692 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\Timeline.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +693 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\JSProfilerCore.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +694 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\ielowutil.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +695 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\ieinstal.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +696 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\IEShims.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +697 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\pdmproxy100.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +698 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\perfcore.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +699 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\D3DCompiler_47.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +700 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\iedvtool.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +701 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\ieproxy.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +702 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\DiagnosticsTap.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +703 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\iediagcmd.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +704 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\perf_nt.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +705 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\DiagnosticsHub.DataWarehouse.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +706 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\F12Tools.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +707 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\jsdebuggeride.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +708 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\networkinspection.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +709 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\jsprofilerui.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +710 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\DiagnosticsHub.ScriptedSandboxPlugin.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +711 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\MemoryAnalyzer.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +712 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\F12Resources.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +713 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\ie9props.propdesc +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +714 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\jsdbgui.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +715 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\F12.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +716 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\DiagnosticsHub_is.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +717 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\Timeline.cpu.xml +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +718 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\sqmapi.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +719 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\jsprofilerui.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +720 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\F12Tools.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +721 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\F12.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +722 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\jsdbgui.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +723 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\iedvtool.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +724 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\F12Resources.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +725 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\ieinstal.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +726 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\DiagnosticsTap.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +727 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\networkinspection.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +728 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\eula.rtf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +729 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +730 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\images\bing.ico +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +731 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\SIGNUP\install.ins +0x000000000000001c +S:AI + +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +732 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieapfltr.dat +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +733 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\url.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +734 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\mshta.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +735 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\jsproxy.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +736 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieUnatt.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +737 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieui.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +738 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\mshtmlmedia.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +739 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieetwproxystub.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +740 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\jsIntl.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +741 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\RegisterIEPKEYs.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +742 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\iepeers.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +743 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\elshyph.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +744 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieframe.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +745 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ie4uinit.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +746 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\licmgr10.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +747 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\mshtmler.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +748 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\iexpress.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +749 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\IEAdvpack.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +750 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\dxtrans.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +751 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wextract.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +752 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieetwcollectorres.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +753 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\SetIEInstalledDate.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +754 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wininet.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +755 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\MshtmlDac.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +756 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\jscript.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +757 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\JavaScriptCollectionAgent.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +758 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\msfeedssync.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +759 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\webcheck.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +760 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\MsSpellCheckingFacility.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +761 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\icardie.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +762 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\iertutil.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +763 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pngfilt.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +764 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\msls31.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +765 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieetwcollector.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +766 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\jscript9diag.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +767 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\iedkcs32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +768 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\iesetup.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +769 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\iernonce.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +770 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\vbscript.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +771 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\inseng.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +772 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\iesysprep.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +773 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\inetcpl.cpl +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +774 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\jscript9.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +775 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\occache.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +776 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieapfltr.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +777 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\html.iec +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +778 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\imgutil.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +779 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\msfeeds.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +780 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieuinit.inf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +781 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\tdc.ocx +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +782 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\mshtml.tlb +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +783 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\mshtml.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +784 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\mshtmled.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +785 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\urlmon.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +786 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\msfeedsbs.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +787 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\msrating.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +788 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\dxtmsft.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +789 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\iesetup.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +790 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\mshtmlmedia.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +791 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\icardie.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +792 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\iepeers.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +793 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\IEAdvpack.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +794 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\jsIntl.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +795 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\occache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +796 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\MsSpellCheckingFacility.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +797 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\wextract.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +798 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\ieunatt.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +799 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\ie4uinit.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +800 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\iernonce.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +801 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\elshyph.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +802 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\jscript.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +803 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\msrating.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +804 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\ieframe.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +805 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\msfeedsbs.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +806 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\vbscript.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +807 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\ieui.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +808 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\html.iec.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +809 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\iexpress.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +810 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\mshtmler.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +811 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\urlmon.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +812 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\jscript9.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +813 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\iedkcs32.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +814 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\webcheck.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +815 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\wininet.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +816 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\mshta.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +817 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\licmgr10.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +818 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\mshtml.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +819 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\inseng.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +820 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\inetcpl.cpl.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +821 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\ieetwcollectorres.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +822 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\spp\tokens\ppdlic\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +823 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wdi\perftrack\Microsoft-Windows-IE-HTMLRendering.ptxml +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +824 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wdi\perftrack\ieframe.ptxml +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +825 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wdi\perftrack\Microsoft-Windows-IE-F12-Provider.ptxml +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +826 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\migration\WininetPlugin.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +827 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\PolicyDefinitions\inetres.admx +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +828 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\PolicyDefinitions\en-US\InetRes.adml +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +829 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ieapfltr.dat +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +830 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\mshta.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +831 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\jsproxy.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +832 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\url.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +833 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ieUnatt.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +834 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ieui.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +835 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\mshtmlmedia.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +836 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\jsIntl.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +837 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ieetwproxystub.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +838 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\RegisterIEPKEYs.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +839 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\elshyph.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +840 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\iepeers.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +841 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ieframe.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +842 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\licmgr10.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +843 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\mshtmler.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +844 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\iexpress.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +845 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\IEAdvpack.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +846 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\wextract.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +847 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\dxtrans.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +848 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\wininet.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +849 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\SetIEInstalledDate.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +850 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\MshtmlDac.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +851 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\jscript.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +852 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +853 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\msfeedssync.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +854 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\webcheck.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +855 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\icardie.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +856 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\iertutil.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +857 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pngfilt.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +858 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\jscript9diag.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +859 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\msls31.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +860 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\iedkcs32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +861 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\iesetup.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +862 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\iernonce.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +863 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\vbscript.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +864 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\iesysprep.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +865 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\inseng.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +866 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\jscript9.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +867 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\occache.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +868 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\inetcpl.cpl +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +869 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ieapfltr.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +870 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\html.iec +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +871 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\imgutil.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +872 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\msfeeds.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +873 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ieuinit.inf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +874 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\tdc.ocx +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +875 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\mshtml.tlb +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +876 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\mshtml.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +877 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\mshtmled.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +878 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\urlmon.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +879 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\msfeedsbs.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +880 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\msrating.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +881 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\dxtmsft.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +882 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\webcheck.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +883 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\iernonce.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +884 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\inseng.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +885 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\html.iec.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +886 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\msrating.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +887 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\wininet.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +888 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\ieui.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +889 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\elshyph.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +890 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\iexpress.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +891 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\ieetwcollectorres.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +892 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\occache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +893 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\ieframe.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +894 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\mshta.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +895 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\mshtml.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +896 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\wextract.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +897 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\iesetup.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +898 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\ieunatt.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +899 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\licmgr10.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +900 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\mshtmler.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +901 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\jscript.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +902 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\vbscript.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +903 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\iepeers.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +904 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\IEAdvpack.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +905 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\msfeedsbs.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +906 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\mshtmlmedia.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +907 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\iedkcs32.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +908 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\urlmon.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +909 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\inetcpl.cpl.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +910 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\jscript9.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +911 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\icardie.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +912 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\wdi\perftrack\wow64_ieframe.ptxml +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +913 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\wdi\perftrack\wow64_Microsoft-Windows-IE-HTMLRendering.ptxml +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +914 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\migration\WininetPlugin.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +915 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.acl +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +916 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.dub +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +917 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.lex +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +918 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Globalization\ELS\HyphenationDictionaries\MsHy7en.lex +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +919 + + +Security +informant-PC + + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +920 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +921 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +922 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +923 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +924 + + +Security +informant-PC + + +0 +0x000000000000c957 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +925 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +926 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +927 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +928 + + +Security +informant-PC + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +929 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +930 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +931 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +932 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +933 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +934 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +935 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +936 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +937 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +938 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +939 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +940 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x000000000001a427 +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +941 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +942 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +943 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +944 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Globalization\ELS\HyphenationDictionaries +0x00000000000002d4 + +S:ARAI(AU;SAFA;0x1f0116;;;WD) +0x00000000000003e8 +C:\Windows\servicing\TrustedInstaller.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +945 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Globalization\ELS\SpellDictionaries +0x00000000000002d0 + +S:ARAI(AU;SAFA;0x1f0116;;;WD) +0x00000000000003e8 +C:\Windows\servicing\TrustedInstaller.exe + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +946 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +947 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000056f8b +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +948 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000056fb9 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +949 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000056f8b +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +950 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +951 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +952 + + +Security +informant-PC + + + + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +953 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000056fb9 + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +954 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +955 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +956 + + +Security +informant-PC + + +0 +0x000000000000c54c + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +957 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +958 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +959 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +960 + + +Security +informant-PC + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +961 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +962 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +963 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +964 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +965 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +966 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +967 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +968 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +969 + + +Security +informant-PC + + + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +970 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +971 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x000000000001c185 +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +972 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +973 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +974 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000022517 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +975 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +976 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +977 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +978 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +979 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +980 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +981 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +982 + + +Security +informant-PC + + +- +informant +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1000 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000022517 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4728 +0 +0 +13826 +0 +0x8020000000000000 + +983 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1001 +None +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-513 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4720 +0 +0 +13824 +0 +0x8020000000000000 + +984 + + +Security +informant-PC + + +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +admin11 +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x0 +0x15 + + %%2080 + %%2082 + %%2084 +%%1793 +- +%%1797 + + + + +4722 +0 +0 +13824 +0 +0x8020000000000000 + +985 + + +Security +informant-PC + + +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +986 + + +Security +informant-PC + + +- +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +admin11 +admin11 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x15 +0x210 + + %%2048 + %%2050 + %%2089 +%%1793 +- +%%1797 + + + + +4732 +0 +0 +13826 +0 +0x8020000000000000 + +987 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1001 +Users +Builtin +S-1-5-32-545 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +988 + + +Security +informant-PC + + +- +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4732 +0 +0 +13826 +0 +0x8020000000000000 + +989 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1001 +Administrators +Builtin +S-1-5-32-544 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +990 + + +Security +informant-PC + + +- +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +admin11 +admin11 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x210 +0x210 +- +%%1793 +- +%%1797 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +991 + + +Security +informant-PC + + +- +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +admin11 +admin11 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +3/22/2015 11:52:10 AM +%%1794 +513 +- +0x210 +0x210 +- +- +- +%%1797 + + + + +4724 +0 +0 +13824 +0 +0x8020000000000000 + +992 + + +Security +informant-PC + + +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +993 + + +Security +informant-PC + + +- +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4728 +0 +0 +13826 +0 +0x8020000000000000 + +994 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1002 +None +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-513 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4720 +0 +0 +13824 +0 +0x8020000000000000 + +995 + + +Security +informant-PC + + +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +ITechTeam +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x0 +0x15 + + %%2080 + %%2082 + %%2084 +%%1793 +- +%%1797 + + + + +4722 +0 +0 +13824 +0 +0x8020000000000000 + +996 + + +Security +informant-PC + + +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +997 + + +Security +informant-PC + + +- +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +ITechTeam +ITechTeam +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x15 +0x210 + + %%2048 + %%2050 + %%2089 +%%1793 +- +%%1797 + + + + +4732 +0 +0 +13826 +0 +0x8020000000000000 + +998 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1002 +Users +Builtin +S-1-5-32-545 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +999 + + +Security +informant-PC + + +- +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4732 +0 +0 +13826 +0 +0x8020000000000000 + +1000 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1002 +Administrators +Builtin +S-1-5-32-544 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1001 + + +Security +informant-PC + + +- +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +ITechTeam +ITechTeam +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x210 +0x210 +- +%%1793 +- +%%1797 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1002 + + +Security +informant-PC + + +- +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +ITechTeam +ITechTeam +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +3/22/2015 11:52:45 AM +%%1794 +513 +- +0x210 +0x210 +- +- +- +%%1797 + + + + +4724 +0 +0 +13824 +0 +0x8020000000000000 + +1003 + + +Security +informant-PC + + +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1004 + + +Security +informant-PC + + +- +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4728 +0 +0 +13826 +0 +0x8020000000000000 + +1005 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1003 +None +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-513 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4720 +0 +0 +13824 +0 +0x8020000000000000 + +1006 + + +Security +informant-PC + + +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +temporary +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x0 +0x15 + + %%2080 + %%2082 + %%2084 +%%1793 +- +%%1797 + + + + +4722 +0 +0 +13824 +0 +0x8020000000000000 + +1007 + + +Security +informant-PC + + +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1008 + + +Security +informant-PC + + +- +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +temporary +temporary +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x15 +0x210 + + %%2048 + %%2050 + %%2089 +%%1793 +- +%%1797 + + + + +4732 +0 +0 +13826 +0 +0x8020000000000000 + +1009 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1003 +Users +Builtin +S-1-5-32-545 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1010 + + +Security +informant-PC + + +- +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1011 + + +Security +informant-PC + + +- +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +temporary +temporary +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x210 +0x210 +- +%%1793 +- +%%1797 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1012 + + +Security +informant-PC + + +- +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +temporary +temporary +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +3/22/2015 11:53:11 AM +%%1794 +513 +- +0x210 +0x210 +- +- +- +%%1797 + + + + +4724 +0 +0 +13824 +0 +0x8020000000000000 + +1013 + + +Security +informant-PC + + +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1014 + + +Security +informant-PC + + +- +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1015 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +admin11 +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x00000000000007a0 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1016 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x0000000000094b57 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000007a0 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1017 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x0000000000094b71 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000007a0 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1018 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x0000000000094b57 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +1019 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x0000000000094b71 + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1020 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +temporary +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x000000000000072c +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1021 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1003 +temporary +informant-PC +0x00000000000f2cd6 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x000000000000072c +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1022 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x0000000000094b71 +2 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1023 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x0000000000094b57 +2 + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +1024 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1003 +temporary +informant-PC +0x00000000000f2cd6 + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1025 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +admin11 +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x0000000000000954 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1026 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x00000000001354b3 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000954 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1027 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x00000000001354c8 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000954 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1028 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x00000000001354b3 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +1029 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x00000000001354c8 + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1030 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x0000000000000c1c +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1031 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157b62 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000c1c +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1032 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157b78 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000c1c +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1033 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157b62 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1034 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157b78 +2 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1035 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157b62 +2 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1036 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1003 +temporary +informant-PC +0x00000000000f2cd6 +2 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1037 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x00000000001354c8 +2 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1038 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x00000000001354b3 +2 + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +1039 + + +Security +informant-PC + + + + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +1040 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000022517 + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +1041 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1042 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +1043 + + +Security +informant-PC + + +0 +0x000000000000bac4 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1044 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1045 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1046 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1047 + + +Security +informant-PC + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1048 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1049 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1050 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1051 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1052 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1053 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1054 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1055 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +1056 + + +Security +informant-PC + + + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +1057 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1058 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x000000000001b9a4 +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1059 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x00000000000001a8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1060 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000002359c +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001a8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1061 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000235cc +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001a8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1062 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000002359c +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1063 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1064 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +1065 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +2015-03-23 17:25:47.192598 +2015-03-23 17:25:47.191999 +0x0000000000000358 +C:\Windows\System32\svchost.exe + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1066 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1067 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1068 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1069 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +1070 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +2015-03-23 18:57:01.113134 +2015-03-23 19:08:15.571480 +0x0000000000000358 +C:\Windows\System32\svchost.exe + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +1071 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +2015-03-23 19:08:15.571480 +2015-03-23 19:08:15.570999 +0x0000000000000358 +C:\Windows\System32\svchost.exe + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +1072 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +2015-03-23 19:08:46.443419 +2015-03-23 19:08:46.442999 +0x0000000000000358 +C:\Windows\System32\svchost.exe + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1073 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1074 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1075 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1076 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1077 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1078 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1079 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1080 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4904 +0 +0 +13568 +0 +0x8020000000000000 + +1081 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000002c2083 +0x0000000000000d40 +C:\Windows\System32\VSSVC.exe + + + + +4905 +0 +0 +13568 +0 +0x8020000000000000 + +1082 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000002c2083 +0x0000000000000d40 +C:\Windows\System32\VSSVC.exe + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1083 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000235cc +{00000000-0000-0000-0000-000000000000} +Company +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +Company-PC +Company-PC +0x0000000000000004 + +- +- + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +1084 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000235cc + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +1085 + + +Security +informant-PC + + + + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +1086 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1087 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +1088 + + +Security +informant-PC + + +0 +0x000000000000b683 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1089 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1090 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1091 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1092 + + +Security +informant-PC + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1093 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1094 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1095 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1096 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1097 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1098 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1099 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1100 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +1101 + + +Security +informant-PC + + + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +1102 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1103 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x000000000001c0ce +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1104 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1105 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000002269c +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1106 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000226c4 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1107 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000002269c +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1108 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1109 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1110 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1111 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1112 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000226c4 +{00000000-0000-0000-0000-000000000000} +Company +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +Company-PC +Company-PC +0x0000000000000004 + +- +- + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1113 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1114 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1115 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1116 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1117 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1118 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1119 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1120 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1121 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1122 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1123 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1124 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000006cabcf +7 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1125 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000006cabdd +7 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1126 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000006cabcf +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1127 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000006cabdd +7 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1128 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000006cabcf +7 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1129 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1130 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +1131 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000226c4 + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +1132 + + +Security +informant-PC + + + + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +1133 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1134 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +1135 + + +Security +informant-PC + + +0 +0x000000000000ba7d + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1136 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1137 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1138 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1139 + + +Security +informant-PC + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1140 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1141 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1142 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1143 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1144 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1145 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1146 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1147 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +1148 + + +Security +informant-PC + + + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +1149 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1150 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x000000000001c0d1 +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1151 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1152 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000025465 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1153 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000025493 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1154 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000025465 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1155 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1156 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1157 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1158 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1159 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1160 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +1161 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +2015-03-25 13:29:46.566790 +2015-03-25 14:13:47.009901 +0x0000000000000330 +C:\Windows\System32\svchost.exe + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +1162 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +2015-03-25 14:13:47.025499 +2015-03-25 14:13:47.025000 +0x0000000000000330 +C:\Windows\System32\svchost.exe + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1163 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1164 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1165 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1166 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157773 +7 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1167 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000015777f +7 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1168 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157773 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1169 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000015777f +7 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1170 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157773 +7 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1171 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1172 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1173 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1174 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1175 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1176 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4904 +0 +0 +13568 +0 +0x8020000000000000 + +1177 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000001aa8e7 +0x0000000000000934 +C:\Windows\System32\VSSVC.exe + + + + +4905 +0 +0 +13568 +0 +0x8020000000000000 + +1178 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000001aa8e7 +0x0000000000000934 +C:\Windows\System32\VSSVC.exe + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1179 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1180 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1181 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1182 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1183 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1184 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1185 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1186 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4904 +0 +0 +13568 +0 +0x8020000000000000 + +1187 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x0000000000245dcb +0x0000000000000aa4 +C:\Windows\System32\VSSVC.exe + + + + +4905 +0 +0 +13568 +0 +0x8020000000000000 + +1188 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x0000000000245dcb +0x0000000000000aa4 +C:\Windows\System32\VSSVC.exe + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1189 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1190 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +1191 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000025493 + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +1192 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +2015-03-25 15:31:00.240004 +2015-03-25 15:31:00.240000 +0x0000000000000330 +C:\Windows\System32\svchost.exe + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +1193 + + +Security +informant-PC + + + + + + + diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/SecurityEvt_ns_removed.xml b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/SecurityEvt_ns_removed.xml new file mode 100644 index 0000000..cc35c57 --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/SecurityEvt_ns_removed.xml @@ -0,0 +1,36682 @@ + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +1 + + +Security +37L4247F27-25 + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +2 + + +Security +37L4247F27-25 + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +3 + + +Security +37L4247F27-25 + + +0 +0x0000000000035ce9 + + + + +4731 +0 +0 +13826 +0 +0x8020000000000000 + +4 + + +Security +37L4247F27-25 + + +Backup Operators +Builtin +S-1-5-32-551 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +Backup Operators +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +5 + + +Security +37L4247F27-25 + + +Backup Operators +Builtin +S-1-5-32-551 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4731 +0 +0 +13826 +0 +0x8020000000000000 + +6 + + +Security +37L4247F27-25 + + +Replicator +Builtin +S-1-5-32-552 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +Replicator +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +7 + + +Security +37L4247F27-25 + + +Replicator +Builtin +S-1-5-32-552 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4731 +0 +0 +13826 +0 +0x8020000000000000 + +8 + + +Security +37L4247F27-25 + + +Remote Desktop Users +Builtin +S-1-5-32-555 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +Remote Desktop Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +9 + + +Security +37L4247F27-25 + + +Remote Desktop Users +Builtin +S-1-5-32-555 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4731 +0 +0 +13826 +0 +0x8020000000000000 + +10 + + +Security +37L4247F27-25 + + +Network Configuration Operators +Builtin +S-1-5-32-556 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +Network Configuration Operators +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +11 + + +Security +37L4247F27-25 + + +Network Configuration Operators +Builtin +S-1-5-32-556 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4731 +0 +0 +13826 +0 +0x8020000000000000 + +12 + + +Security +37L4247F27-25 + + +Power Users +Builtin +S-1-5-32-547 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +Power Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +13 + + +Security +37L4247F27-25 + + +Power Users +Builtin +S-1-5-32-547 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4731 +0 +0 +13826 +0 +0x8020000000000000 + +14 + + +Security +37L4247F27-25 + + +Cryptographic Operators +Builtin +S-1-5-32-569 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +Cryptographic Operators +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +15 + + +Security +37L4247F27-25 + + +Cryptographic Operators +Builtin +S-1-5-32-569 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +16 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +17 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +18 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +19 + + +Security +37L4247F27-25 + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +20 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +21 + + +Security +37L4247F27-25 + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +22 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +23 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +24 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +25 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +26 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +27 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +28 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +29 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +30 + + +Security +37L4247F27-25 + + + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +31 + + +Security +37L4247F27-25 + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +32 + + +Security +37L4247F27-25 + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x00000000000454a7 +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +33 + + +Security +37L4247F27-25 + + +- +Administrator +37L4247F27-25 +S-1-5-21-2425377081-3129163575-2985601102-500 +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +- +- +- +- +- +- +- +- +- +- +- +- +- +0x211 +0x211 +- +- +- +- + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +34 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +35 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +36 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +37 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +38 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +39 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +40 + + +Security +37L4247F27-25 + + +S-1-5-18 +37L4247F27-25$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +41 + + +Security +37L4247F27-25 + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +42 + + +Security +37L4247F27-25 + + + + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +43 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +44 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +45 + + +Security +informant-PC + + +0 +0x000000000000d031 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +46 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +47 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +48 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +49 + + +Security +informant-PC + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +50 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +51 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +52 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +53 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +54 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +55 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +56 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +57 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +58 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +59 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +60 + + +Security +informant-PC + + + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +61 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +62 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x0000000000028c63 +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +63 + + +Security +informant-PC + + +Administrators +Builtin +S-1-5-32-544 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +64 + + +Security +informant-PC + + +Administrators +Administrators +Builtin +S-1-5-32-544 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +65 + + +Security +informant-PC + + +Administrators +Builtin +S-1-5-32-544 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Administrators +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +66 + + +Security +informant-PC + + +Users +Builtin +S-1-5-32-545 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +67 + + +Security +informant-PC + + +Users +Users +Builtin +S-1-5-32-545 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +68 + + +Security +informant-PC + + +Users +Builtin +S-1-5-32-545 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +69 + + +Security +informant-PC + + +Guests +Builtin +S-1-5-32-546 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +70 + + +Security +informant-PC + + +Guests +Guests +Builtin +S-1-5-32-546 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +71 + + +Security +informant-PC + + +Guests +Builtin +S-1-5-32-546 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Guests +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +72 + + +Security +informant-PC + + +Backup Operators +Builtin +S-1-5-32-551 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +73 + + +Security +informant-PC + + +Backup Operators +Backup Operators +Builtin +S-1-5-32-551 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +74 + + +Security +informant-PC + + +Backup Operators +Builtin +S-1-5-32-551 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Backup Operators +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +75 + + +Security +informant-PC + + +Replicator +Builtin +S-1-5-32-552 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +76 + + +Security +informant-PC + + +Replicator +Replicator +Builtin +S-1-5-32-552 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +77 + + +Security +informant-PC + + +Replicator +Builtin +S-1-5-32-552 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Replicator +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +78 + + +Security +informant-PC + + +Remote Desktop Users +Builtin +S-1-5-32-555 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +79 + + +Security +informant-PC + + +Remote Desktop Users +Remote Desktop Users +Builtin +S-1-5-32-555 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +80 + + +Security +informant-PC + + +Remote Desktop Users +Builtin +S-1-5-32-555 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Remote Desktop Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +81 + + +Security +informant-PC + + +Network Configuration Operators +Builtin +S-1-5-32-556 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +82 + + +Security +informant-PC + + +Network Configuration Operators +Network Configuration Operators +Builtin +S-1-5-32-556 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +83 + + +Security +informant-PC + + +Network Configuration Operators +Builtin +S-1-5-32-556 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Network Configuration Operators +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +84 + + +Security +informant-PC + + +Power Users +Builtin +S-1-5-32-547 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +85 + + +Security +informant-PC + + +Power Users +Power Users +Builtin +S-1-5-32-547 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +86 + + +Security +informant-PC + + +Power Users +Builtin +S-1-5-32-547 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Power Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +87 + + +Security +informant-PC + + +Performance Monitor Users +Builtin +S-1-5-32-558 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +88 + + +Security +informant-PC + + +Performance Monitor Users +Performance Monitor Users +Builtin +S-1-5-32-558 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +89 + + +Security +informant-PC + + +Performance Monitor Users +Builtin +S-1-5-32-558 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Performance Monitor Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +90 + + +Security +informant-PC + + +Performance Log Users +Builtin +S-1-5-32-559 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +91 + + +Security +informant-PC + + +Performance Log Users +Performance Log Users +Builtin +S-1-5-32-559 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +92 + + +Security +informant-PC + + +Performance Log Users +Builtin +S-1-5-32-559 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Performance Log Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +93 + + +Security +informant-PC + + +Distributed COM Users +Builtin +S-1-5-32-562 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +94 + + +Security +informant-PC + + +Distributed COM Users +Distributed COM Users +Builtin +S-1-5-32-562 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +95 + + +Security +informant-PC + + +Distributed COM Users +Builtin +S-1-5-32-562 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Distributed COM Users +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +96 + + +Security +informant-PC + + +IIS_IUSRS +Builtin +S-1-5-32-568 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +97 + + +Security +informant-PC + + +IIS_IUSRS +IIS_IUSRS +Builtin +S-1-5-32-568 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +98 + + +Security +informant-PC + + +IIS_IUSRS +Builtin +S-1-5-32-568 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +IIS_IUSRS +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +99 + + +Security +informant-PC + + +Cryptographic Operators +Builtin +S-1-5-32-569 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +100 + + +Security +informant-PC + + +Cryptographic Operators +Cryptographic Operators +Builtin +S-1-5-32-569 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +101 + + +Security +informant-PC + + +Cryptographic Operators +Builtin +S-1-5-32-569 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Cryptographic Operators +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +102 + + +Security +informant-PC + + +Event Log Readers +Builtin +S-1-5-32-573 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- + + + + +4781 +0 +0 +13824 +0 +0x8020000000000000 + +103 + + +Security +informant-PC + + +Event Log Readers +Event Log Readers +Builtin +S-1-5-32-573 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4735 +0 +0 +13826 +0 +0x8020000000000000 + +104 + + +Security +informant-PC + + +Event Log Readers +Builtin +S-1-5-32-573 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Event Log Readers +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +105 + + +Security +informant-PC + + +- +Administrator +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-500 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Administrator +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +11/20/2010 8:57:24 PM +%%1794 +513 +- +0x211 +0x211 +- +%%1793 +- +%%1797 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +106 + + +Security +informant-PC + + +- +Administrator +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-500 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Administrator +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +11/20/2010 8:57:24 PM +%%1794 +513 +- +0x211 +0x211 +- +%%1793 +- +%%1797 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +107 + + +Security +informant-PC + + +- +Guest +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-501 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Guest +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x215 +0x215 +- +%%1793 +- +%%1797 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +108 + + +Security +informant-PC + + +- +Guest +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-501 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +Guest +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x215 +0x215 +- +%%1793 +- +%%1797 + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +109 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +2015-03-25 10:34:25.685648 +2015-03-22 14:33:53.237000 +0x0000000000000340 +C:\Windows\System32\oobe\msoobe.exe + + + + +4728 +0 +0 +13826 +0 +0x8020000000000000 + +110 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1000 +None +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-513 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4720 +0 +0 +13824 +0 +0x8020000000000000 + +111 + + +Security +informant-PC + + +informant +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1000 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +informant +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x0 +0x15 + + %%2080 + %%2082 + %%2084 +%%1793 +- +%%1797 + + + + +4732 +0 +0 +13826 +0 +0x8020000000000000 + +112 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1000 +Users +Builtin +S-1-5-32-545 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4722 +0 +0 +13824 +0 +0x8020000000000000 + +113 + + +Security +informant-PC + + +informant +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1000 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +114 + + +Security +informant-PC + + +- +informant +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1000 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +informant +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x15 +0x14 + + %%2048 +%%1793 +- +%%1797 + + + + +4732 +0 +0 +13826 +0 +0x8020000000000000 + +115 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1000 +Administrators +Builtin +S-1-5-32-544 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4733 +0 +0 +13826 +0 +0x8020000000000000 + +116 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1000 +Users +Builtin +S-1-5-32-545 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +117 + + +Security +informant-PC + + +- +informant +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1000 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +informant +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +3/22/2015 10:33:54 AM +%%1794 +513 +- +0x14 +0x214 + + %%2089 +- +- +%%1797 + + + + +4724 +0 +0 +13824 +0 +0x8020000000000000 + +118 + + +Security +informant-PC + + +informant +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1000 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +119 + + +Security +informant-PC + + +- +informant +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1000 +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +120 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +121 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +122 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +123 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000003be29 +2 +User32 +Negotiate +WIN-D9RGPJQ68G8 +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +124 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000003db0a +2 +User32 +Negotiate +WIN-D9RGPJQ68G8 +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +125 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000003be29 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +126 + + +Security +informant-PC + + +S-1-5-18 +WIN-D9RGPJQ68G8$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +127 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +128 + + +Security +informant-PC + + + + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +129 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000003db0a + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +130 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +131 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +132 + + +Security +informant-PC + + +0 +0x000000000000b8dc + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +133 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +134 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +135 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +136 + + +Security +informant-PC + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +137 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +138 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +139 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +140 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +141 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +142 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +143 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +144 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +145 + + +Security +informant-PC + + + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +146 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +147 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x000000000001a667 +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +148 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +149 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +150 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +151 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +152 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x0000000000000184 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +153 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000026923 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000184 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +154 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000026951 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000184 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +155 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000026923 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +156 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +157 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +158 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +159 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +160 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +161 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4904 +0 +0 +13568 +0 +0x8020000000000000 + +162 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x0000000000069adb +0x0000000000000bc0 +C:\Windows\System32\VSSVC.exe + + + + +4905 +0 +0 +13568 +0 +0x8020000000000000 + +163 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x0000000000069adb +0x0000000000000bc0 +C:\Windows\System32\VSSVC.exe + + + + +4904 +0 +0 +13568 +0 +0x8020000000000000 + +164 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000000835e3 +0x0000000000000bc0 +C:\Windows\System32\VSSVC.exe + + + + +4905 +0 +0 +13568 +0 +0x8020000000000000 + +165 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000000835e3 +0x0000000000000bc0 +C:\Windows\System32\VSSVC.exe + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +166 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +167 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +168 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +169 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +170 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +171 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +172 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +173 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4904 +0 +0 +13568 +0 +0x8020000000000000 + +174 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000001fa262 +0x0000000000000e6c +C:\Windows\System32\VSSVC.exe + + + + +4905 +0 +0 +13568 +0 +0x8020000000000000 + +175 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000001fa262 +0x0000000000000e6c +C:\Windows\System32\VSSVC.exe + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +176 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +177 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +178 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\winsxs\Temp\PendingRenames\a86dcf49b364d00184220000f80e440b.install.ins +0x00000000000086e8 + +S:ARAI +0x0000000000000ef8 +C:\Windows\servicing\TrustedInstaller.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +179 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\winsxs\Temp\PendingRenames\08cfd149b364d00185220000f80e440b.install.ins +0x00000000000088b0 + +S:ARAI +0x0000000000000ef8 +C:\Windows\servicing\TrustedInstaller.exe + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +180 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000026951 + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +181 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\DWrite.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +182 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d2d1.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +183 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\msmpeg2vdec.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +184 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +185 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d3d10core.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +186 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +187 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +188 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\XpsGdiConverter.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +189 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +190 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d3d10warp.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +191 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +192 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\dxgi.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +193 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\WMPhoto.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +194 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\FntCache.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +195 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +196 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d3d10_1.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +197 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\WindowsCodecsExt.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +198 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +199 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d3d10level9.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +200 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\UIAnimation.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +201 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +202 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d3d10_1core.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +203 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\XpsPrint.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +204 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +205 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d3d10.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +206 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\WindowsCodecs.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +207 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\d3d11.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +208 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +209 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +210 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +211 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +212 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +213 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\da-DK\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +214 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\da-DK\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +215 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\da-DK\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +216 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\da-DK\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +217 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nb-NO\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +218 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nb-NO\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +219 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nb-NO\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +220 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nb-NO\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +221 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\spp\tokens\ppdlic\msmpeg2vdec-ppdlic.xrm-ms +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +222 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ru-RU\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +223 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ru-RU\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +224 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ru-RU\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +225 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ru-RU\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +226 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ja-JP\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +227 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ja-JP\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +228 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ja-JP\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +229 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ja-JP\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +230 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ja-JP\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +231 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-CN\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +232 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-CN\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +233 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-CN\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +234 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-CN\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +235 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\cs-CZ\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +236 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\cs-CZ\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +237 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\cs-CZ\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +238 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\cs-CZ\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +239 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\de-DE\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +240 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\de-DE\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +241 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\de-DE\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +242 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\de-DE\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +243 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\de-DE\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +244 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-TW\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +245 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-TW\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +246 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-TW\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +247 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-TW\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +248 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\es-ES\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +249 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\es-ES\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +250 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\es-ES\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +251 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\es-ES\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +252 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\es-ES\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +253 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\sv-SE\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +254 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\sv-SE\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +255 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\sv-SE\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +256 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\sv-SE\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +257 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\tr-TR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +258 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\tr-TR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +259 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\tr-TR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +260 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\tr-TR\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +261 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fi-FI\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +262 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fi-FI\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +263 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fi-FI\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +264 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fi-FI\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +265 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fr-FR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +266 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fr-FR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +267 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fr-FR\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +268 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fr-FR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +269 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\fr-FR\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +270 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nl-NL\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +271 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nl-NL\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +272 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nl-NL\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +273 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nl-NL\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +274 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\nl-NL\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +275 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\el-GR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +276 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\el-GR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +277 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\el-GR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +278 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\el-GR\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +279 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-HK\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +280 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-HK\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +281 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-HK\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +282 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\zh-HK\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +283 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\hu-HU\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +284 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\hu-HU\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +285 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\hu-HU\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +286 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\hu-HU\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +287 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ko-KR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +288 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ko-KR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +289 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ko-KR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +290 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ko-KR\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +291 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pl-PL\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +292 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pl-PL\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +293 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pl-PL\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +294 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pl-PL\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +295 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-PT\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +296 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-PT\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +297 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-PT\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +298 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-PT\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +299 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\it-IT\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +300 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\it-IT\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +301 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\it-IT\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +302 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\it-IT\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +303 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\it-IT\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +304 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-BR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +305 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-BR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +306 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-BR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +307 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pt-BR\FntCache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +308 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\DWrite.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +309 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d2d1.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +310 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\msmpeg2vdec.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +311 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +312 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d3d10core.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +313 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +314 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +315 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\XpsGdiConverter.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +316 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +317 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d3d10warp.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +318 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\dxgi.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +319 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +320 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\WMPhoto.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +321 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +322 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d3d10_1.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +323 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d3d10level9.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +324 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\WindowsCodecsExt.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +325 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +326 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +327 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\UIAnimation.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +328 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d3d10_1core.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +329 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\XpsPrint.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +330 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +331 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d3d10.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +332 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\WindowsCodecs.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +333 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\d3d11.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +334 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +335 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +336 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +337 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +338 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\da-DK\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +339 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\da-DK\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +340 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\da-DK\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +341 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\nb-NO\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +342 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\nb-NO\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +343 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\nb-NO\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +344 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\spp\tokens\ppdlic\msmpeg2vdec-ppdlic.xrm-ms +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +345 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ru-RU\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +346 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ru-RU\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +347 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ru-RU\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +348 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ja-JP\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +349 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ja-JP\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +350 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ja-JP\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +351 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ja-JP\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +352 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-CN\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +353 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-CN\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +354 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-CN\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +355 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\cs-CZ\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +356 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\cs-CZ\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +357 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\cs-CZ\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +358 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\de-DE\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +359 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\de-DE\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +360 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\de-DE\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +361 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\de-DE\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +362 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-TW\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +363 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-TW\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +364 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-TW\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +365 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\es-ES\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +366 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\es-ES\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +367 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\es-ES\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +368 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\es-ES\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +369 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\sv-SE\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +370 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\sv-SE\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +371 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\sv-SE\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +372 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\tr-TR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +373 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\tr-TR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +374 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\tr-TR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +375 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\fi-FI\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +376 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\fi-FI\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +377 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\fi-FI\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +378 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\fr-FR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +379 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\fr-FR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +380 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\fr-FR\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +381 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\fr-FR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +382 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\nl-NL\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +383 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\nl-NL\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +384 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\nl-NL\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +385 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\nl-NL\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +386 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\el-GR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +387 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\el-GR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +388 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\el-GR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +389 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-HK\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +390 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-HK\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +391 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\zh-HK\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +392 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\hu-HU\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +393 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\hu-HU\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +394 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\hu-HU\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +395 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ko-KR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +396 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ko-KR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +397 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ko-KR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +398 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pl-PL\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +399 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pl-PL\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +400 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pl-PL\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +401 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pt-PT\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +402 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pt-PT\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +403 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pt-PT\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +404 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\it-IT\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +405 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\it-IT\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +406 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\it-IT\UIAnimation.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +407 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\it-IT\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +408 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pt-BR\WMPhoto.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +409 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pt-BR\d2d1.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +410 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pt-BR\DWrite.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +411 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ntoskrnl.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +412 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntoskrnl.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +413 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntkrnlpa.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +414 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\AppPatch\acwow64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +415 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +416 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +417 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +418 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +419 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +420 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64cpu.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +421 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +422 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +423 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +424 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +425 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +426 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +427 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +428 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ntvdm64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +429 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +430 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +431 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +432 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +433 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +434 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +435 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\conhost.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +436 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +437 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +438 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +439 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64win.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +440 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +441 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\kernel32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +442 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\KernelBase.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +443 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +444 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +445 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +446 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +447 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\winsrv.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +448 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +449 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +450 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +451 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +452 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +453 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\setup16.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +454 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\user.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +455 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +456 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntvdm64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +457 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +458 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +459 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +460 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +461 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +462 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +463 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +464 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +465 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +466 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\instnm.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +467 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +468 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +469 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +470 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +471 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +472 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +473 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\kernel32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +474 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +475 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +476 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +477 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +478 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +479 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\KernelBase.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +480 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +481 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +482 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +483 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +484 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +485 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\wow32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +486 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\AppPatch\acwow64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +487 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +488 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +489 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +490 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +491 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +492 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64cpu.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +493 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +494 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +495 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +496 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +497 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +498 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +499 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +500 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ntvdm64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +501 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +502 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +503 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +504 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +505 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +506 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +507 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\conhost.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +508 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +509 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +510 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +511 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64win.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +512 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +513 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\kernel32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +514 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\KernelBase.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +515 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +516 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +517 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +518 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +519 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\winsrv.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +520 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +521 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +522 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +523 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\KernelBase.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +524 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\instnm.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +525 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +526 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +527 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +528 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +529 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\user.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +530 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +531 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +532 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +533 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +534 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +535 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +536 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +537 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntvdm64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +538 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +539 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +540 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +541 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +542 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +543 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +544 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\wow32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +545 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +546 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +547 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +548 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +549 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\kernel32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +550 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\KernelBase.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +551 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +552 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +553 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +554 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +555 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +556 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\setup16.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +557 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +558 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +559 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\KernelBase.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +560 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Fonts\seguisym.ttf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +561 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Fonts\segoeui.ttf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +562 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Fonts\segoeuiz.ttf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +563 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Fonts\segoeuib.ttf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +564 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Fonts\segoeuii.ttf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +565 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\taskhost.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +566 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\drivers\afd.sys +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +567 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\drivers\FWPKCLNT.SYS +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +568 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\drivers\tcpip.sys +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +569 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\drivers\netio.sys +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +570 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\mswsock.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +571 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\mswsock.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +572 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\smss.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +573 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\csrsrv.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +574 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ntdll.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +575 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ntoskrnl.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +576 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\apisetschema.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +577 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntdll.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +578 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntoskrnl.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +579 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntkrnlpa.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +580 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\AppPatch\acwow64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +581 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\tdh.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +582 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +583 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +584 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +585 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +586 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +587 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64cpu.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +588 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +589 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +590 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +591 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +592 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +593 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +594 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +595 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ntvdm64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +596 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +597 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +598 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +599 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +600 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +601 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +602 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\conhost.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +603 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +604 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\advapi32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +605 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +606 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +607 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wow64win.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +608 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +609 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\kernel32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +610 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\KernelBase.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +611 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +612 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +613 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +614 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +615 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\winsrv.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +616 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +617 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +618 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +619 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\instnm.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +620 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\tdh.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +621 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +622 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +623 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +624 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +625 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\user.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +626 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +627 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +628 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +629 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +630 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +631 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +632 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +633 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ntvdm64.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +634 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +635 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +636 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +637 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +638 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +639 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +640 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\wow32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +641 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +642 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\advapi32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +643 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +644 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +645 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +646 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\KernelBase.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +647 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\kernel32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +648 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +649 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +650 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +651 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +652 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +653 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\setup16.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +654 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +655 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +656 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Common Files\microsoft shared\VGX\VGX.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +657 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\D3DCompiler_47.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +658 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\iexplore.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +659 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\ie9props.propdesc +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +660 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\JSProfilerCore.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +661 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\jsprofilerui.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +662 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\pdm.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +663 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\pdmproxy100.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +664 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\DiagnosticsTap.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +665 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\ExtExport.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +666 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\sqmapi.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +667 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\jsdebuggeride.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +668 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\jsdbgui.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +669 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\msdbg2.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +670 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\networkinspection.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +671 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\iedvtool.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +672 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\ielowutil.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +673 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\ieproxy.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +674 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\ieinstal.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +675 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\F12Tools.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +676 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\IEShims.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +677 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\SIGNUP\install.ins +0x000000000000001c +S:AI + +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +678 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\F12Tools.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +679 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\jsprofilerui.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +680 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\jsdbgui.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +681 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\iedvtool.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +682 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\DiagnosticsTap.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +683 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\ieinstal.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +684 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\eula.rtf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +685 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\networkinspection.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +686 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +687 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +688 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\iexplore.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +689 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\Timeline_is.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +690 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\pdm.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +691 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\msdbg2.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +692 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\Timeline.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +693 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\JSProfilerCore.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +694 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\ielowutil.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +695 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\ieinstal.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +696 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\IEShims.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +697 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\pdmproxy100.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +698 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\perfcore.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +699 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\D3DCompiler_47.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +700 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\iedvtool.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +701 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\ieproxy.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +702 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\DiagnosticsTap.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +703 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\iediagcmd.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +704 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\perf_nt.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +705 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\DiagnosticsHub.DataWarehouse.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +706 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\F12Tools.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +707 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\jsdebuggeride.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +708 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\networkinspection.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +709 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\jsprofilerui.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +710 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\DiagnosticsHub.ScriptedSandboxPlugin.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +711 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\MemoryAnalyzer.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +712 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\F12Resources.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +713 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\ie9props.propdesc +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +714 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\jsdbgui.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +715 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\F12.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +716 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\DiagnosticsHub_is.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +717 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\Timeline.cpu.xml +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +718 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\sqmapi.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +719 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\jsprofilerui.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +720 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\F12Tools.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +721 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\F12.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +722 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\jsdbgui.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +723 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\iedvtool.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +724 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\F12Resources.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +725 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\ieinstal.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +726 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\DiagnosticsTap.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +727 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\networkinspection.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +728 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\eula.rtf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +729 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +730 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\images\bing.ico +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +731 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Program Files\Internet Explorer\SIGNUP\install.ins +0x000000000000001c +S:AI + +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +732 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieapfltr.dat +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +733 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\url.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +734 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\mshta.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +735 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\jsproxy.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +736 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieUnatt.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +737 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieui.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +738 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\mshtmlmedia.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +739 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieetwproxystub.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +740 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\jsIntl.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +741 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\RegisterIEPKEYs.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +742 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\iepeers.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +743 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\elshyph.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +744 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieframe.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +745 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ie4uinit.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +746 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\licmgr10.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +747 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\mshtmler.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +748 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\iexpress.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +749 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\IEAdvpack.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +750 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\dxtrans.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +751 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wextract.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +752 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieetwcollectorres.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +753 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\SetIEInstalledDate.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +754 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wininet.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +755 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\MshtmlDac.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +756 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\jscript.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +757 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\JavaScriptCollectionAgent.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +758 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\msfeedssync.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +759 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\webcheck.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +760 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\MsSpellCheckingFacility.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +761 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\icardie.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +762 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\iertutil.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +763 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\pngfilt.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +764 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\msls31.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +765 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieetwcollector.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +766 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\jscript9diag.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +767 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\iedkcs32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +768 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\iesetup.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +769 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\iernonce.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +770 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\vbscript.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +771 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\inseng.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +772 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\iesysprep.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +773 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\inetcpl.cpl +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +774 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\jscript9.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +775 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\occache.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +776 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieapfltr.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +777 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\html.iec +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +778 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\imgutil.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +779 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\msfeeds.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +780 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\ieuinit.inf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +781 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\tdc.ocx +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +782 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\mshtml.tlb +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +783 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\mshtml.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +784 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\mshtmled.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +785 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\urlmon.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +786 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\msfeedsbs.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +787 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\msrating.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +788 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\dxtmsft.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +789 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\iesetup.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +790 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\mshtmlmedia.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +791 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\icardie.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +792 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\iepeers.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +793 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\IEAdvpack.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +794 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\jsIntl.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +795 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\occache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +796 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\MsSpellCheckingFacility.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +797 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\wextract.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +798 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\ieunatt.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +799 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\ie4uinit.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +800 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\iernonce.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +801 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\elshyph.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +802 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\jscript.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +803 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\msrating.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +804 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\ieframe.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +805 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\msfeedsbs.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +806 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\vbscript.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +807 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\ieui.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +808 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\html.iec.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +809 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\iexpress.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +810 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\mshtmler.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +811 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\urlmon.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +812 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\jscript9.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +813 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\iedkcs32.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +814 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\webcheck.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +815 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\wininet.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +816 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\mshta.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +817 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\licmgr10.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +818 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\mshtml.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +819 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\inseng.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +820 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\inetcpl.cpl.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +821 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\en-US\ieetwcollectorres.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +822 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\spp\tokens\ppdlic\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +823 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wdi\perftrack\Microsoft-Windows-IE-HTMLRendering.ptxml +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +824 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wdi\perftrack\ieframe.ptxml +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +825 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\wdi\perftrack\Microsoft-Windows-IE-F12-Provider.ptxml +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +826 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\System32\migration\WininetPlugin.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +827 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\PolicyDefinitions\inetres.admx +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +828 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\PolicyDefinitions\en-US\InetRes.adml +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +829 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ieapfltr.dat +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +830 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\mshta.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +831 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\jsproxy.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +832 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\url.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +833 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ieUnatt.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +834 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ieui.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +835 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\mshtmlmedia.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +836 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\jsIntl.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +837 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ieetwproxystub.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +838 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\RegisterIEPKEYs.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +839 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\elshyph.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +840 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\iepeers.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +841 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ieframe.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +842 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\licmgr10.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +843 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\mshtmler.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +844 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\iexpress.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +845 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\IEAdvpack.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +846 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\wextract.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +847 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\dxtrans.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +848 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\wininet.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +849 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\SetIEInstalledDate.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +850 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\MshtmlDac.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +851 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\jscript.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +852 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +853 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\msfeedssync.exe +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +854 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\webcheck.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +855 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\icardie.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +856 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\iertutil.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +857 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\pngfilt.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +858 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\jscript9diag.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +859 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\msls31.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +860 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\iedkcs32.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +861 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\iesetup.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +862 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\iernonce.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +863 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\vbscript.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +864 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\iesysprep.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +865 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\inseng.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +866 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\jscript9.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +867 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\occache.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +868 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\inetcpl.cpl +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +869 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ieapfltr.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +870 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\html.iec +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +871 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\imgutil.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +872 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\msfeeds.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +873 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\ieuinit.inf +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +874 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\tdc.ocx +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +875 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\mshtml.tlb +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +876 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\mshtml.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +877 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\mshtmled.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +878 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\urlmon.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +879 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\msfeedsbs.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +880 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\msrating.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +881 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\dxtmsft.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +882 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\webcheck.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +883 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\iernonce.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +884 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\inseng.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +885 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\html.iec.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +886 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\msrating.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +887 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\wininet.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +888 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\ieui.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +889 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\elshyph.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +890 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\iexpress.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +891 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\ieetwcollectorres.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +892 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\occache.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +893 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\ieframe.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +894 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\mshta.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +895 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\mshtml.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +896 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\wextract.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +897 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\iesetup.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +898 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\ieunatt.exe.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +899 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\licmgr10.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +900 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\mshtmler.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +901 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\jscript.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +902 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\vbscript.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +903 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\iepeers.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +904 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\IEAdvpack.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +905 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\msfeedsbs.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +906 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\mshtmlmedia.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +907 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\iedkcs32.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +908 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\urlmon.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +909 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\inetcpl.cpl.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +910 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\jscript9.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +911 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\en-US\icardie.dll.mui +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +912 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\wdi\perftrack\wow64_ieframe.ptxml +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +913 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\wdi\perftrack\wow64_Microsoft-Windows-IE-HTMLRendering.ptxml +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +914 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\SysWOW64\migration\WininetPlugin.dll +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +915 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.acl +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +916 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.dub +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +917 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.lex +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +918 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Globalization\ELS\HyphenationDictionaries\MsHy7en.lex +0x000000000000001c + +S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) +0x0000000000000cdc +C:\Windows\System32\poqexec.exe + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +919 + + +Security +informant-PC + + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +920 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001c0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +921 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +922 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +923 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +924 + + +Security +informant-PC + + +0 +0x000000000000c957 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +925 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +926 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +927 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +928 + + +Security +informant-PC + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +929 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +930 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +931 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +932 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +933 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +934 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +935 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +936 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +937 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +938 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +939 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +940 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x000000000001a427 +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +941 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +942 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +943 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +944 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Globalization\ELS\HyphenationDictionaries +0x00000000000002d4 + +S:ARAI(AU;SAFA;0x1f0116;;;WD) +0x00000000000003e8 +C:\Windows\servicing\TrustedInstaller.exe + + + + +4907 +0 +0 +13568 +0 +0x8020000000000000 + +945 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +Security +File +C:\Windows\Globalization\ELS\SpellDictionaries +0x00000000000002d0 + +S:ARAI(AU;SAFA;0x1f0116;;;WD) +0x00000000000003e8 +C:\Windows\servicing\TrustedInstaller.exe + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +946 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +947 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000056f8b +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +948 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000056fb9 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +949 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000056f8b +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +950 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +951 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +952 + + +Security +informant-PC + + + + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +953 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000056fb9 + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +954 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +955 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +956 + + +Security +informant-PC + + +0 +0x000000000000c54c + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +957 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +958 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +959 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +960 + + +Security +informant-PC + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +961 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +962 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +963 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +964 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +965 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +966 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +967 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +968 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +969 + + +Security +informant-PC + + + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +970 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +971 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x000000000001c185 +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +972 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +973 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +974 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000022517 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +975 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +976 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +977 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +978 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +979 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +980 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +981 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +982 + + +Security +informant-PC + + +- +informant +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1000 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000022517 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4728 +0 +0 +13826 +0 +0x8020000000000000 + +983 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1001 +None +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-513 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4720 +0 +0 +13824 +0 +0x8020000000000000 + +984 + + +Security +informant-PC + + +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +admin11 +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x0 +0x15 + + %%2080 + %%2082 + %%2084 +%%1793 +- +%%1797 + + + + +4722 +0 +0 +13824 +0 +0x8020000000000000 + +985 + + +Security +informant-PC + + +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +986 + + +Security +informant-PC + + +- +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +admin11 +admin11 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x15 +0x210 + + %%2048 + %%2050 + %%2089 +%%1793 +- +%%1797 + + + + +4732 +0 +0 +13826 +0 +0x8020000000000000 + +987 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1001 +Users +Builtin +S-1-5-32-545 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +988 + + +Security +informant-PC + + +- +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4732 +0 +0 +13826 +0 +0x8020000000000000 + +989 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1001 +Administrators +Builtin +S-1-5-32-544 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +990 + + +Security +informant-PC + + +- +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +admin11 +admin11 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x210 +0x210 +- +%%1793 +- +%%1797 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +991 + + +Security +informant-PC + + +- +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +admin11 +admin11 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +3/22/2015 11:52:10 AM +%%1794 +513 +- +0x210 +0x210 +- +- +- +%%1797 + + + + +4724 +0 +0 +13824 +0 +0x8020000000000000 + +992 + + +Security +informant-PC + + +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +993 + + +Security +informant-PC + + +- +admin11 +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1001 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4728 +0 +0 +13826 +0 +0x8020000000000000 + +994 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1002 +None +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-513 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4720 +0 +0 +13824 +0 +0x8020000000000000 + +995 + + +Security +informant-PC + + +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +ITechTeam +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x0 +0x15 + + %%2080 + %%2082 + %%2084 +%%1793 +- +%%1797 + + + + +4722 +0 +0 +13824 +0 +0x8020000000000000 + +996 + + +Security +informant-PC + + +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +997 + + +Security +informant-PC + + +- +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +ITechTeam +ITechTeam +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x15 +0x210 + + %%2048 + %%2050 + %%2089 +%%1793 +- +%%1797 + + + + +4732 +0 +0 +13826 +0 +0x8020000000000000 + +998 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1002 +Users +Builtin +S-1-5-32-545 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +999 + + +Security +informant-PC + + +- +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4732 +0 +0 +13826 +0 +0x8020000000000000 + +1000 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1002 +Administrators +Builtin +S-1-5-32-544 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1001 + + +Security +informant-PC + + +- +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +ITechTeam +ITechTeam +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x210 +0x210 +- +%%1793 +- +%%1797 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1002 + + +Security +informant-PC + + +- +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +ITechTeam +ITechTeam +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +3/22/2015 11:52:45 AM +%%1794 +513 +- +0x210 +0x210 +- +- +- +%%1797 + + + + +4724 +0 +0 +13824 +0 +0x8020000000000000 + +1003 + + +Security +informant-PC + + +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1004 + + +Security +informant-PC + + +- +ITechTeam +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1002 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4728 +0 +0 +13826 +0 +0x8020000000000000 + +1005 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1003 +None +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-513 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4720 +0 +0 +13824 +0 +0x8020000000000000 + +1006 + + +Security +informant-PC + + +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +temporary +%%1793 +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x0 +0x15 + + %%2080 + %%2082 + %%2084 +%%1793 +- +%%1797 + + + + +4722 +0 +0 +13824 +0 +0x8020000000000000 + +1007 + + +Security +informant-PC + + +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1008 + + +Security +informant-PC + + +- +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +temporary +temporary +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x15 +0x210 + + %%2048 + %%2050 + %%2089 +%%1793 +- +%%1797 + + + + +4732 +0 +0 +13826 +0 +0x8020000000000000 + +1009 + + +Security +informant-PC + + +- +S-1-5-21-2425377081-3129163575-2985601102-1003 +Users +Builtin +S-1-5-32-545 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1010 + + +Security +informant-PC + + +- +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1011 + + +Security +informant-PC + + +- +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +temporary +temporary +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +%%1794 +%%1794 +513 +- +0x210 +0x210 +- +%%1793 +- +%%1797 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1012 + + +Security +informant-PC + + +- +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +temporary +temporary +- +%%1793 +%%1793 +%%1793 +%%1793 +%%1793 +3/22/2015 11:53:11 AM +%%1794 +513 +- +0x210 +0x210 +- +- +- +%%1797 + + + + +4724 +0 +0 +13824 +0 +0x8020000000000000 + +1013 + + +Security +informant-PC + + +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 + + + + +4738 +0 +0 +13824 +0 +0x8020000000000000 + +1014 + + +Security +informant-PC + + +- +temporary +informant-PC +S-1-5-21-2425377081-3129163575-2985601102-1003 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000224e3 +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1015 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +admin11 +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x00000000000007a0 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1016 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x0000000000094b57 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000007a0 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1017 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x0000000000094b71 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000007a0 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1018 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x0000000000094b57 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +1019 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x0000000000094b71 + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1020 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +temporary +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x000000000000072c +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1021 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1003 +temporary +informant-PC +0x00000000000f2cd6 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x000000000000072c +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1022 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x0000000000094b71 +2 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1023 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x0000000000094b57 +2 + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +1024 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1003 +temporary +informant-PC +0x00000000000f2cd6 + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1025 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +admin11 +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x0000000000000954 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1026 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x00000000001354b3 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000954 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1027 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x00000000001354c8 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000954 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1028 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x00000000001354b3 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +1029 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x00000000001354c8 + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1030 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x0000000000000c1c +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1031 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157b62 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000c1c +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1032 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157b78 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000c1c +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1033 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157b62 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1034 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157b78 +2 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1035 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157b62 +2 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1036 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1003 +temporary +informant-PC +0x00000000000f2cd6 +2 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1037 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x00000000001354c8 +2 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1038 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1001 +admin11 +informant-PC +0x00000000001354b3 +2 + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +1039 + + +Security +informant-PC + + + + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +1040 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000022517 + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +1041 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1042 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +1043 + + +Security +informant-PC + + +0 +0x000000000000bac4 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1044 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1045 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1046 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1047 + + +Security +informant-PC + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1048 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1049 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1050 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1051 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1052 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1053 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1054 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1055 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +1056 + + +Security +informant-PC + + + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +1057 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1058 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x000000000001b9a4 +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1059 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x00000000000001a8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1060 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000002359c +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001a8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1061 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000235cc +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001a8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1062 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000002359c +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1063 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1064 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +1065 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +2015-03-23 17:25:47.192598 +2015-03-23 17:25:47.191999 +0x0000000000000358 +C:\Windows\System32\svchost.exe + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1066 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1067 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1068 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1069 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +1070 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +2015-03-23 18:57:01.113134 +2015-03-23 19:08:15.571480 +0x0000000000000358 +C:\Windows\System32\svchost.exe + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +1071 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +2015-03-23 19:08:15.571480 +2015-03-23 19:08:15.570999 +0x0000000000000358 +C:\Windows\System32\svchost.exe + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +1072 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +2015-03-23 19:08:46.443419 +2015-03-23 19:08:46.442999 +0x0000000000000358 +C:\Windows\System32\svchost.exe + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1073 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1074 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1075 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1076 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1077 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1078 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1079 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e4 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1080 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4904 +0 +0 +13568 +0 +0x8020000000000000 + +1081 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000002c2083 +0x0000000000000d40 +C:\Windows\System32\VSSVC.exe + + + + +4905 +0 +0 +13568 +0 +0x8020000000000000 + +1082 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000002c2083 +0x0000000000000d40 +C:\Windows\System32\VSSVC.exe + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1083 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000235cc +{00000000-0000-0000-0000-000000000000} +Company +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +Company-PC +Company-PC +0x0000000000000004 + +- +- + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +1084 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000235cc + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +1085 + + +Security +informant-PC + + + + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +1086 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1087 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +1088 + + +Security +informant-PC + + +0 +0x000000000000b683 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1089 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1090 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1091 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1092 + + +Security +informant-PC + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1093 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1094 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1095 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1096 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1097 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1098 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1099 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1100 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +1101 + + +Security +informant-PC + + + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +1102 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1103 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x000000000001c0ce +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1104 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1105 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000002269c +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1106 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000226c4 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1107 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000002269c +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1108 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1109 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1110 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1111 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1112 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000226c4 +{00000000-0000-0000-0000-000000000000} +Company +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +Company-PC +Company-PC +0x0000000000000004 + +- +- + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1113 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1114 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1115 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1116 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1117 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1118 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1119 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1120 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1121 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1122 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1123 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1124 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000006cabcf +7 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1125 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000006cabdd +7 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001b8 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1126 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000006cabcf +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1127 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000006cabdd +7 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1128 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000006cabcf +7 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1129 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001e8 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1130 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +1131 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x00000000000226c4 + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +1132 + + +Security +informant-PC + + + + + + + +4608 +0 +0 +12288 +0 +0x8020000000000000 + +1133 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1134 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +0 +- +- +- +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000004 + +- +- + + + + +4902 +0 +0 +13568 +0 +0x8020000000000000 + +1135 + + +Security +informant-PC + + +0 +0x000000000000ba7d + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1136 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1137 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1138 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1139 + + +Security +informant-PC + + +S-1-5-20 +NETWORK SERVICE +NT AUTHORITY +0x00000000000003e4 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1140 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1141 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1142 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1143 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1144 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1145 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1146 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1147 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +5033 +0 +0 +12292 +0 +0x8020000000000000 + +1148 + + +Security +informant-PC + + + + + + +5024 +0 +0 +12292 +0 +0x8020000000000000 + +1149 + + +Security +informant-PC + + + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1150 + + +Security +informant-PC + + +S-1-0-0 +- +- +0x0000000000000000 +S-1-5-7 +ANONYMOUS LOGON +NT AUTHORITY +0x000000000001c0d1 +3 +NtLmSsp +NTLM + +{00000000-0000-0000-0000-000000000000} +- +NTLM V1 +0 +0x0000000000000000 +- +- +- + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1151 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1152 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000025465 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1153 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000025493 +2 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1154 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000025465 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1155 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1156 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1157 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1158 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1159 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1160 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +1161 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +2015-03-25 13:29:46.566790 +2015-03-25 14:13:47.009901 +0x0000000000000330 +C:\Windows\System32\svchost.exe + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +1162 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +2015-03-25 14:13:47.025499 +2015-03-25 14:13:47.025000 +0x0000000000000330 +C:\Windows\System32\svchost.exe + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1163 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1164 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4648 +0 +0 +12544 +0 +0x8020000000000000 + +1165 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +{00000000-0000-0000-0000-000000000000} +informant +informant-PC +{00000000-0000-0000-0000-000000000000} +localhost +localhost +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1166 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157773 +7 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1167 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000015777f +7 +User32 +Negotiate +INFORMANT-PC +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x0000000000000194 +C:\Windows\System32\winlogon.exe +127.0.0.1 +0 + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1168 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157773 +SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1169 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x000000000015777f +7 + + + + +4634 +0 +0 +12545 +0 +0x8020000000000000 + +1170 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000157773 +7 + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1171 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1172 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1173 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1174 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1175 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1176 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4904 +0 +0 +13568 +0 +0x8020000000000000 + +1177 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000001aa8e7 +0x0000000000000934 +C:\Windows\System32\VSSVC.exe + + + + +4905 +0 +0 +13568 +0 +0x8020000000000000 + +1178 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x00000000001aa8e7 +0x0000000000000934 +C:\Windows\System32\VSSVC.exe + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1179 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1180 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1181 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1182 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1183 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1184 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1185 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1186 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4904 +0 +0 +13568 +0 +0x8020000000000000 + +1187 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x0000000000245dcb +0x0000000000000aa4 +C:\Windows\System32\VSSVC.exe + + + + +4905 +0 +0 +13568 +0 +0x8020000000000000 + +1188 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +VSSAudit +0x0000000000245dcb +0x0000000000000aa4 +C:\Windows\System32\VSSVC.exe + + + + +4624 +0 +0 +12544 +0 +0x8020000000000000 + +1189 + + +Security +informant-PC + + +S-1-5-18 +INFORMANT-PC$ +WORKGROUP +0x00000000000003e7 +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +5 +Advapi +Negotiate + +{00000000-0000-0000-0000-000000000000} +- +- +0 +0x00000000000001d0 +C:\Windows\System32\services.exe +- +- + + + + +4672 +0 +0 +12548 +0 +0x8020000000000000 + +1190 + + +Security +informant-PC + + +S-1-5-18 +SYSTEM +NT AUTHORITY +0x00000000000003e7 +SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + +4647 +0 +0 +12545 +0 +0x8020000000000000 + +1191 + + +Security +informant-PC + + +S-1-5-21-2425377081-3129163575-2985601102-1000 +informant +informant-PC +0x0000000000025493 + + + + +4616 +1 +0 +12288 +0 +0x8020000000000000 + +1192 + + +Security +informant-PC + + +S-1-5-19 +LOCAL SERVICE +NT AUTHORITY +0x00000000000003e5 +2015-03-25 15:31:00.240004 +2015-03-25 15:31:00.240000 +0x0000000000000330 +C:\Windows\System32\svchost.exe + + + + +1100 +0 +4 +103 +0 +0x4020000000000000 + +1193 + + +Security +informant-PC + + + + + + + \ No newline at end of file diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore.xml b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore.xml new file mode 100644 index 0000000..3f0376a --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore.xml @@ -0,0 +1,21 @@ + + + + Everyday Italian + Giada De Laurentiis + 2005 + 30.00 + + + Harry Potter + J K. Rowling + 2005 + 29.99 + + + Learning XML + Erik T. Ray + 2003 + 39.95 + + \ No newline at end of file diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_book_category_attrib.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_book_category_attrib.py new file mode 100644 index 0000000..36e0a1f --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_book_category_attrib.py @@ -0,0 +1,10 @@ +import xml.etree.ElementTree as ET + +tree = ET.parse("bookstore_removed_ns.xml") +root = tree.getroot() + +# Iterate through the book elements and print their category attributes +for book in root.findall(".//book"): # Find all 'book' elements at any depth + # Get book category attribute + cate = book.attrib.get("category") + print("book category: {}".format(cate)) diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_tags.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_tags.py new file mode 100644 index 0000000..b760977 --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_tags.py @@ -0,0 +1,16 @@ +import xml.etree.ElementTree as ET + +tree = ET.parse("bookstore.xml") +root = tree.getroot() + +# Create an empty set to store unique tag names +tag_names = set() + +# Iterate through the elements and collect unique tag names +for element in root.iter(): + tag_names.add(element.tag) + +# Convert the set to a sorted list and print the tag names +tag_list = sorted(tag_names) +for tag in tag_list: + print(tag) diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_titles_v1.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_titles_v1.py new file mode 100644 index 0000000..93914fc --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_titles_v1.py @@ -0,0 +1,11 @@ +import xml.etree.ElementTree as ET + +tree = ET.parse("bookstore.xml") +root = tree.getroot() + +# Iterate through the book elements and print their titles +for book in root.findall(".//book"): # Find all 'book' elements at any depth + # Find the first 'title' elements at current depth + title_element = book.find("title") + if title_element is not None: + print("Book Title: {}".format(title_element.text)) diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_titles_v2.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_titles_v2.py new file mode 100644 index 0000000..5dd52b2 --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_titles_v2.py @@ -0,0 +1,8 @@ +import xml.etree.ElementTree as ET + +tree = ET.parse("bookstore.xml") +root = tree.getroot() + +# Find and print all the "year" elements +for title_element in root.findall(".//title"): + print(title_element.text) diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_ns.xml b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_ns.xml new file mode 100644 index 0000000..faba862 --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_ns.xml @@ -0,0 +1,21 @@ + + + + Everyday Italian + Giada De Laurentiis + 2005 + 30.00 + + + Harry Potter + J K. Rowling + 2005 + 29.99 + + + Learning XML + Erik T. Ray + 2003 + 39.95 + + \ No newline at end of file diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_remove_ns.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_remove_ns.py new file mode 100644 index 0000000..a6b4da7 --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_remove_ns.py @@ -0,0 +1,23 @@ +import xml.etree.ElementTree as ET + +tree = ET.parse("bookstore.xml") +root = tree.getroot() + + +# Define a function to recursively remove all namespace prefixes +def remove_namespace_prefix(element): + print(element.tag) + element.tag = element.tag.split("}", 1)[-1] # Remove namespace prefix + for child in element: + remove_namespace_prefix(child) + + +# Remove namespace prefixes from the root element and its descendants +remove_namespace_prefix(root) + +# Convert the modified XML tree to a string +modified_xml = ET.tostring(root, encoding="utf-8") + +# Save the updated XML to a new file +with open("bookstore_removed_ns.xml", "wb") as f: + f.write(modified_xml) diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_removed_ns.xml b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_removed_ns.xml new file mode 100644 index 0000000..92266b6 --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_removed_ns.xml @@ -0,0 +1,20 @@ + + + Everyday Italian + Giada De Laurentiis + 2005 + 30.00 + + + Harry Potter + J K. Rowling + 2005 + 29.99 + + + Learning XML + Erik T. Ray + 2003 + 39.95 + + \ No newline at end of file diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_show_first_book.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_show_first_book.py new file mode 100644 index 0000000..baceb9c --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_show_first_book.py @@ -0,0 +1,12 @@ +import xml.etree.ElementTree as ET + +tree = ET.parse("bookstore.xml") +root = tree.getroot() + +# Access the first child element of the root directly using indexing +first_element = root[0] + +# Print the tag name and text content of the first element +print("Tag Name:", first_element.tag) +for child in first_element: + print(f"{child.tag}: {child.text}") diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_update_one_author.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_update_one_author.py new file mode 100644 index 0000000..c5afd4e --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_update_one_author.py @@ -0,0 +1,15 @@ +import xml.etree.ElementTree as ET + +tree = ET.parse("bookstore.xml") +root = tree.getroot() + +# Find the "author" element with the current name and update it +for author_element in root.findall(".//author"): + if author_element.text == "Giada De Laurentiis": + author_element.text = "Giada Laurentiis" + +# Serialize the updated XML to a string +updated_xml_content = ET.tostring(root, encoding="utf-8") + +# Print the updated XML content +print(updated_xml_content.decode("utf-8")) diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_update_price_plus1.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_update_price_plus1.py new file mode 100644 index 0000000..f3f381d --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_update_price_plus1.py @@ -0,0 +1,17 @@ +import xml.etree.ElementTree as ET + +tree = ET.parse("bookstore.xml") +root = tree.getroot() + +# Find and update all the "price" elements +for price_element in root.findall(".//price"): + current_price = float(price_element.text) + new_price = current_price + 1 + price_element.text = str(new_price) + +# Serialize the updated XML to a string +updated_xml_content = ET.tostring(root, encoding="utf-8") + +# Save the updated XML to a new file +with open("bookstore_updated.xml", "wb") as f: + f.write(updated_xml_content) diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityEvt_formatted.xml b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityEvt_formatted.xml new file mode 100644 index 0000000..a046350 --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityEvt_formatted.xml @@ -0,0 +1,39045 @@ + + + + + + 4608 + 0 + 0 + 12288 + 0 + 0x8020000000000000 + + 1 + + + Security + 37L4247F27-25 + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 2 + + + Security + 37L4247F27-25 + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 0 + - + - + - + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000004 + + - + - + + + + + + 4902 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 3 + + + Security + 37L4247F27-25 + + + + 0 + 0x0000000000035ce9 + + + + + + 4731 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 4 + + + Security + 37L4247F27-25 + + + + Backup Operators + Builtin + S-1-5-32-551 + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + - + Backup Operators + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 5 + + + Security + 37L4247F27-25 + + + + Backup Operators + Builtin + S-1-5-32-551 + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4731 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 6 + + + Security + 37L4247F27-25 + + + + Replicator + Builtin + S-1-5-32-552 + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + - + Replicator + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 7 + + + Security + 37L4247F27-25 + + + + Replicator + Builtin + S-1-5-32-552 + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4731 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 8 + + + Security + 37L4247F27-25 + + + + Remote Desktop Users + Builtin + S-1-5-32-555 + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + - + Remote Desktop Users + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 9 + + + Security + 37L4247F27-25 + + + + Remote Desktop Users + Builtin + S-1-5-32-555 + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4731 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 10 + + + Security + 37L4247F27-25 + + + + Network Configuration Operators + Builtin + S-1-5-32-556 + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + - + Network Configuration Operators + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 11 + + + Security + 37L4247F27-25 + + + + Network Configuration Operators + Builtin + S-1-5-32-556 + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4731 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 12 + + + Security + 37L4247F27-25 + + + + Power Users + Builtin + S-1-5-32-547 + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + - + Power Users + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 13 + + + Security + 37L4247F27-25 + + + + Power Users + Builtin + S-1-5-32-547 + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4731 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 14 + + + Security + 37L4247F27-25 + + + + Cryptographic Operators + Builtin + S-1-5-32-569 + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + - + Cryptographic Operators + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 15 + + + Security + 37L4247F27-25 + + + + Cryptographic Operators + Builtin + S-1-5-32-569 + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 16 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 17 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 18 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 19 + + + Security + 37L4247F27-25 + + + + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 20 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 21 + + + Security + 37L4247F27-25 + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 22 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 23 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 24 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 25 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 26 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 27 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 28 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 29 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 5033 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 30 + + + Security + 37L4247F27-25 + + + + + + + + 5024 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 31 + + + Security + 37L4247F27-25 + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 32 + + + Security + 37L4247F27-25 + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-7 + ANONYMOUS LOGON + NT AUTHORITY + 0x00000000000454a7 + 3 + NtLmSsp + NTLM + + {00000000-0000-0000-0000-000000000000} + - + NTLM V1 + 0 + 0x0000000000000000 + - + - + - + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 33 + + + Security + 37L4247F27-25 + + + + - + Administrator + 37L4247F27-25 + S-1-5-21-2425377081-3129163575-2985601102-500 + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + - + - + - + - + - + - + - + - + - + - + - + - + - + 0x211 + 0x211 + - + - + - + - + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 34 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 35 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 36 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 37 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 38 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 39 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 40 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + 37L4247F27-25$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 41 + + + Security + 37L4247F27-25 + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 1100 + 0 + 4 + 103 + 0 + 0x4020000000000000 + + 42 + + + Security + 37L4247F27-25 + + + + + + + + + + 4608 + 0 + 0 + 12288 + 0 + 0x8020000000000000 + + 43 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 44 + + + Security + informant-PC + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 0 + - + - + - + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000004 + + - + - + + + + + + 4902 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 45 + + + Security + informant-PC + + + + 0 + 0x000000000000d031 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 46 + + + Security + informant-PC + + + + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 47 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 48 + + + Security + informant-PC + + + + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 49 + + + Security + informant-PC + + + + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 50 + + + Security + informant-PC + + + + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 51 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 52 + + + Security + informant-PC + + + + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 53 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 54 + + + Security + informant-PC + + + + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 55 + + + Security + informant-PC + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 56 + + + Security + informant-PC + + + + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 57 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 58 + + + Security + informant-PC + + + + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 59 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 5033 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 60 + + + Security + informant-PC + + + + + + + + 5024 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 61 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 62 + + + Security + informant-PC + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-7 + ANONYMOUS LOGON + NT AUTHORITY + 0x0000000000028c63 + 3 + NtLmSsp + NTLM + + {00000000-0000-0000-0000-000000000000} + - + NTLM V1 + 0 + 0x0000000000000000 + - + - + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 63 + + + Security + informant-PC + + + + Administrators + Builtin + S-1-5-32-544 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4781 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 64 + + + Security + informant-PC + + + + Administrators + Administrators + Builtin + S-1-5-32-544 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 65 + + + Security + informant-PC + + + + Administrators + Builtin + S-1-5-32-544 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Administrators + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 66 + + + Security + informant-PC + + + + Users + Builtin + S-1-5-32-545 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4781 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 67 + + + Security + informant-PC + + + + Users + Users + Builtin + S-1-5-32-545 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 68 + + + Security + informant-PC + + + + Users + Builtin + S-1-5-32-545 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Users + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 69 + + + Security + informant-PC + + + + Guests + Builtin + S-1-5-32-546 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4781 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 70 + + + Security + informant-PC + + + + Guests + Guests + Builtin + S-1-5-32-546 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 71 + + + Security + informant-PC + + + + Guests + Builtin + S-1-5-32-546 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Guests + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 72 + + + Security + informant-PC + + + + Backup Operators + Builtin + S-1-5-32-551 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4781 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 73 + + + Security + informant-PC + + + + Backup Operators + Backup Operators + Builtin + S-1-5-32-551 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 74 + + + Security + informant-PC + + + + Backup Operators + Builtin + S-1-5-32-551 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Backup Operators + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 75 + + + Security + informant-PC + + + + Replicator + Builtin + S-1-5-32-552 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4781 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 76 + + + Security + informant-PC + + + + Replicator + Replicator + Builtin + S-1-5-32-552 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 77 + + + Security + informant-PC + + + + Replicator + Builtin + S-1-5-32-552 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Replicator + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 78 + + + Security + informant-PC + + + + Remote Desktop Users + Builtin + S-1-5-32-555 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4781 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 79 + + + Security + informant-PC + + + + Remote Desktop Users + Remote Desktop Users + Builtin + S-1-5-32-555 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 80 + + + Security + informant-PC + + + + Remote Desktop Users + Builtin + S-1-5-32-555 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Remote Desktop Users + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 81 + + + Security + informant-PC + + + + Network Configuration Operators + Builtin + S-1-5-32-556 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4781 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 82 + + + Security + informant-PC + + + + Network Configuration Operators + Network Configuration Operators + Builtin + S-1-5-32-556 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 83 + + + Security + informant-PC + + + + Network Configuration Operators + Builtin + S-1-5-32-556 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Network Configuration Operators + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 84 + + + Security + informant-PC + + + + Power Users + Builtin + S-1-5-32-547 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4781 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 85 + + + Security + informant-PC + + + + Power Users + Power Users + Builtin + S-1-5-32-547 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 86 + + + Security + informant-PC + + + + Power Users + Builtin + S-1-5-32-547 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Power Users + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 87 + + + Security + informant-PC + + + + Performance Monitor Users + Builtin + S-1-5-32-558 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4781 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 88 + + + Security + informant-PC + + + + Performance Monitor Users + Performance Monitor Users + Builtin + S-1-5-32-558 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 89 + + + Security + informant-PC + + + + Performance Monitor Users + Builtin + S-1-5-32-558 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Performance Monitor Users + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 90 + + + Security + informant-PC + + + + Performance Log Users + Builtin + S-1-5-32-559 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4781 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 91 + + + Security + informant-PC + + + + Performance Log Users + Performance Log Users + Builtin + S-1-5-32-559 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 92 + + + Security + informant-PC + + + + Performance Log Users + Builtin + S-1-5-32-559 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Performance Log Users + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 93 + + + Security + informant-PC + + + + Distributed COM Users + Builtin + S-1-5-32-562 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4781 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 94 + + + Security + informant-PC + + + + Distributed COM Users + Distributed COM Users + Builtin + S-1-5-32-562 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 95 + + + Security + informant-PC + + + + Distributed COM Users + Builtin + S-1-5-32-562 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Distributed COM Users + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 96 + + + Security + informant-PC + + + + IIS_IUSRS + Builtin + S-1-5-32-568 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4781 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 97 + + + Security + informant-PC + + + + IIS_IUSRS + IIS_IUSRS + Builtin + S-1-5-32-568 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 98 + + + Security + informant-PC + + + + IIS_IUSRS + Builtin + S-1-5-32-568 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + IIS_IUSRS + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 99 + + + Security + informant-PC + + + + Cryptographic Operators + Builtin + S-1-5-32-569 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4781 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 100 + + + Security + informant-PC + + + + Cryptographic Operators + Cryptographic Operators + Builtin + S-1-5-32-569 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 101 + + + Security + informant-PC + + + + Cryptographic Operators + Builtin + S-1-5-32-569 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Cryptographic Operators + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 102 + + + Security + informant-PC + + + + Event Log Readers + Builtin + S-1-5-32-573 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + + + + + + 4781 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 103 + + + Security + informant-PC + + + + Event Log Readers + Event Log Readers + Builtin + S-1-5-32-573 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4735 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 104 + + + Security + informant-PC + + + + Event Log Readers + Builtin + S-1-5-32-573 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Event Log Readers + - + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 105 + + + Security + informant-PC + + + + - + Administrator + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-500 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Administrator + %%1793 + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + 11/20/2010 8:57:24 PM + %%1794 + 513 + - + 0x211 + 0x211 + - + %%1793 + - + %%1797 + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 106 + + + Security + informant-PC + + + + - + Administrator + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-500 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Administrator + %%1793 + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + 11/20/2010 8:57:24 PM + %%1794 + 513 + - + 0x211 + 0x211 + - + %%1793 + - + %%1797 + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 107 + + + Security + informant-PC + + + + - + Guest + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-501 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Guest + %%1793 + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + %%1794 + %%1794 + 513 + - + 0x215 + 0x215 + - + %%1793 + - + %%1797 + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 108 + + + Security + informant-PC + + + + - + Guest + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-501 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + Guest + %%1793 + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + %%1794 + %%1794 + 513 + - + 0x215 + 0x215 + - + %%1793 + - + %%1797 + + + + + + 4616 + 1 + 0 + 12288 + 0 + 0x8020000000000000 + + 109 + + + Security + informant-PC + + + + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + 2015-03-25 10:34:25.685648 + 2015-03-22 14:33:53.237000 + 0x0000000000000340 + C:\Windows\System32\oobe\msoobe.exe + + + + + + 4728 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 110 + + + Security + informant-PC + + + + - + S-1-5-21-2425377081-3129163575-2985601102-1000 + None + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-513 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4720 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 111 + + + Security + informant-PC + + + + informant + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1000 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + informant + %%1793 + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + %%1794 + %%1794 + 513 + - + 0x0 + 0x15 + + %%2080 + %%2082 + %%2084 + %%1793 + - + %%1797 + + + + + + 4732 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 112 + + + Security + informant-PC + + + + - + S-1-5-21-2425377081-3129163575-2985601102-1000 + Users + Builtin + S-1-5-32-545 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4722 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 113 + + + Security + informant-PC + + + + informant + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1000 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 114 + + + Security + informant-PC + + + + - + informant + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1000 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + informant + %%1793 + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + %%1794 + %%1794 + 513 + - + 0x15 + 0x14 + + %%2048 + %%1793 + - + %%1797 + + + + + + 4732 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 115 + + + Security + informant-PC + + + + - + S-1-5-21-2425377081-3129163575-2985601102-1000 + Administrators + Builtin + S-1-5-32-544 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4733 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 116 + + + Security + informant-PC + + + + - + S-1-5-21-2425377081-3129163575-2985601102-1000 + Users + Builtin + S-1-5-32-545 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 117 + + + Security + informant-PC + + + + - + informant + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1000 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + informant + %%1793 + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + 3/22/2015 10:33:54 AM + %%1794 + 513 + - + 0x14 + 0x214 + + %%2089 + - + - + %%1797 + + + + + + 4724 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 118 + + + Security + informant-PC + + + + informant + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1000 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 119 + + + Security + informant-PC + + + + - + informant + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1000 + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 120 + + + Security + informant-PC + + + + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 121 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 122 + + + Security + informant-PC + + + + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + {00000000-0000-0000-0000-000000000000} + informant + informant-PC + {00000000-0000-0000-0000-000000000000} + localhost + localhost + 0x0000000000000194 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 123 + + + Security + informant-PC + + + + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x000000000003be29 + 2 + User32 + Negotiate + WIN-D9RGPJQ68G8 + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000194 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 124 + + + Security + informant-PC + + + + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x000000000003db0a + 2 + User32 + Negotiate + WIN-D9RGPJQ68G8 + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000194 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 125 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x000000000003be29 + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 126 + + + Security + informant-PC + + + + S-1-5-18 + WIN-D9RGPJQ68G8$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 127 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 1100 + 0 + 4 + 103 + 0 + 0x4020000000000000 + + 128 + + + Security + informant-PC + + + + + + + + + + 4647 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 129 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x000000000003db0a + + + + + + 4608 + 0 + 0 + 12288 + 0 + 0x8020000000000000 + + 130 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 131 + + + Security + informant-PC + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 0 + - + - + - + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000004 + + - + - + + + + + + 4902 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 132 + + + Security + informant-PC + + + + 0 + 0x000000000000b8dc + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 133 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 134 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 135 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 136 + + + Security + informant-PC + + + + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 137 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 138 + + + Security + informant-PC + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 139 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 140 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 141 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 142 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 143 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 144 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 5033 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 145 + + + Security + informant-PC + + + + + + + + 5024 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 146 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 147 + + + Security + informant-PC + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-7 + ANONYMOUS LOGON + NT AUTHORITY + 0x000000000001a667 + 3 + NtLmSsp + NTLM + + {00000000-0000-0000-0000-000000000000} + - + NTLM V1 + 0 + 0x0000000000000000 + - + - + - + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 148 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 149 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 150 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 151 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 152 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + {00000000-0000-0000-0000-000000000000} + informant + informant-PC + {00000000-0000-0000-0000-000000000000} + localhost + localhost + 0x0000000000000184 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 153 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000026923 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000184 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 154 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000026951 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000184 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 155 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000026923 + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 156 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 157 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 158 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 159 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 160 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 161 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4904 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 162 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + VSSAudit + 0x0000000000069adb + 0x0000000000000bc0 + C:\Windows\System32\VSSVC.exe + + + + + + 4905 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 163 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + VSSAudit + 0x0000000000069adb + 0x0000000000000bc0 + C:\Windows\System32\VSSVC.exe + + + + + + 4904 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 164 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + VSSAudit + 0x00000000000835e3 + 0x0000000000000bc0 + C:\Windows\System32\VSSVC.exe + + + + + + 4905 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 165 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + VSSAudit + 0x00000000000835e3 + 0x0000000000000bc0 + C:\Windows\System32\VSSVC.exe + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 166 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 167 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 168 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 169 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 170 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 171 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 172 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 173 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4904 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 174 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + VSSAudit + 0x00000000001fa262 + 0x0000000000000e6c + C:\Windows\System32\VSSVC.exe + + + + + + 4905 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 175 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + VSSAudit + 0x00000000001fa262 + 0x0000000000000e6c + C:\Windows\System32\VSSVC.exe + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 176 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 177 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 178 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\winsxs\Temp\PendingRenames\a86dcf49b364d00184220000f80e440b.install.ins + 0x00000000000086e8 + + S:ARAI + 0x0000000000000ef8 + C:\Windows\servicing\TrustedInstaller.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 179 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\winsxs\Temp\PendingRenames\08cfd149b364d00185220000f80e440b.install.ins + 0x00000000000088b0 + + S:ARAI + 0x0000000000000ef8 + C:\Windows\servicing\TrustedInstaller.exe + + + + + + 4647 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 180 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000026951 + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 181 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\DWrite.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 182 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\d2d1.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 183 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\msmpeg2vdec.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 184 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 185 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\d3d10core.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 186 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 187 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 188 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\XpsGdiConverter.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 189 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 190 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\d3d10warp.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 191 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 192 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\dxgi.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 193 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\WMPhoto.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 194 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\FntCache.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 195 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 196 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\d3d10_1.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 197 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\WindowsCodecsExt.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 198 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 199 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\d3d10level9.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 200 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\UIAnimation.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 201 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 202 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\d3d10_1core.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 203 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\XpsPrint.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 204 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 205 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\d3d10.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 206 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\WindowsCodecs.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 207 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\d3d11.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 208 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 209 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 210 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\UIAnimation.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 211 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 212 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 213 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\da-DK\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 214 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\da-DK\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 215 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\da-DK\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 216 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\da-DK\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 217 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\nb-NO\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 218 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\nb-NO\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 219 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\nb-NO\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 220 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\nb-NO\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 221 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\spp\tokens\ppdlic\msmpeg2vdec-ppdlic.xrm-ms + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 222 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ru-RU\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 223 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ru-RU\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 224 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ru-RU\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 225 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ru-RU\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 226 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ja-JP\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 227 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ja-JP\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 228 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ja-JP\UIAnimation.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 229 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ja-JP\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 230 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ja-JP\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 231 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\zh-CN\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 232 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\zh-CN\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 233 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\zh-CN\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 234 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\zh-CN\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 235 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\cs-CZ\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 236 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\cs-CZ\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 237 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\cs-CZ\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 238 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\cs-CZ\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 239 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\de-DE\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 240 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\de-DE\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 241 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\de-DE\UIAnimation.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 242 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\de-DE\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 243 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\de-DE\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 244 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\zh-TW\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 245 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\zh-TW\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 246 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\zh-TW\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 247 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\zh-TW\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 248 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\es-ES\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 249 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\es-ES\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 250 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\es-ES\UIAnimation.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 251 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\es-ES\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 252 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\es-ES\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 253 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\sv-SE\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 254 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\sv-SE\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 255 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\sv-SE\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 256 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\sv-SE\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 257 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\tr-TR\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 258 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\tr-TR\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 259 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\tr-TR\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 260 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\tr-TR\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 261 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\fi-FI\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 262 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\fi-FI\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 263 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\fi-FI\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 264 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\fi-FI\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 265 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\fr-FR\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 266 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\fr-FR\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 267 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\fr-FR\UIAnimation.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 268 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\fr-FR\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 269 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\fr-FR\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 270 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\nl-NL\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 271 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\nl-NL\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 272 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\nl-NL\UIAnimation.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 273 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\nl-NL\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 274 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\nl-NL\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 275 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\el-GR\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 276 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\el-GR\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 277 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\el-GR\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 278 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\el-GR\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 279 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\zh-HK\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 280 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\zh-HK\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 281 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\zh-HK\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 282 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\zh-HK\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 283 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\hu-HU\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 284 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\hu-HU\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 285 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\hu-HU\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 286 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\hu-HU\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 287 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ko-KR\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 288 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ko-KR\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 289 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ko-KR\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 290 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ko-KR\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 291 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\pl-PL\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 292 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\pl-PL\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 293 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\pl-PL\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 294 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\pl-PL\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 295 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\pt-PT\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 296 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\pt-PT\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 297 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\pt-PT\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 298 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\pt-PT\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 299 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\it-IT\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 300 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\it-IT\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 301 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\it-IT\UIAnimation.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 302 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\it-IT\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 303 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\it-IT\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 304 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\pt-BR\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 305 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\pt-BR\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 306 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\pt-BR\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 307 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\pt-BR\FntCache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 308 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\DWrite.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 309 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\d2d1.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 310 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\msmpeg2vdec.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 311 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 312 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\d3d10core.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 313 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 314 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 315 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\XpsGdiConverter.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 316 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 317 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\d3d10warp.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 318 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\dxgi.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 319 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 320 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\WMPhoto.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 321 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 322 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\d3d10_1.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 323 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\d3d10level9.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 324 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\WindowsCodecsExt.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 325 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 326 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 327 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\UIAnimation.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 328 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\d3d10_1core.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 329 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\XpsPrint.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 330 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 331 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\d3d10.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 332 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\WindowsCodecs.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 333 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\d3d11.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 334 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 335 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 336 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\UIAnimation.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 337 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 338 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\da-DK\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 339 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\da-DK\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 340 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\da-DK\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 341 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\nb-NO\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 342 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\nb-NO\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 343 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\nb-NO\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 344 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\spp\tokens\ppdlic\msmpeg2vdec-ppdlic.xrm-ms + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 345 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ru-RU\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 346 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ru-RU\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 347 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ru-RU\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 348 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ja-JP\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 349 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ja-JP\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 350 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ja-JP\UIAnimation.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 351 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ja-JP\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 352 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\zh-CN\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 353 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\zh-CN\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 354 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\zh-CN\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 355 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\cs-CZ\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 356 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\cs-CZ\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 357 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\cs-CZ\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 358 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\de-DE\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 359 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\de-DE\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 360 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\de-DE\UIAnimation.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 361 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\de-DE\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 362 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\zh-TW\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 363 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\zh-TW\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 364 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\zh-TW\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 365 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\es-ES\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 366 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\es-ES\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 367 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\es-ES\UIAnimation.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 368 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\es-ES\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 369 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\sv-SE\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 370 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\sv-SE\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 371 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\sv-SE\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 372 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\tr-TR\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 373 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\tr-TR\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 374 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\tr-TR\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 375 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\fi-FI\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 376 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\fi-FI\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 377 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\fi-FI\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 378 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\fr-FR\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 379 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\fr-FR\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 380 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\fr-FR\UIAnimation.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 381 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\fr-FR\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 382 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\nl-NL\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 383 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\nl-NL\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 384 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\nl-NL\UIAnimation.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 385 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\nl-NL\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 386 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\el-GR\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 387 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\el-GR\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 388 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\el-GR\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 389 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\zh-HK\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 390 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\zh-HK\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 391 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\zh-HK\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 392 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\hu-HU\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 393 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\hu-HU\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 394 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\hu-HU\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 395 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ko-KR\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 396 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ko-KR\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 397 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ko-KR\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 398 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\pl-PL\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 399 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\pl-PL\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 400 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\pl-PL\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 401 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\pt-PT\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 402 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\pt-PT\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 403 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\pt-PT\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 404 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\it-IT\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 405 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\it-IT\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 406 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\it-IT\UIAnimation.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 407 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\it-IT\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 408 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\pt-BR\WMPhoto.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 409 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\pt-BR\d2d1.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 410 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\pt-BR\DWrite.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 411 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ntoskrnl.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 412 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ntoskrnl.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 413 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ntkrnlpa.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 414 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\AppPatch\acwow64.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 415 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 416 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 417 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 418 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 419 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\wow64.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 420 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\wow64cpu.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 421 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 422 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 423 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 424 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 425 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 426 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 427 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 428 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ntvdm64.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 429 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 430 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 431 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 432 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 433 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 434 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 435 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\conhost.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 436 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 437 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 438 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 439 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\wow64win.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 440 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 441 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\kernel32.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 442 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\KernelBase.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 443 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 444 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 445 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 446 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 447 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\winsrv.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 448 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 449 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 450 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 451 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 452 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 453 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\setup16.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 454 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\user.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 455 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 456 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ntvdm64.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 457 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 458 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 459 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 460 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 461 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 462 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 463 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 464 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 465 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 466 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\instnm.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 467 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 468 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 469 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 470 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 471 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 472 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 473 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\kernel32.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 474 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 475 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 476 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 477 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 478 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 479 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\KernelBase.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 480 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 481 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 482 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 483 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 484 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 485 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\wow32.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 486 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\AppPatch\acwow64.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 487 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 488 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 489 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 490 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 491 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\wow64.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 492 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\wow64cpu.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 493 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 494 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 495 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 496 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 497 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 498 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 499 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 500 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ntvdm64.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 501 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 502 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 503 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 504 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 505 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 506 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 507 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\conhost.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 508 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 509 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 510 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 511 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\wow64win.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 512 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 513 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\kernel32.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 514 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\KernelBase.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 515 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 516 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 517 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 518 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 519 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\winsrv.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 520 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 521 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 522 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 523 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\KernelBase.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 524 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\instnm.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 525 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 526 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 527 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 528 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 529 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\user.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 530 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 531 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 532 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 533 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 534 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 535 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 536 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 537 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ntvdm64.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 538 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 539 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 540 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 541 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 542 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 543 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 544 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\wow32.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 545 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 546 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 547 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 548 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 549 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\kernel32.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 550 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\KernelBase.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 551 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 552 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 553 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 554 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 555 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 556 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\setup16.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 557 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 558 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 559 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\KernelBase.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 560 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\Fonts\seguisym.ttf + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 561 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\Fonts\segoeui.ttf + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 562 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\Fonts\segoeuiz.ttf + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 563 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\Fonts\segoeuib.ttf + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 564 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\Fonts\segoeuii.ttf + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 565 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\taskhost.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 566 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\drivers\afd.sys + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 567 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\drivers\FWPKCLNT.SYS + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 568 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\drivers\tcpip.sys + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 569 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\drivers\netio.sys + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 570 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\mswsock.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 571 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\mswsock.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 572 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\smss.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 573 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\csrsrv.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 574 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ntdll.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 575 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ntoskrnl.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 576 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\apisetschema.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 577 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ntdll.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 578 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ntoskrnl.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 579 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ntkrnlpa.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 580 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\AppPatch\acwow64.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 581 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\tdh.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 582 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 583 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 584 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 585 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 586 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\wow64.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 587 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\wow64cpu.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 588 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 589 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 590 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 591 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 592 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 593 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 594 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 595 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ntvdm64.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 596 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 597 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 598 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 599 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 600 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 601 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 602 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\conhost.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 603 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 604 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\advapi32.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 605 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 606 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 607 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\wow64win.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 608 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 609 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\kernel32.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 610 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\KernelBase.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 611 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 612 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 613 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 614 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 615 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\winsrv.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 616 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 617 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 618 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 619 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\instnm.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 620 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\tdh.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 621 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 622 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 623 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 624 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 625 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\user.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 626 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 627 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 628 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 629 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 630 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 631 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 632 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 633 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ntvdm64.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 634 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 635 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 636 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 637 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 638 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 639 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 640 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\wow32.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 641 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 642 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\advapi32.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 643 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 644 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 645 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 646 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\KernelBase.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 647 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\kernel32.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 648 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 649 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 650 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 651 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 652 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 653 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\setup16.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 654 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 655 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 656 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Common Files\microsoft shared\VGX\VGX.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 657 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\D3DCompiler_47.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 658 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\iexplore.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 659 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\ie9props.propdesc + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 660 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\JSProfilerCore.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 661 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\jsprofilerui.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 662 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\pdm.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 663 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\pdmproxy100.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 664 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\DiagnosticsTap.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 665 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\ExtExport.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 666 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\sqmapi.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 667 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\jsdebuggeride.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 668 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\jsdbgui.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 669 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\msdbg2.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 670 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\networkinspection.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 671 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\iedvtool.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 672 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\ielowutil.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 673 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\ieproxy.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 674 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\ieinstal.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 675 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\F12Tools.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 676 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\IEShims.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 677 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\SIGNUP\install.ins + 0x000000000000001c + S:AI + + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 678 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\en-US\F12Tools.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 679 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\en-US\jsprofilerui.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 680 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\en-US\jsdbgui.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 681 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\en-US\iedvtool.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 682 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\en-US\DiagnosticsTap.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 683 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\en-US\ieinstal.exe.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 684 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\en-US\eula.rtf + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 685 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\en-US\networkinspection.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 686 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 687 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 688 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\iexplore.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 689 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\Timeline_is.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 690 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\pdm.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 691 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\msdbg2.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 692 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\Timeline.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 693 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\JSProfilerCore.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 694 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\ielowutil.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 695 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\ieinstal.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 696 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\IEShims.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 697 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\pdmproxy100.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 698 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\perfcore.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 699 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\D3DCompiler_47.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 700 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\iedvtool.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 701 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\ieproxy.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 702 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\DiagnosticsTap.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 703 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\iediagcmd.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 704 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\perf_nt.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 705 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\DiagnosticsHub.DataWarehouse.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 706 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\F12Tools.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 707 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\jsdebuggeride.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 708 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\networkinspection.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 709 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\jsprofilerui.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 710 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\DiagnosticsHub.ScriptedSandboxPlugin.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 711 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\MemoryAnalyzer.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 712 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\F12Resources.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 713 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\ie9props.propdesc + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 714 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\jsdbgui.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 715 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\F12.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 716 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\DiagnosticsHub_is.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 717 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\Timeline.cpu.xml + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 718 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\sqmapi.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 719 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\en-US\jsprofilerui.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 720 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\en-US\F12Tools.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 721 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\en-US\F12.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 722 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\en-US\jsdbgui.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 723 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\en-US\iedvtool.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 724 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\en-US\F12Resources.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 725 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\en-US\ieinstal.exe.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 726 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\en-US\DiagnosticsTap.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 727 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\en-US\networkinspection.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 728 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\en-US\eula.rtf + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 729 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 730 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\images\bing.ico + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 731 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Program Files\Internet Explorer\SIGNUP\install.ins + 0x000000000000001c + S:AI + + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 732 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ieapfltr.dat + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 733 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\url.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 734 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\mshta.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 735 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\jsproxy.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 736 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ieUnatt.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 737 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ieui.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 738 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\mshtmlmedia.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 739 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ieetwproxystub.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 740 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\jsIntl.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 741 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\RegisterIEPKEYs.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 742 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\iepeers.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 743 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\elshyph.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 744 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ieframe.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 745 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ie4uinit.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 746 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\licmgr10.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 747 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\mshtmler.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 748 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\iexpress.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 749 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\IEAdvpack.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 750 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\dxtrans.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 751 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\wextract.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 752 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ieetwcollectorres.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 753 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\SetIEInstalledDate.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 754 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\wininet.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 755 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\MshtmlDac.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 756 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\jscript.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 757 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\JavaScriptCollectionAgent.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 758 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\msfeedssync.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 759 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\webcheck.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 760 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\MsSpellCheckingFacility.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 761 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\icardie.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 762 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\iertutil.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 763 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\pngfilt.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 764 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\msls31.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 765 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ieetwcollector.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 766 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\jscript9diag.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 767 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\iedkcs32.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 768 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\iesetup.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 769 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\iernonce.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 770 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\vbscript.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 771 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\inseng.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 772 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\iesysprep.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 773 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\inetcpl.cpl + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 774 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\jscript9.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 775 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\occache.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 776 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ieapfltr.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 777 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\html.iec + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 778 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\imgutil.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 779 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\msfeeds.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 780 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\ieuinit.inf + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 781 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\tdc.ocx + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 782 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\mshtml.tlb + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 783 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\mshtml.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 784 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\mshtmled.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 785 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\urlmon.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 786 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\msfeedsbs.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 787 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\msrating.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 788 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\dxtmsft.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 789 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\iesetup.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 790 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\mshtmlmedia.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 791 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\icardie.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 792 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\iepeers.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 793 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\IEAdvpack.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 794 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\jsIntl.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 795 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\occache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 796 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\MsSpellCheckingFacility.exe.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 797 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\wextract.exe.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 798 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\ieunatt.exe.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 799 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\ie4uinit.exe.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 800 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\iernonce.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 801 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\elshyph.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 802 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\jscript.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 803 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\msrating.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 804 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\ieframe.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 805 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\msfeedsbs.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 806 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\vbscript.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 807 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\ieui.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 808 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\html.iec.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 809 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\iexpress.exe.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 810 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\mshtmler.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 811 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\urlmon.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 812 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\jscript9.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 813 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\iedkcs32.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 814 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\webcheck.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 815 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\wininet.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 816 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\mshta.exe.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 817 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\licmgr10.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 818 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\mshtml.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 819 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\inseng.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 820 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\inetcpl.cpl.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 821 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\en-US\ieetwcollectorres.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 822 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\spp\tokens\ppdlic\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 823 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\wdi\perftrack\Microsoft-Windows-IE-HTMLRendering.ptxml + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 824 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\wdi\perftrack\ieframe.ptxml + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 825 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\wdi\perftrack\Microsoft-Windows-IE-F12-Provider.ptxml + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 826 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\System32\migration\WininetPlugin.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 827 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\PolicyDefinitions\inetres.admx + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 828 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\PolicyDefinitions\en-US\InetRes.adml + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 829 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ieapfltr.dat + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 830 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\mshta.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 831 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\jsproxy.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 832 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\url.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 833 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ieUnatt.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 834 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ieui.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 835 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\mshtmlmedia.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 836 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\jsIntl.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 837 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ieetwproxystub.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 838 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\RegisterIEPKEYs.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 839 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\elshyph.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 840 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\iepeers.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 841 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ieframe.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 842 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\licmgr10.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 843 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\mshtmler.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 844 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\iexpress.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 845 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\IEAdvpack.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 846 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\wextract.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 847 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\dxtrans.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 848 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\wininet.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 849 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\SetIEInstalledDate.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 850 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\MshtmlDac.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 851 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\jscript.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 852 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 853 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\msfeedssync.exe + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 854 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\webcheck.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 855 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\icardie.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 856 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\iertutil.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 857 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\pngfilt.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 858 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\jscript9diag.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 859 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\msls31.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 860 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\iedkcs32.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 861 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\iesetup.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 862 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\iernonce.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 863 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\vbscript.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 864 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\iesysprep.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 865 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\inseng.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 866 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\jscript9.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 867 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\occache.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 868 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\inetcpl.cpl + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 869 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ieapfltr.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 870 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\html.iec + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 871 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\imgutil.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 872 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\msfeeds.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 873 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\ieuinit.inf + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 874 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\tdc.ocx + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 875 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\mshtml.tlb + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 876 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\mshtml.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 877 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\mshtmled.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 878 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\urlmon.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 879 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\msfeedsbs.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 880 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\msrating.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 881 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\dxtmsft.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 882 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\webcheck.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 883 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\iernonce.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 884 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\inseng.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 885 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\html.iec.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 886 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\msrating.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 887 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\wininet.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 888 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\ieui.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 889 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\elshyph.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 890 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\iexpress.exe.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 891 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\ieetwcollectorres.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 892 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\occache.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 893 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\ieframe.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 894 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\mshta.exe.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 895 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\mshtml.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 896 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\wextract.exe.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 897 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\iesetup.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 898 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\ieunatt.exe.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 899 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\licmgr10.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 900 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\mshtmler.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 901 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\jscript.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 902 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\vbscript.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 903 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\iepeers.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 904 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\IEAdvpack.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 905 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\msfeedsbs.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 906 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\mshtmlmedia.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 907 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\iedkcs32.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 908 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\urlmon.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 909 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\inetcpl.cpl.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 910 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\jscript9.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 911 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\en-US\icardie.dll.mui + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 912 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\wdi\perftrack\wow64_ieframe.ptxml + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 913 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\wdi\perftrack\wow64_Microsoft-Windows-IE-HTMLRendering.ptxml + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 914 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\SysWOW64\migration\WininetPlugin.dll + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 915 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.acl + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 916 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.dub + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 917 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.lex + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 918 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\Globalization\ELS\HyphenationDictionaries\MsHy7en.lex + 0x000000000000001c + + S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD) + 0x0000000000000cdc + C:\Windows\System32\poqexec.exe + + + + + + 1100 + 0 + 4 + 103 + 0 + 0x4020000000000000 + + 919 + + + Security + informant-PC + + + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 920 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001c0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 921 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4608 + 0 + 0 + 12288 + 0 + 0x8020000000000000 + + 922 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 923 + + + Security + informant-PC + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 0 + - + - + - + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000004 + + - + - + + + + + + 4902 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 924 + + + Security + informant-PC + + + + 0 + 0x000000000000c957 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 925 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 926 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 927 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 928 + + + Security + informant-PC + + + + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 929 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 930 + + + Security + informant-PC + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 931 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 932 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 933 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 934 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 935 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 936 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 937 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 938 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 5033 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 939 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 940 + + + Security + informant-PC + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-7 + ANONYMOUS LOGON + NT AUTHORITY + 0x000000000001a427 + 3 + NtLmSsp + NTLM + + {00000000-0000-0000-0000-000000000000} + - + NTLM V1 + 0 + 0x0000000000000000 + - + - + - + + + + + + 5024 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 941 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 942 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 943 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 944 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\Globalization\ELS\HyphenationDictionaries + 0x00000000000002d4 + + S:ARAI(AU;SAFA;0x1f0116;;;WD) + 0x00000000000003e8 + C:\Windows\servicing\TrustedInstaller.exe + + + + + + 4907 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 945 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + Security + File + C:\Windows\Globalization\ELS\SpellDictionaries + 0x00000000000002d0 + + S:ARAI(AU;SAFA;0x1f0116;;;WD) + 0x00000000000003e8 + C:\Windows\servicing\TrustedInstaller.exe + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 946 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + {00000000-0000-0000-0000-000000000000} + informant + informant-PC + {00000000-0000-0000-0000-000000000000} + localhost + localhost + 0x00000000000001b8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 947 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000056f8b + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001b8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 948 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000056fb9 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001b8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 949 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000056f8b + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 950 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 951 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 1100 + 0 + 4 + 103 + 0 + 0x4020000000000000 + + 952 + + + Security + informant-PC + + + + + + + + + + 4647 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 953 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000056fb9 + + + + + + 4608 + 0 + 0 + 12288 + 0 + 0x8020000000000000 + + 954 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 955 + + + Security + informant-PC + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 0 + - + - + - + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000004 + + - + - + + + + + + 4902 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 956 + + + Security + informant-PC + + + + 0 + 0x000000000000c54c + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 957 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 958 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 959 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 960 + + + Security + informant-PC + + + + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 961 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 962 + + + Security + informant-PC + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 963 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 964 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 965 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 966 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 967 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 968 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 5033 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 969 + + + Security + informant-PC + + + + + + + + 5024 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 970 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 971 + + + Security + informant-PC + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-7 + ANONYMOUS LOGON + NT AUTHORITY + 0x000000000001c185 + 3 + NtLmSsp + NTLM + + {00000000-0000-0000-0000-000000000000} + - + NTLM V1 + 0 + 0x0000000000000000 + - + - + - + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 972 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + {00000000-0000-0000-0000-000000000000} + informant + informant-PC + {00000000-0000-0000-0000-000000000000} + localhost + localhost + 0x00000000000001b8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 973 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001b8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 974 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000022517 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001b8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 975 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 976 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 977 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 978 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 979 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 980 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 981 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 982 + + + Security + informant-PC + + + + - + informant + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1000 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000022517 + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + + + + + + 4728 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 983 + + + Security + informant-PC + + + + - + S-1-5-21-2425377081-3129163575-2985601102-1001 + None + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-513 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + + + + + + 4720 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 984 + + + Security + informant-PC + + + + admin11 + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1001 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + admin11 + %%1793 + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + %%1794 + %%1794 + 513 + - + 0x0 + 0x15 + + %%2080 + %%2082 + %%2084 + %%1793 + - + %%1797 + + + + + + 4722 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 985 + + + Security + informant-PC + + + + admin11 + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1001 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 986 + + + Security + informant-PC + + + + - + admin11 + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1001 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + admin11 + admin11 + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + %%1794 + %%1794 + 513 + - + 0x15 + 0x210 + + %%2048 + %%2050 + %%2089 + %%1793 + - + %%1797 + + + + + + 4732 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 987 + + + Security + informant-PC + + + + - + S-1-5-21-2425377081-3129163575-2985601102-1001 + Users + Builtin + S-1-5-32-545 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 988 + + + Security + informant-PC + + + + - + admin11 + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1001 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + + + + + + 4732 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 989 + + + Security + informant-PC + + + + - + S-1-5-21-2425377081-3129163575-2985601102-1001 + Administrators + Builtin + S-1-5-32-544 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 990 + + + Security + informant-PC + + + + - + admin11 + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1001 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + admin11 + admin11 + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + %%1794 + %%1794 + 513 + - + 0x210 + 0x210 + - + %%1793 + - + %%1797 + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 991 + + + Security + informant-PC + + + + - + admin11 + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1001 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + admin11 + admin11 + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + 3/22/2015 11:52:10 AM + %%1794 + 513 + - + 0x210 + 0x210 + - + - + - + %%1797 + + + + + + 4724 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 992 + + + Security + informant-PC + + + + admin11 + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1001 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 993 + + + Security + informant-PC + + + + - + admin11 + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1001 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + + + + + + 4728 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 994 + + + Security + informant-PC + + + + - + S-1-5-21-2425377081-3129163575-2985601102-1002 + None + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-513 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + + + + + + 4720 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 995 + + + Security + informant-PC + + + + ITechTeam + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1002 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + ITechTeam + %%1793 + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + %%1794 + %%1794 + 513 + - + 0x0 + 0x15 + + %%2080 + %%2082 + %%2084 + %%1793 + - + %%1797 + + + + + + 4722 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 996 + + + Security + informant-PC + + + + ITechTeam + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1002 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 997 + + + Security + informant-PC + + + + - + ITechTeam + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1002 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + ITechTeam + ITechTeam + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + %%1794 + %%1794 + 513 + - + 0x15 + 0x210 + + %%2048 + %%2050 + %%2089 + %%1793 + - + %%1797 + + + + + + 4732 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 998 + + + Security + informant-PC + + + + - + S-1-5-21-2425377081-3129163575-2985601102-1002 + Users + Builtin + S-1-5-32-545 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 999 + + + Security + informant-PC + + + + - + ITechTeam + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1002 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + + + + + + 4732 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 1000 + + + Security + informant-PC + + + + - + S-1-5-21-2425377081-3129163575-2985601102-1002 + Administrators + Builtin + S-1-5-32-544 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 1001 + + + Security + informant-PC + + + + - + ITechTeam + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1002 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + ITechTeam + ITechTeam + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + %%1794 + %%1794 + 513 + - + 0x210 + 0x210 + - + %%1793 + - + %%1797 + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 1002 + + + Security + informant-PC + + + + - + ITechTeam + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1002 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + ITechTeam + ITechTeam + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + 3/22/2015 11:52:45 AM + %%1794 + 513 + - + 0x210 + 0x210 + - + - + - + %%1797 + + + + + + 4724 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 1003 + + + Security + informant-PC + + + + ITechTeam + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1002 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 1004 + + + Security + informant-PC + + + + - + ITechTeam + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1002 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + + + + + + 4728 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 1005 + + + Security + informant-PC + + + + - + S-1-5-21-2425377081-3129163575-2985601102-1003 + None + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-513 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + + + + + + 4720 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 1006 + + + Security + informant-PC + + + + temporary + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1003 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + temporary + %%1793 + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + %%1794 + %%1794 + 513 + - + 0x0 + 0x15 + + %%2080 + %%2082 + %%2084 + %%1793 + - + %%1797 + + + + + + 4722 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 1007 + + + Security + informant-PC + + + + temporary + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1003 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 1008 + + + Security + informant-PC + + + + - + temporary + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1003 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + temporary + temporary + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + %%1794 + %%1794 + 513 + - + 0x15 + 0x210 + + %%2048 + %%2050 + %%2089 + %%1793 + - + %%1797 + + + + + + 4732 + 0 + 0 + 13826 + 0 + 0x8020000000000000 + + 1009 + + + Security + informant-PC + + + + - + S-1-5-21-2425377081-3129163575-2985601102-1003 + Users + Builtin + S-1-5-32-545 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 1010 + + + Security + informant-PC + + + + - + temporary + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1003 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 1011 + + + Security + informant-PC + + + + - + temporary + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1003 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + temporary + temporary + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + %%1794 + %%1794 + 513 + - + 0x210 + 0x210 + - + %%1793 + - + %%1797 + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 1012 + + + Security + informant-PC + + + + - + temporary + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1003 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + temporary + temporary + - + %%1793 + %%1793 + %%1793 + %%1793 + %%1793 + 3/22/2015 11:53:11 AM + %%1794 + 513 + - + 0x210 + 0x210 + - + - + - + %%1797 + + + + + + 4724 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 1013 + + + Security + informant-PC + + + + temporary + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1003 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + + + + + + 4738 + 0 + 0 + 13824 + 0 + 0x8020000000000000 + + 1014 + + + Security + informant-PC + + + + - + temporary + informant-PC + S-1-5-21-2425377081-3129163575-2985601102-1003 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000224e3 + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1015 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + {00000000-0000-0000-0000-000000000000} + admin11 + informant-PC + {00000000-0000-0000-0000-000000000000} + localhost + localhost + 0x00000000000007a0 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1016 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1001 + admin11 + informant-PC + 0x0000000000094b57 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000007a0 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1017 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1001 + admin11 + informant-PC + 0x0000000000094b71 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000007a0 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1018 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1001 + admin11 + informant-PC + 0x0000000000094b57 + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4647 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1019 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1001 + admin11 + informant-PC + 0x0000000000094b71 + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1020 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + {00000000-0000-0000-0000-000000000000} + temporary + informant-PC + {00000000-0000-0000-0000-000000000000} + localhost + localhost + 0x000000000000072c + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1021 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1003 + temporary + informant-PC + 0x00000000000f2cd6 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x000000000000072c + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4634 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1022 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1001 + admin11 + informant-PC + 0x0000000000094b71 + 2 + + + + + + 4634 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1023 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1001 + admin11 + informant-PC + 0x0000000000094b57 + 2 + + + + + + 4647 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1024 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1003 + temporary + informant-PC + 0x00000000000f2cd6 + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1025 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + {00000000-0000-0000-0000-000000000000} + admin11 + informant-PC + {00000000-0000-0000-0000-000000000000} + localhost + localhost + 0x0000000000000954 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1026 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1001 + admin11 + informant-PC + 0x00000000001354b3 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000954 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1027 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1001 + admin11 + informant-PC + 0x00000000001354c8 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000954 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1028 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1001 + admin11 + informant-PC + 0x00000000001354b3 + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4647 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1029 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1001 + admin11 + informant-PC + 0x00000000001354c8 + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1030 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + {00000000-0000-0000-0000-000000000000} + informant + informant-PC + {00000000-0000-0000-0000-000000000000} + localhost + localhost + 0x0000000000000c1c + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1031 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000157b62 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000c1c + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1032 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000157b78 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000c1c + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1033 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000157b62 + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4634 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1034 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000157b78 + 2 + + + + + + 4634 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1035 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000157b62 + 2 + + + + + + 4634 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1036 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1003 + temporary + informant-PC + 0x00000000000f2cd6 + 2 + + + + + + 4634 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1037 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1001 + admin11 + informant-PC + 0x00000000001354c8 + 2 + + + + + + 4634 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1038 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1001 + admin11 + informant-PC + 0x00000000001354b3 + 2 + + + + + + 1100 + 0 + 4 + 103 + 0 + 0x4020000000000000 + + 1039 + + + Security + informant-PC + + + + + + + + + + 4647 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1040 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000022517 + + + + + + 4608 + 0 + 0 + 12288 + 0 + 0x8020000000000000 + + 1041 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1042 + + + Security + informant-PC + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 0 + - + - + - + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000004 + + - + - + + + + + + 4902 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 1043 + + + Security + informant-PC + + + + 0 + 0x000000000000bac4 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1044 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1045 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1046 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1047 + + + Security + informant-PC + + + + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1048 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1049 + + + Security + informant-PC + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1050 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1051 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1052 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1053 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1054 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1055 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 5033 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 1056 + + + Security + informant-PC + + + + + + + + 5024 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 1057 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1058 + + + Security + informant-PC + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-7 + ANONYMOUS LOGON + NT AUTHORITY + 0x000000000001b9a4 + 3 + NtLmSsp + NTLM + + {00000000-0000-0000-0000-000000000000} + - + NTLM V1 + 0 + 0x0000000000000000 + - + - + - + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1059 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + {00000000-0000-0000-0000-000000000000} + informant + informant-PC + {00000000-0000-0000-0000-000000000000} + localhost + localhost + 0x00000000000001a8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1060 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x000000000002359c + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001a8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1061 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000235cc + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001a8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1062 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x000000000002359c + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1063 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1064 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4616 + 1 + 0 + 12288 + 0 + 0x8020000000000000 + + 1065 + + + Security + informant-PC + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 2015-03-23 17:25:47.192598 + 2015-03-23 17:25:47.191999 + 0x0000000000000358 + C:\Windows\System32\svchost.exe + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1066 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1067 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1068 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1069 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4616 + 1 + 0 + 12288 + 0 + 0x8020000000000000 + + 1070 + + + Security + informant-PC + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 2015-03-23 18:57:01.113134 + 2015-03-23 19:08:15.571480 + 0x0000000000000358 + C:\Windows\System32\svchost.exe + + + + + + 4616 + 1 + 0 + 12288 + 0 + 0x8020000000000000 + + 1071 + + + Security + informant-PC + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 2015-03-23 19:08:15.571480 + 2015-03-23 19:08:15.570999 + 0x0000000000000358 + C:\Windows\System32\svchost.exe + + + + + + 4616 + 1 + 0 + 12288 + 0 + 0x8020000000000000 + + 1072 + + + Security + informant-PC + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 2015-03-23 19:08:46.443419 + 2015-03-23 19:08:46.442999 + 0x0000000000000358 + C:\Windows\System32\svchost.exe + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1073 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1074 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1075 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1076 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1077 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1078 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1079 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e4 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1080 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4904 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 1081 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + VSSAudit + 0x00000000002c2083 + 0x0000000000000d40 + C:\Windows\System32\VSSVC.exe + + + + + + 4905 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 1082 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + VSSAudit + 0x00000000002c2083 + 0x0000000000000d40 + C:\Windows\System32\VSSVC.exe + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1083 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000235cc + {00000000-0000-0000-0000-000000000000} + Company + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + Company-PC + Company-PC + 0x0000000000000004 + + - + - + + + + + + 4647 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1084 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000235cc + + + + + + 1100 + 0 + 4 + 103 + 0 + 0x4020000000000000 + + 1085 + + + Security + informant-PC + + + + + + + + + + 4608 + 0 + 0 + 12288 + 0 + 0x8020000000000000 + + 1086 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1087 + + + Security + informant-PC + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 0 + - + - + - + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000004 + + - + - + + + + + + 4902 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 1088 + + + Security + informant-PC + + + + 0 + 0x000000000000b683 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1089 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e8 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1090 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1091 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e8 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1092 + + + Security + informant-PC + + + + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1093 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e8 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1094 + + + Security + informant-PC + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1095 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e8 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1096 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1097 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e8 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1098 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1099 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e8 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1100 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 5033 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 1101 + + + Security + informant-PC + + + + + + + + 5024 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 1102 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1103 + + + Security + informant-PC + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-7 + ANONYMOUS LOGON + NT AUTHORITY + 0x000000000001c0ce + 3 + NtLmSsp + NTLM + + {00000000-0000-0000-0000-000000000000} + - + NTLM V1 + 0 + 0x0000000000000000 + - + - + - + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1104 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + {00000000-0000-0000-0000-000000000000} + informant + informant-PC + {00000000-0000-0000-0000-000000000000} + localhost + localhost + 0x00000000000001b8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1105 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x000000000002269c + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001b8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1106 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000226c4 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001b8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1107 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x000000000002269c + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1108 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e8 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1109 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1110 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e8 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1111 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1112 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000226c4 + {00000000-0000-0000-0000-000000000000} + Company + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + Company-PC + Company-PC + 0x0000000000000004 + + - + - + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1113 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e8 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1114 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1115 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e8 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1116 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1117 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e8 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1118 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1119 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e8 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1120 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1121 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e8 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1122 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1123 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + {00000000-0000-0000-0000-000000000000} + informant + informant-PC + {00000000-0000-0000-0000-000000000000} + localhost + localhost + 0x00000000000001b8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1124 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000006cabcf + 7 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001b8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1125 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000006cabdd + 7 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001b8 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1126 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000006cabcf + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4634 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1127 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000006cabdd + 7 + + + + + + 4634 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1128 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000006cabcf + 7 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1129 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001e8 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1130 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4647 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1131 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x00000000000226c4 + + + + + + 1100 + 0 + 4 + 103 + 0 + 0x4020000000000000 + + 1132 + + + Security + informant-PC + + + + + + + + + + 4608 + 0 + 0 + 12288 + 0 + 0x8020000000000000 + + 1133 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1134 + + + Security + informant-PC + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 0 + - + - + - + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000004 + + - + - + + + + + + 4902 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 1135 + + + Security + informant-PC + + + + 0 + 0x000000000000ba7d + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1136 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1137 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1138 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1139 + + + Security + informant-PC + + + + S-1-5-20 + NETWORK SERVICE + NT AUTHORITY + 0x00000000000003e4 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1140 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1141 + + + Security + informant-PC + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + SeAssignPrimaryTokenPrivilege + SeAuditPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1142 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1143 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1144 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1145 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1146 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1147 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 5033 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 1148 + + + Security + informant-PC + + + + + + + + 5024 + 0 + 0 + 12292 + 0 + 0x8020000000000000 + + 1149 + + + Security + informant-PC + + + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1150 + + + Security + informant-PC + + + + S-1-0-0 + - + - + 0x0000000000000000 + S-1-5-7 + ANONYMOUS LOGON + NT AUTHORITY + 0x000000000001c0d1 + 3 + NtLmSsp + NTLM + + {00000000-0000-0000-0000-000000000000} + - + NTLM V1 + 0 + 0x0000000000000000 + - + - + - + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1151 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + {00000000-0000-0000-0000-000000000000} + informant + informant-PC + {00000000-0000-0000-0000-000000000000} + localhost + localhost + 0x0000000000000194 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1152 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000025465 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000194 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1153 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000025493 + 2 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000194 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1154 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000025465 + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1155 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1156 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1157 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1158 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1159 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1160 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4616 + 1 + 0 + 12288 + 0 + 0x8020000000000000 + + 1161 + + + Security + informant-PC + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 2015-03-25 13:29:46.566790 + 2015-03-25 14:13:47.009901 + 0x0000000000000330 + C:\Windows\System32\svchost.exe + + + + + + 4616 + 1 + 0 + 12288 + 0 + 0x8020000000000000 + + 1162 + + + Security + informant-PC + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 2015-03-25 14:13:47.025499 + 2015-03-25 14:13:47.025000 + 0x0000000000000330 + C:\Windows\System32\svchost.exe + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1163 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1164 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4648 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1165 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + {00000000-0000-0000-0000-000000000000} + informant + informant-PC + {00000000-0000-0000-0000-000000000000} + localhost + localhost + 0x0000000000000194 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1166 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000157773 + 7 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000194 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1167 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x000000000015777f + 7 + User32 + Negotiate + INFORMANT-PC + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x0000000000000194 + C:\Windows\System32\winlogon.exe + 127.0.0.1 + 0 + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1168 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000157773 + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4634 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1169 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x000000000015777f + 7 + + + + + + 4634 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1170 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000157773 + 7 + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1171 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1172 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1173 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1174 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1175 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1176 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4904 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 1177 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + VSSAudit + 0x00000000001aa8e7 + 0x0000000000000934 + C:\Windows\System32\VSSVC.exe + + + + + + 4905 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 1178 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + VSSAudit + 0x00000000001aa8e7 + 0x0000000000000934 + C:\Windows\System32\VSSVC.exe + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1179 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1180 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1181 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1182 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1183 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1184 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1185 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1186 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4904 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 1187 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + VSSAudit + 0x0000000000245dcb + 0x0000000000000aa4 + C:\Windows\System32\VSSVC.exe + + + + + + 4905 + 0 + 0 + 13568 + 0 + 0x8020000000000000 + + 1188 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + VSSAudit + 0x0000000000245dcb + 0x0000000000000aa4 + C:\Windows\System32\VSSVC.exe + + + + + + 4624 + 0 + 0 + 12544 + 0 + 0x8020000000000000 + + 1189 + + + Security + informant-PC + + + + S-1-5-18 + INFORMANT-PC$ + WORKGROUP + 0x00000000000003e7 + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + 5 + Advapi + Negotiate + + {00000000-0000-0000-0000-000000000000} + - + - + 0 + 0x00000000000001d0 + C:\Windows\System32\services.exe + - + - + + + + + + 4672 + 0 + 0 + 12548 + 0 + 0x8020000000000000 + + 1190 + + + Security + informant-PC + + + + S-1-5-18 + SYSTEM + NT AUTHORITY + 0x00000000000003e7 + SeAssignPrimaryTokenPrivilege + SeTcbPrivilege + SeSecurityPrivilege + SeTakeOwnershipPrivilege + SeLoadDriverPrivilege + SeBackupPrivilege + SeRestorePrivilege + SeDebugPrivilege + SeAuditPrivilege + SeSystemEnvironmentPrivilege + SeImpersonatePrivilege + + + + + + 4647 + 0 + 0 + 12545 + 0 + 0x8020000000000000 + + 1191 + + + Security + informant-PC + + + + S-1-5-21-2425377081-3129163575-2985601102-1000 + informant + informant-PC + 0x0000000000025493 + + + + + + 4616 + 1 + 0 + 12288 + 0 + 0x8020000000000000 + + 1192 + + + Security + informant-PC + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x00000000000003e5 + 2015-03-25 15:31:00.240004 + 2015-03-25 15:31:00.240000 + 0x0000000000000330 + C:\Windows\System32\svchost.exe + + + + + + 1100 + 0 + 4 + 103 + 0 + 0x4020000000000000 + + 1193 + + + Security + informant-PC + + + + + + + \ No newline at end of file diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_findall_eventid_time.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_findall_eventid_time.py new file mode 100644 index 0000000..f178e39 --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_findall_eventid_time.py @@ -0,0 +1,22 @@ +import xml.etree.ElementTree as ET +import xml.dom.minidom as minidom + +tree = ET.parse("SecurityEvt_ns_removed.xml") +root = tree.getroot() + +# Iterate through all System elements +for system_element in root.findall(".//System"): + event_id_element = system_element.find("EventID") + time_created_element = system_element.find("TimeCreated") + + # Check if EventID and TimeCreated elements exist + if ( + event_id_element is not None + and event_id_element.text == "4608" + and time_created_element is not None + ): + event_id = event_id_element.text + system_time = time_created_element.get("SystemTime") + + # Print the lists of EventID and TimeCreated values + print("EventIDs: {} and SystemTimes: {}".format(event_id, system_time)) diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_format.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_format.py new file mode 100644 index 0000000..1e80eca --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_format.py @@ -0,0 +1,26 @@ +import xml.etree.ElementTree as ET +import xml.dom.minidom as minidom + +tree = ET.parse("SecurityEvt_ns_removed.xml") +root = tree.getroot() + +# Convert the entire XML to a string with pretty formatting +formatted_xml_str = ET.tostring(root, encoding="utf-8", method="xml").decode("utf-8") + +# Parse the formatted XML content +dom = minidom.parseString(formatted_xml_str) + +# Pretty print the XML content +pretty_xml = dom.toprettyxml(indent=" ") + +# Remove extra blank lines +non_empty_pretty_lines = [line for line in pretty_xml.splitlines() if line.strip()] + +# Join the lines to get the final XML content +formatted_xml = "\n".join(non_empty_pretty_lines) + +# Save the nicely formatted XML to a new file +with open("securityEvt_formatted.xml", "w") as file: + file.write(formatted_xml) + +print("Formatted XML saved to 'securityEvt_formatted.xml'.") diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_list_tags.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_list_tags.py new file mode 100644 index 0000000..bed55e8 --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_list_tags.py @@ -0,0 +1,16 @@ +import xml.etree.ElementTree as ET + +tree = ET.parse("SecurityEvt.xml") +root = tree.getroot() + +# Create an empty set to store unique tag names +tag_names = set() + +# Iterate through the elements and collect unique tag names +for element in root.iter(): + tag_names.add(element.tag) + +# Convert the set to a sorted list and print the tag names +tag_list = sorted(tag_names) +for tag in tag_list: + print(tag) diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_ns_remove.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_ns_remove.py new file mode 100644 index 0000000..87de7db --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_ns_remove.py @@ -0,0 +1,23 @@ +import xml.etree.ElementTree as ET + +tree = ET.parse("SecurityEvt.xml") +root = tree.getroot() + + +# Define a function to recursively remove all namespace prefixes +def remove_namespace_prefix(element): + # print(element.tag) + element.tag = element.tag.split("}", 1)[-1] # Remove namespace prefix + for child in element: + remove_namespace_prefix(child) + + +# Remove namespace prefixes from the root element and its descendants +remove_namespace_prefix(root) + +# Convert the modified XML tree to a string +modified_xml = ET.tostring(root, encoding="utf-8") + +# Save the updated XML to a new file +with open("SecurityEvt_ns_removed.xml", "wb") as f: + f.write(modified_xml) diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_show_first_event.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_show_first_event.py new file mode 100644 index 0000000..9dc05c0 --- /dev/null +++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_show_first_event.py @@ -0,0 +1,24 @@ +import xml.etree.ElementTree as ET +import xml.dom.minidom as minidom + +tree = ET.parse("SecurityEvt_ns_removed.xml") +root = tree.getroot() + +# Find the first Event element +first_event = root.find(".//Event") + +# Check if a Event element was found +if first_event is not None: + # Convert the first Event element to a string with pretty formatting + first_event_str = ET.tostring(first_event, encoding="unicode", method="xml") + + # Parse the XML content + dom = minidom.parseString(first_event_str) + + # Pretty print the XML content + pretty_xml = dom.toprettyxml(indent=" ") + + # Print the nicely formatted XML + print(pretty_xml) +else: + print("No Event elements found in the XML.")