diff --git a/NIST_Data_Leakage_Case/NIST_Answers/lab_generated_file/Registry.zip b/NIST_Data_Leakage_Case/NIST_Answers/lab_generated_file/Registry.zip
new file mode 100644
index 0000000..f4186e2
Binary files /dev/null and b/NIST_Data_Leakage_Case/NIST_Answers/lab_generated_file/Registry.zip differ
diff --git a/NIST_Data_Leakage_Case/NIST_Data_Leakage_00_Env_Setting.pptx b/NIST_Data_Leakage_Case/NIST_Data_Leakage_00_Env_Setting.pptx
index 47120dd..9a69d5a 100644
Binary files a/NIST_Data_Leakage_Case/NIST_Data_Leakage_00_Env_Setting.pptx and b/NIST_Data_Leakage_Case/NIST_Data_Leakage_00_Env_Setting.pptx differ
diff --git a/NIST_Data_Leakage_Case/NIST_Data_Leakage_01_Registry.pptx b/NIST_Data_Leakage_Case/NIST_Data_Leakage_01_Registry.pptx
index 0f14917..4f30e4d 100644
Binary files a/NIST_Data_Leakage_Case/NIST_Data_Leakage_01_Registry.pptx and b/NIST_Data_Leakage_Case/NIST_Data_Leakage_01_Registry.pptx differ
diff --git a/NIST_Data_Leakage_Case/NIST_Data_Leakage_02._WinEvt_XML_Python.pptx b/NIST_Data_Leakage_Case/NIST_Data_Leakage_02._WinEvt_XML_Python.pptx
new file mode 100644
index 0000000..22fbba2
Binary files /dev/null and b/NIST_Data_Leakage_Case/NIST_Data_Leakage_02._WinEvt_XML_Python.pptx differ
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/SecurityEvt.xml b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/SecurityEvt.xml
new file mode 100644
index 0000000..23d89ea
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/SecurityEvt.xml
@@ -0,0 +1,36684 @@
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+1
+
+
+Security
+37L4247F27-25
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+2
+
+
+Security
+37L4247F27-25
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+3
+
+
+Security
+37L4247F27-25
+
+
+0
+0x0000000000035ce9
+
+
+
+
+4731
+0
+0
+13826
+0
+0x8020000000000000
+
+4
+
+
+Security
+37L4247F27-25
+
+
+Backup Operators
+Builtin
+S-1-5-32-551
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+Backup Operators
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+5
+
+
+Security
+37L4247F27-25
+
+
+Backup Operators
+Builtin
+S-1-5-32-551
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4731
+0
+0
+13826
+0
+0x8020000000000000
+
+6
+
+
+Security
+37L4247F27-25
+
+
+Replicator
+Builtin
+S-1-5-32-552
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+Replicator
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+7
+
+
+Security
+37L4247F27-25
+
+
+Replicator
+Builtin
+S-1-5-32-552
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4731
+0
+0
+13826
+0
+0x8020000000000000
+
+8
+
+
+Security
+37L4247F27-25
+
+
+Remote Desktop Users
+Builtin
+S-1-5-32-555
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+Remote Desktop Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+9
+
+
+Security
+37L4247F27-25
+
+
+Remote Desktop Users
+Builtin
+S-1-5-32-555
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4731
+0
+0
+13826
+0
+0x8020000000000000
+
+10
+
+
+Security
+37L4247F27-25
+
+
+Network Configuration Operators
+Builtin
+S-1-5-32-556
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+Network Configuration Operators
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+11
+
+
+Security
+37L4247F27-25
+
+
+Network Configuration Operators
+Builtin
+S-1-5-32-556
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4731
+0
+0
+13826
+0
+0x8020000000000000
+
+12
+
+
+Security
+37L4247F27-25
+
+
+Power Users
+Builtin
+S-1-5-32-547
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+Power Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+13
+
+
+Security
+37L4247F27-25
+
+
+Power Users
+Builtin
+S-1-5-32-547
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4731
+0
+0
+13826
+0
+0x8020000000000000
+
+14
+
+
+Security
+37L4247F27-25
+
+
+Cryptographic Operators
+Builtin
+S-1-5-32-569
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+Cryptographic Operators
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+15
+
+
+Security
+37L4247F27-25
+
+
+Cryptographic Operators
+Builtin
+S-1-5-32-569
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+16
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+17
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+18
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+19
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+20
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+21
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+22
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+23
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+24
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+25
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+26
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+27
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+28
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+29
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+30
+
+
+Security
+37L4247F27-25
+
+
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+31
+
+
+Security
+37L4247F27-25
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+32
+
+
+Security
+37L4247F27-25
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x00000000000454a7
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+33
+
+
+Security
+37L4247F27-25
+
+
+-
+Administrator
+37L4247F27-25
+S-1-5-21-2425377081-3129163575-2985601102-500
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+0x211
+0x211
+-
+-
+-
+-
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+34
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+35
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+36
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+37
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+38
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+39
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+40
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+41
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+42
+
+
+Security
+37L4247F27-25
+
+
+
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+43
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+44
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+45
+
+
+Security
+informant-PC
+
+
+0
+0x000000000000d031
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+46
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+47
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+48
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+49
+
+
+Security
+informant-PC
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+50
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+51
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+52
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+53
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+54
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+55
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+56
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+57
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+58
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+59
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+60
+
+
+Security
+informant-PC
+
+
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+61
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+62
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x0000000000028c63
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+63
+
+
+Security
+informant-PC
+
+
+Administrators
+Builtin
+S-1-5-32-544
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+64
+
+
+Security
+informant-PC
+
+
+Administrators
+Administrators
+Builtin
+S-1-5-32-544
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+65
+
+
+Security
+informant-PC
+
+
+Administrators
+Builtin
+S-1-5-32-544
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Administrators
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+66
+
+
+Security
+informant-PC
+
+
+Users
+Builtin
+S-1-5-32-545
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+67
+
+
+Security
+informant-PC
+
+
+Users
+Users
+Builtin
+S-1-5-32-545
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+68
+
+
+Security
+informant-PC
+
+
+Users
+Builtin
+S-1-5-32-545
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+69
+
+
+Security
+informant-PC
+
+
+Guests
+Builtin
+S-1-5-32-546
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+70
+
+
+Security
+informant-PC
+
+
+Guests
+Guests
+Builtin
+S-1-5-32-546
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+71
+
+
+Security
+informant-PC
+
+
+Guests
+Builtin
+S-1-5-32-546
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Guests
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+72
+
+
+Security
+informant-PC
+
+
+Backup Operators
+Builtin
+S-1-5-32-551
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+73
+
+
+Security
+informant-PC
+
+
+Backup Operators
+Backup Operators
+Builtin
+S-1-5-32-551
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+74
+
+
+Security
+informant-PC
+
+
+Backup Operators
+Builtin
+S-1-5-32-551
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Backup Operators
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+75
+
+
+Security
+informant-PC
+
+
+Replicator
+Builtin
+S-1-5-32-552
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+76
+
+
+Security
+informant-PC
+
+
+Replicator
+Replicator
+Builtin
+S-1-5-32-552
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+77
+
+
+Security
+informant-PC
+
+
+Replicator
+Builtin
+S-1-5-32-552
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Replicator
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+78
+
+
+Security
+informant-PC
+
+
+Remote Desktop Users
+Builtin
+S-1-5-32-555
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+79
+
+
+Security
+informant-PC
+
+
+Remote Desktop Users
+Remote Desktop Users
+Builtin
+S-1-5-32-555
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+80
+
+
+Security
+informant-PC
+
+
+Remote Desktop Users
+Builtin
+S-1-5-32-555
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Remote Desktop Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+81
+
+
+Security
+informant-PC
+
+
+Network Configuration Operators
+Builtin
+S-1-5-32-556
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+82
+
+
+Security
+informant-PC
+
+
+Network Configuration Operators
+Network Configuration Operators
+Builtin
+S-1-5-32-556
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+83
+
+
+Security
+informant-PC
+
+
+Network Configuration Operators
+Builtin
+S-1-5-32-556
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Network Configuration Operators
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+84
+
+
+Security
+informant-PC
+
+
+Power Users
+Builtin
+S-1-5-32-547
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+85
+
+
+Security
+informant-PC
+
+
+Power Users
+Power Users
+Builtin
+S-1-5-32-547
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+86
+
+
+Security
+informant-PC
+
+
+Power Users
+Builtin
+S-1-5-32-547
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Power Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+87
+
+
+Security
+informant-PC
+
+
+Performance Monitor Users
+Builtin
+S-1-5-32-558
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+88
+
+
+Security
+informant-PC
+
+
+Performance Monitor Users
+Performance Monitor Users
+Builtin
+S-1-5-32-558
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+89
+
+
+Security
+informant-PC
+
+
+Performance Monitor Users
+Builtin
+S-1-5-32-558
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Performance Monitor Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+90
+
+
+Security
+informant-PC
+
+
+Performance Log Users
+Builtin
+S-1-5-32-559
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+91
+
+
+Security
+informant-PC
+
+
+Performance Log Users
+Performance Log Users
+Builtin
+S-1-5-32-559
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+92
+
+
+Security
+informant-PC
+
+
+Performance Log Users
+Builtin
+S-1-5-32-559
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Performance Log Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+93
+
+
+Security
+informant-PC
+
+
+Distributed COM Users
+Builtin
+S-1-5-32-562
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+94
+
+
+Security
+informant-PC
+
+
+Distributed COM Users
+Distributed COM Users
+Builtin
+S-1-5-32-562
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+95
+
+
+Security
+informant-PC
+
+
+Distributed COM Users
+Builtin
+S-1-5-32-562
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Distributed COM Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+96
+
+
+Security
+informant-PC
+
+
+IIS_IUSRS
+Builtin
+S-1-5-32-568
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+97
+
+
+Security
+informant-PC
+
+
+IIS_IUSRS
+IIS_IUSRS
+Builtin
+S-1-5-32-568
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+98
+
+
+Security
+informant-PC
+
+
+IIS_IUSRS
+Builtin
+S-1-5-32-568
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+IIS_IUSRS
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+99
+
+
+Security
+informant-PC
+
+
+Cryptographic Operators
+Builtin
+S-1-5-32-569
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+100
+
+
+Security
+informant-PC
+
+
+Cryptographic Operators
+Cryptographic Operators
+Builtin
+S-1-5-32-569
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+101
+
+
+Security
+informant-PC
+
+
+Cryptographic Operators
+Builtin
+S-1-5-32-569
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Cryptographic Operators
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+102
+
+
+Security
+informant-PC
+
+
+Event Log Readers
+Builtin
+S-1-5-32-573
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+103
+
+
+Security
+informant-PC
+
+
+Event Log Readers
+Event Log Readers
+Builtin
+S-1-5-32-573
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+104
+
+
+Security
+informant-PC
+
+
+Event Log Readers
+Builtin
+S-1-5-32-573
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Event Log Readers
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+105
+
+
+Security
+informant-PC
+
+
+-
+Administrator
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-500
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Administrator
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+11/20/2010 8:57:24 PM
+%%1794
+513
+-
+0x211
+0x211
+-
+%%1793
+-
+%%1797
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+106
+
+
+Security
+informant-PC
+
+
+-
+Administrator
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-500
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Administrator
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+11/20/2010 8:57:24 PM
+%%1794
+513
+-
+0x211
+0x211
+-
+%%1793
+-
+%%1797
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+107
+
+
+Security
+informant-PC
+
+
+-
+Guest
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-501
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Guest
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x215
+0x215
+-
+%%1793
+-
+%%1797
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+108
+
+
+Security
+informant-PC
+
+
+-
+Guest
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-501
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Guest
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x215
+0x215
+-
+%%1793
+-
+%%1797
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+109
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+2015-03-25 10:34:25.685648
+2015-03-22 14:33:53.237000
+0x0000000000000340
+C:\Windows\System32\oobe\msoobe.exe
+
+
+
+
+4728
+0
+0
+13826
+0
+0x8020000000000000
+
+110
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1000
+None
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-513
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4720
+0
+0
+13824
+0
+0x8020000000000000
+
+111
+
+
+Security
+informant-PC
+
+
+informant
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1000
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+informant
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x0
+0x15
+
+ %%2080
+ %%2082
+ %%2084
+%%1793
+-
+%%1797
+
+
+
+
+4732
+0
+0
+13826
+0
+0x8020000000000000
+
+112
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1000
+Users
+Builtin
+S-1-5-32-545
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4722
+0
+0
+13824
+0
+0x8020000000000000
+
+113
+
+
+Security
+informant-PC
+
+
+informant
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1000
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+114
+
+
+Security
+informant-PC
+
+
+-
+informant
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1000
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+informant
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x15
+0x14
+
+ %%2048
+%%1793
+-
+%%1797
+
+
+
+
+4732
+0
+0
+13826
+0
+0x8020000000000000
+
+115
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1000
+Administrators
+Builtin
+S-1-5-32-544
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4733
+0
+0
+13826
+0
+0x8020000000000000
+
+116
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1000
+Users
+Builtin
+S-1-5-32-545
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+117
+
+
+Security
+informant-PC
+
+
+-
+informant
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1000
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+informant
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+3/22/2015 10:33:54 AM
+%%1794
+513
+-
+0x14
+0x214
+
+ %%2089
+-
+-
+%%1797
+
+
+
+
+4724
+0
+0
+13824
+0
+0x8020000000000000
+
+118
+
+
+Security
+informant-PC
+
+
+informant
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1000
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+119
+
+
+Security
+informant-PC
+
+
+-
+informant
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1000
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+120
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+121
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+122
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+123
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000003be29
+2
+User32
+Negotiate
+WIN-D9RGPJQ68G8
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+124
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000003db0a
+2
+User32
+Negotiate
+WIN-D9RGPJQ68G8
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+125
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000003be29
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+126
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+127
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+128
+
+
+Security
+informant-PC
+
+
+
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+129
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000003db0a
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+130
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+131
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+132
+
+
+Security
+informant-PC
+
+
+0
+0x000000000000b8dc
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+133
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+134
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+135
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+136
+
+
+Security
+informant-PC
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+137
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+138
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+139
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+140
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+141
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+142
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+143
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+144
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+145
+
+
+Security
+informant-PC
+
+
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+146
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+147
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x000000000001a667
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+148
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+149
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+150
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+151
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+152
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x0000000000000184
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+153
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000026923
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000184
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+154
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000026951
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000184
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+155
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000026923
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+156
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+157
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+158
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+159
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+160
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+161
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4904
+0
+0
+13568
+0
+0x8020000000000000
+
+162
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x0000000000069adb
+0x0000000000000bc0
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4905
+0
+0
+13568
+0
+0x8020000000000000
+
+163
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x0000000000069adb
+0x0000000000000bc0
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4904
+0
+0
+13568
+0
+0x8020000000000000
+
+164
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000000835e3
+0x0000000000000bc0
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4905
+0
+0
+13568
+0
+0x8020000000000000
+
+165
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000000835e3
+0x0000000000000bc0
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+166
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+167
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+168
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+169
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+170
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+171
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+172
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+173
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4904
+0
+0
+13568
+0
+0x8020000000000000
+
+174
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000001fa262
+0x0000000000000e6c
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4905
+0
+0
+13568
+0
+0x8020000000000000
+
+175
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000001fa262
+0x0000000000000e6c
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+176
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+177
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+178
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\winsxs\Temp\PendingRenames\a86dcf49b364d00184220000f80e440b.install.ins
+0x00000000000086e8
+
+S:ARAI
+0x0000000000000ef8
+C:\Windows\servicing\TrustedInstaller.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+179
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\winsxs\Temp\PendingRenames\08cfd149b364d00185220000f80e440b.install.ins
+0x00000000000088b0
+
+S:ARAI
+0x0000000000000ef8
+C:\Windows\servicing\TrustedInstaller.exe
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+180
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000026951
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+181
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\DWrite.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+182
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d2d1.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+183
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\msmpeg2vdec.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+184
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+185
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d3d10core.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+186
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+187
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+188
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\XpsGdiConverter.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+189
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+190
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d3d10warp.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+191
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+192
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\dxgi.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+193
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\WMPhoto.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+194
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\FntCache.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+195
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+196
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d3d10_1.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+197
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\WindowsCodecsExt.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+198
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+199
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d3d10level9.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+200
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\UIAnimation.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+201
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+202
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d3d10_1core.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+203
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\XpsPrint.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+204
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+205
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d3d10.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+206
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\WindowsCodecs.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+207
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d3d11.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+208
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+209
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+210
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+211
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+212
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+213
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\da-DK\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+214
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\da-DK\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+215
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\da-DK\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+216
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\da-DK\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+217
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nb-NO\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+218
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nb-NO\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+219
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nb-NO\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+220
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nb-NO\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+221
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\spp\tokens\ppdlic\msmpeg2vdec-ppdlic.xrm-ms
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+222
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ru-RU\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+223
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ru-RU\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+224
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ru-RU\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+225
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ru-RU\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+226
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ja-JP\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+227
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ja-JP\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+228
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ja-JP\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+229
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ja-JP\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+230
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ja-JP\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+231
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-CN\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+232
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-CN\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+233
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-CN\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+234
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-CN\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+235
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\cs-CZ\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+236
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\cs-CZ\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+237
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\cs-CZ\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+238
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\cs-CZ\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+239
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\de-DE\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+240
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\de-DE\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+241
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\de-DE\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+242
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\de-DE\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+243
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\de-DE\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+244
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-TW\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+245
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-TW\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+246
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-TW\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+247
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-TW\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+248
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\es-ES\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+249
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\es-ES\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+250
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\es-ES\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+251
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\es-ES\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+252
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\es-ES\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+253
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\sv-SE\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+254
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\sv-SE\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+255
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\sv-SE\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+256
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\sv-SE\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+257
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\tr-TR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+258
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\tr-TR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+259
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\tr-TR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+260
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\tr-TR\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+261
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fi-FI\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+262
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fi-FI\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+263
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fi-FI\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+264
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fi-FI\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+265
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fr-FR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+266
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fr-FR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+267
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fr-FR\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+268
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fr-FR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+269
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fr-FR\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+270
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nl-NL\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+271
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nl-NL\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+272
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nl-NL\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+273
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nl-NL\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+274
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nl-NL\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+275
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\el-GR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+276
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\el-GR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+277
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\el-GR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+278
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\el-GR\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+279
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-HK\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+280
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-HK\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+281
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-HK\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+282
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-HK\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+283
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\hu-HU\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+284
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\hu-HU\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+285
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\hu-HU\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+286
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\hu-HU\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+287
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ko-KR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+288
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ko-KR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+289
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ko-KR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+290
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ko-KR\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+291
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pl-PL\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+292
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pl-PL\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+293
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pl-PL\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+294
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pl-PL\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+295
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-PT\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+296
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-PT\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+297
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-PT\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+298
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-PT\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+299
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\it-IT\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+300
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\it-IT\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+301
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\it-IT\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+302
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\it-IT\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+303
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\it-IT\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+304
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-BR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+305
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-BR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+306
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-BR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+307
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-BR\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+308
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\DWrite.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+309
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d2d1.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+310
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\msmpeg2vdec.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+311
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+312
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d3d10core.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+313
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+314
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+315
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\XpsGdiConverter.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+316
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+317
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d3d10warp.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+318
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\dxgi.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+319
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+320
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\WMPhoto.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+321
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+322
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d3d10_1.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+323
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d3d10level9.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+324
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\WindowsCodecsExt.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+325
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+326
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+327
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\UIAnimation.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+328
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d3d10_1core.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+329
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\XpsPrint.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+330
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+331
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d3d10.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+332
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\WindowsCodecs.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+333
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d3d11.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+334
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+335
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+336
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+337
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+338
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\da-DK\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+339
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\da-DK\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+340
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\da-DK\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+341
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\nb-NO\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+342
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\nb-NO\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+343
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\nb-NO\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+344
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\spp\tokens\ppdlic\msmpeg2vdec-ppdlic.xrm-ms
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+345
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ru-RU\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+346
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ru-RU\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+347
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ru-RU\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+348
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ja-JP\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+349
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ja-JP\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+350
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ja-JP\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+351
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ja-JP\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+352
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-CN\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+353
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-CN\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+354
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-CN\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+355
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\cs-CZ\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+356
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\cs-CZ\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+357
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\cs-CZ\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+358
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\de-DE\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+359
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\de-DE\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+360
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\de-DE\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+361
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\de-DE\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+362
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-TW\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+363
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-TW\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+364
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-TW\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+365
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\es-ES\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+366
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\es-ES\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+367
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\es-ES\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+368
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\es-ES\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+369
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\sv-SE\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+370
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\sv-SE\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+371
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\sv-SE\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+372
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\tr-TR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+373
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\tr-TR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+374
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\tr-TR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+375
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\fi-FI\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+376
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\fi-FI\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+377
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\fi-FI\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+378
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\fr-FR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+379
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\fr-FR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+380
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\fr-FR\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+381
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\fr-FR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+382
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\nl-NL\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+383
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\nl-NL\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+384
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\nl-NL\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+385
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\nl-NL\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+386
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\el-GR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+387
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\el-GR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+388
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\el-GR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+389
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-HK\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+390
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-HK\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+391
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-HK\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+392
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\hu-HU\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+393
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\hu-HU\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+394
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\hu-HU\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+395
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ko-KR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+396
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ko-KR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+397
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ko-KR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+398
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pl-PL\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+399
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pl-PL\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+400
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pl-PL\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+401
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pt-PT\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+402
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pt-PT\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+403
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pt-PT\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+404
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\it-IT\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+405
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\it-IT\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+406
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\it-IT\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+407
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\it-IT\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+408
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pt-BR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+409
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pt-BR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+410
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pt-BR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+411
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ntoskrnl.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+412
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntoskrnl.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+413
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntkrnlpa.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+414
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\AppPatch\acwow64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+415
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+416
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+417
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+418
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+419
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+420
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64cpu.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+421
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+422
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+423
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+424
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+425
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+426
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+427
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+428
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ntvdm64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+429
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+430
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+431
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+432
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+433
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+434
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+435
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\conhost.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+436
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+437
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+438
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+439
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64win.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+440
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+441
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\kernel32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+442
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\KernelBase.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+443
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+444
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+445
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+446
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+447
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\winsrv.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+448
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+449
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+450
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+451
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+452
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+453
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\setup16.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+454
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\user.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+455
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+456
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntvdm64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+457
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+458
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+459
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+460
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+461
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+462
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+463
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+464
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+465
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+466
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\instnm.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+467
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+468
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+469
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+470
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+471
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+472
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+473
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\kernel32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+474
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+475
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+476
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+477
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+478
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+479
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\KernelBase.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+480
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+481
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+482
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+483
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+484
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+485
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\wow32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+486
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\AppPatch\acwow64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+487
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+488
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+489
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+490
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+491
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+492
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64cpu.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+493
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+494
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+495
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+496
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+497
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+498
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+499
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+500
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ntvdm64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+501
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+502
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+503
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+504
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+505
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+506
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+507
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\conhost.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+508
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+509
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+510
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+511
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64win.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+512
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+513
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\kernel32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+514
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\KernelBase.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+515
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+516
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+517
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+518
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+519
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\winsrv.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+520
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+521
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+522
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+523
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\KernelBase.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+524
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\instnm.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+525
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+526
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+527
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+528
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+529
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\user.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+530
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+531
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+532
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+533
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+534
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+535
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+536
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+537
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntvdm64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+538
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+539
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+540
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+541
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+542
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+543
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+544
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\wow32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+545
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+546
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+547
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+548
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+549
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\kernel32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+550
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\KernelBase.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+551
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+552
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+553
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+554
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+555
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+556
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\setup16.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+557
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+558
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+559
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\KernelBase.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+560
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Fonts\seguisym.ttf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+561
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Fonts\segoeui.ttf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+562
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Fonts\segoeuiz.ttf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+563
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Fonts\segoeuib.ttf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+564
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Fonts\segoeuii.ttf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+565
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\taskhost.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+566
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\drivers\afd.sys
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+567
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\drivers\FWPKCLNT.SYS
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+568
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\drivers\tcpip.sys
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+569
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\drivers\netio.sys
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+570
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\mswsock.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+571
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\mswsock.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+572
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\smss.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+573
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\csrsrv.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+574
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ntdll.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+575
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ntoskrnl.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+576
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\apisetschema.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+577
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntdll.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+578
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntoskrnl.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+579
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntkrnlpa.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+580
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\AppPatch\acwow64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+581
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\tdh.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+582
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+583
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+584
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+585
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+586
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+587
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64cpu.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+588
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+589
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+590
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+591
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+592
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+593
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+594
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+595
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ntvdm64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+596
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+597
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+598
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+599
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+600
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+601
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+602
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\conhost.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+603
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+604
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\advapi32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+605
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+606
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+607
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64win.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+608
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+609
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\kernel32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+610
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\KernelBase.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+611
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+612
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+613
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+614
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+615
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\winsrv.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+616
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+617
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+618
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+619
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\instnm.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+620
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\tdh.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+621
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+622
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+623
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+624
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+625
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\user.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+626
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+627
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+628
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+629
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+630
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+631
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+632
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+633
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntvdm64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+634
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+635
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+636
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+637
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+638
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+639
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+640
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\wow32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+641
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+642
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\advapi32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+643
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+644
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+645
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+646
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\KernelBase.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+647
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\kernel32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+648
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+649
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+650
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+651
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+652
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+653
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\setup16.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+654
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+655
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+656
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Common Files\microsoft shared\VGX\VGX.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+657
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\D3DCompiler_47.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+658
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\iexplore.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+659
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\ie9props.propdesc
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+660
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\JSProfilerCore.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+661
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\jsprofilerui.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+662
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\pdm.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+663
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\pdmproxy100.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+664
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\DiagnosticsTap.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+665
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\ExtExport.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+666
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\sqmapi.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+667
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\jsdebuggeride.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+668
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\jsdbgui.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+669
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\msdbg2.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+670
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\networkinspection.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+671
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\iedvtool.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+672
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\ielowutil.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+673
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\ieproxy.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+674
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\ieinstal.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+675
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\F12Tools.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+676
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\IEShims.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+677
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\SIGNUP\install.ins
+0x000000000000001c
+S:AI
+
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+678
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\F12Tools.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+679
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\jsprofilerui.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+680
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\jsdbgui.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+681
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\iedvtool.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+682
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\DiagnosticsTap.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+683
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\ieinstal.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+684
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\eula.rtf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+685
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\networkinspection.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+686
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+687
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+688
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\iexplore.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+689
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\Timeline_is.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+690
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\pdm.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+691
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\msdbg2.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+692
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\Timeline.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+693
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\JSProfilerCore.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+694
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\ielowutil.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+695
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\ieinstal.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+696
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\IEShims.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+697
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\pdmproxy100.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+698
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\perfcore.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+699
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\D3DCompiler_47.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+700
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\iedvtool.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+701
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\ieproxy.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+702
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\DiagnosticsTap.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+703
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\iediagcmd.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+704
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\perf_nt.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+705
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\DiagnosticsHub.DataWarehouse.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+706
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\F12Tools.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+707
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\jsdebuggeride.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+708
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\networkinspection.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+709
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\jsprofilerui.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+710
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\DiagnosticsHub.ScriptedSandboxPlugin.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+711
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\MemoryAnalyzer.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+712
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\F12Resources.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+713
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\ie9props.propdesc
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+714
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\jsdbgui.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+715
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\F12.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+716
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\DiagnosticsHub_is.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+717
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\Timeline.cpu.xml
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+718
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\sqmapi.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+719
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\jsprofilerui.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+720
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\F12Tools.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+721
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\F12.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+722
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\jsdbgui.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+723
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\iedvtool.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+724
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\F12Resources.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+725
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\ieinstal.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+726
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\DiagnosticsTap.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+727
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\networkinspection.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+728
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\eula.rtf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+729
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+730
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\images\bing.ico
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+731
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\SIGNUP\install.ins
+0x000000000000001c
+S:AI
+
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+732
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieapfltr.dat
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+733
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\url.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+734
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\mshta.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+735
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\jsproxy.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+736
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieUnatt.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+737
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieui.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+738
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\mshtmlmedia.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+739
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieetwproxystub.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+740
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\jsIntl.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+741
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\RegisterIEPKEYs.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+742
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\iepeers.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+743
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\elshyph.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+744
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieframe.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+745
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ie4uinit.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+746
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\licmgr10.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+747
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\mshtmler.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+748
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\iexpress.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+749
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\IEAdvpack.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+750
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\dxtrans.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+751
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wextract.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+752
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieetwcollectorres.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+753
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\SetIEInstalledDate.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+754
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wininet.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+755
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\MshtmlDac.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+756
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\jscript.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+757
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\JavaScriptCollectionAgent.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+758
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\msfeedssync.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+759
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\webcheck.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+760
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\MsSpellCheckingFacility.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+761
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\icardie.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+762
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\iertutil.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+763
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pngfilt.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+764
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\msls31.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+765
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieetwcollector.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+766
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\jscript9diag.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+767
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\iedkcs32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+768
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\iesetup.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+769
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\iernonce.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+770
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\vbscript.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+771
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\inseng.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+772
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\iesysprep.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+773
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\inetcpl.cpl
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+774
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\jscript9.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+775
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\occache.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+776
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieapfltr.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+777
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\html.iec
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+778
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\imgutil.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+779
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\msfeeds.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+780
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieuinit.inf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+781
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\tdc.ocx
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+782
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\mshtml.tlb
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+783
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\mshtml.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+784
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\mshtmled.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+785
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\urlmon.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+786
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\msfeedsbs.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+787
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\msrating.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+788
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\dxtmsft.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+789
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\iesetup.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+790
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\mshtmlmedia.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+791
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\icardie.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+792
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\iepeers.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+793
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\IEAdvpack.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+794
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\jsIntl.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+795
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\occache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+796
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\MsSpellCheckingFacility.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+797
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\wextract.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+798
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\ieunatt.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+799
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\ie4uinit.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+800
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\iernonce.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+801
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\elshyph.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+802
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\jscript.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+803
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\msrating.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+804
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\ieframe.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+805
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\msfeedsbs.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+806
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\vbscript.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+807
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\ieui.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+808
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\html.iec.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+809
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\iexpress.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+810
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\mshtmler.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+811
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\urlmon.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+812
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\jscript9.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+813
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\iedkcs32.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+814
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\webcheck.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+815
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\wininet.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+816
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\mshta.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+817
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\licmgr10.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+818
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\mshtml.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+819
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\inseng.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+820
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\inetcpl.cpl.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+821
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\ieetwcollectorres.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+822
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\spp\tokens\ppdlic\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+823
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wdi\perftrack\Microsoft-Windows-IE-HTMLRendering.ptxml
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+824
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wdi\perftrack\ieframe.ptxml
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+825
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wdi\perftrack\Microsoft-Windows-IE-F12-Provider.ptxml
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+826
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\migration\WininetPlugin.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+827
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\PolicyDefinitions\inetres.admx
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+828
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\PolicyDefinitions\en-US\InetRes.adml
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+829
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ieapfltr.dat
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+830
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\mshta.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+831
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\jsproxy.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+832
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\url.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+833
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ieUnatt.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+834
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ieui.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+835
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\mshtmlmedia.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+836
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\jsIntl.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+837
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ieetwproxystub.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+838
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\RegisterIEPKEYs.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+839
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\elshyph.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+840
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\iepeers.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+841
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ieframe.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+842
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\licmgr10.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+843
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\mshtmler.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+844
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\iexpress.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+845
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\IEAdvpack.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+846
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\wextract.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+847
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\dxtrans.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+848
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\wininet.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+849
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\SetIEInstalledDate.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+850
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\MshtmlDac.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+851
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\jscript.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+852
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+853
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\msfeedssync.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+854
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\webcheck.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+855
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\icardie.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+856
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\iertutil.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+857
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pngfilt.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+858
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\jscript9diag.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+859
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\msls31.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+860
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\iedkcs32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+861
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\iesetup.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+862
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\iernonce.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+863
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\vbscript.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+864
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\iesysprep.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+865
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\inseng.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+866
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\jscript9.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+867
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\occache.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+868
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\inetcpl.cpl
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+869
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ieapfltr.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+870
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\html.iec
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+871
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\imgutil.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+872
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\msfeeds.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+873
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ieuinit.inf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+874
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\tdc.ocx
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+875
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\mshtml.tlb
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+876
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\mshtml.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+877
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\mshtmled.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+878
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\urlmon.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+879
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\msfeedsbs.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+880
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\msrating.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+881
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\dxtmsft.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+882
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\webcheck.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+883
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\iernonce.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+884
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\inseng.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+885
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\html.iec.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+886
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\msrating.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+887
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\wininet.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+888
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\ieui.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+889
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\elshyph.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+890
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\iexpress.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+891
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\ieetwcollectorres.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+892
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\occache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+893
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\ieframe.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+894
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\mshta.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+895
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\mshtml.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+896
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\wextract.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+897
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\iesetup.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+898
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\ieunatt.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+899
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\licmgr10.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+900
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\mshtmler.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+901
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\jscript.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+902
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\vbscript.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+903
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\iepeers.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+904
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\IEAdvpack.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+905
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\msfeedsbs.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+906
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\mshtmlmedia.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+907
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\iedkcs32.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+908
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\urlmon.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+909
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\inetcpl.cpl.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+910
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\jscript9.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+911
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\icardie.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+912
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\wdi\perftrack\wow64_ieframe.ptxml
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+913
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\wdi\perftrack\wow64_Microsoft-Windows-IE-HTMLRendering.ptxml
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+914
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\migration\WininetPlugin.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+915
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.acl
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+916
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.dub
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+917
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.lex
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+918
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Globalization\ELS\HyphenationDictionaries\MsHy7en.lex
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+919
+
+
+Security
+informant-PC
+
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+920
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+921
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+922
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+923
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+924
+
+
+Security
+informant-PC
+
+
+0
+0x000000000000c957
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+925
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+926
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+927
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+928
+
+
+Security
+informant-PC
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+929
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+930
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+931
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+932
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+933
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+934
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+935
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+936
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+937
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+938
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+939
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+940
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x000000000001a427
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+941
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+942
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+943
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+944
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Globalization\ELS\HyphenationDictionaries
+0x00000000000002d4
+
+S:ARAI(AU;SAFA;0x1f0116;;;WD)
+0x00000000000003e8
+C:\Windows\servicing\TrustedInstaller.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+945
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Globalization\ELS\SpellDictionaries
+0x00000000000002d0
+
+S:ARAI(AU;SAFA;0x1f0116;;;WD)
+0x00000000000003e8
+C:\Windows\servicing\TrustedInstaller.exe
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+946
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+947
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000056f8b
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+948
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000056fb9
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+949
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000056f8b
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+950
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+951
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+952
+
+
+Security
+informant-PC
+
+
+
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+953
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000056fb9
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+954
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+955
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+956
+
+
+Security
+informant-PC
+
+
+0
+0x000000000000c54c
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+957
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+958
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+959
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+960
+
+
+Security
+informant-PC
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+961
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+962
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+963
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+964
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+965
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+966
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+967
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+968
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+969
+
+
+Security
+informant-PC
+
+
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+970
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+971
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x000000000001c185
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+972
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+973
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+974
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000022517
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+975
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+976
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+977
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+978
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+979
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+980
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+981
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+982
+
+
+Security
+informant-PC
+
+
+-
+informant
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1000
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000022517
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4728
+0
+0
+13826
+0
+0x8020000000000000
+
+983
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1001
+None
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-513
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4720
+0
+0
+13824
+0
+0x8020000000000000
+
+984
+
+
+Security
+informant-PC
+
+
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+admin11
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x0
+0x15
+
+ %%2080
+ %%2082
+ %%2084
+%%1793
+-
+%%1797
+
+
+
+
+4722
+0
+0
+13824
+0
+0x8020000000000000
+
+985
+
+
+Security
+informant-PC
+
+
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+986
+
+
+Security
+informant-PC
+
+
+-
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+admin11
+admin11
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x15
+0x210
+
+ %%2048
+ %%2050
+ %%2089
+%%1793
+-
+%%1797
+
+
+
+
+4732
+0
+0
+13826
+0
+0x8020000000000000
+
+987
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1001
+Users
+Builtin
+S-1-5-32-545
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+988
+
+
+Security
+informant-PC
+
+
+-
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4732
+0
+0
+13826
+0
+0x8020000000000000
+
+989
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1001
+Administrators
+Builtin
+S-1-5-32-544
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+990
+
+
+Security
+informant-PC
+
+
+-
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+admin11
+admin11
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x210
+0x210
+-
+%%1793
+-
+%%1797
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+991
+
+
+Security
+informant-PC
+
+
+-
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+admin11
+admin11
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+3/22/2015 11:52:10 AM
+%%1794
+513
+-
+0x210
+0x210
+-
+-
+-
+%%1797
+
+
+
+
+4724
+0
+0
+13824
+0
+0x8020000000000000
+
+992
+
+
+Security
+informant-PC
+
+
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+993
+
+
+Security
+informant-PC
+
+
+-
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4728
+0
+0
+13826
+0
+0x8020000000000000
+
+994
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1002
+None
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-513
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4720
+0
+0
+13824
+0
+0x8020000000000000
+
+995
+
+
+Security
+informant-PC
+
+
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+ITechTeam
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x0
+0x15
+
+ %%2080
+ %%2082
+ %%2084
+%%1793
+-
+%%1797
+
+
+
+
+4722
+0
+0
+13824
+0
+0x8020000000000000
+
+996
+
+
+Security
+informant-PC
+
+
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+997
+
+
+Security
+informant-PC
+
+
+-
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+ITechTeam
+ITechTeam
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x15
+0x210
+
+ %%2048
+ %%2050
+ %%2089
+%%1793
+-
+%%1797
+
+
+
+
+4732
+0
+0
+13826
+0
+0x8020000000000000
+
+998
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1002
+Users
+Builtin
+S-1-5-32-545
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+999
+
+
+Security
+informant-PC
+
+
+-
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4732
+0
+0
+13826
+0
+0x8020000000000000
+
+1000
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1002
+Administrators
+Builtin
+S-1-5-32-544
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1001
+
+
+Security
+informant-PC
+
+
+-
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+ITechTeam
+ITechTeam
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x210
+0x210
+-
+%%1793
+-
+%%1797
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1002
+
+
+Security
+informant-PC
+
+
+-
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+ITechTeam
+ITechTeam
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+3/22/2015 11:52:45 AM
+%%1794
+513
+-
+0x210
+0x210
+-
+-
+-
+%%1797
+
+
+
+
+4724
+0
+0
+13824
+0
+0x8020000000000000
+
+1003
+
+
+Security
+informant-PC
+
+
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1004
+
+
+Security
+informant-PC
+
+
+-
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4728
+0
+0
+13826
+0
+0x8020000000000000
+
+1005
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1003
+None
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-513
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4720
+0
+0
+13824
+0
+0x8020000000000000
+
+1006
+
+
+Security
+informant-PC
+
+
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+temporary
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x0
+0x15
+
+ %%2080
+ %%2082
+ %%2084
+%%1793
+-
+%%1797
+
+
+
+
+4722
+0
+0
+13824
+0
+0x8020000000000000
+
+1007
+
+
+Security
+informant-PC
+
+
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1008
+
+
+Security
+informant-PC
+
+
+-
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+temporary
+temporary
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x15
+0x210
+
+ %%2048
+ %%2050
+ %%2089
+%%1793
+-
+%%1797
+
+
+
+
+4732
+0
+0
+13826
+0
+0x8020000000000000
+
+1009
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1003
+Users
+Builtin
+S-1-5-32-545
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1010
+
+
+Security
+informant-PC
+
+
+-
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1011
+
+
+Security
+informant-PC
+
+
+-
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+temporary
+temporary
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x210
+0x210
+-
+%%1793
+-
+%%1797
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1012
+
+
+Security
+informant-PC
+
+
+-
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+temporary
+temporary
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+3/22/2015 11:53:11 AM
+%%1794
+513
+-
+0x210
+0x210
+-
+-
+-
+%%1797
+
+
+
+
+4724
+0
+0
+13824
+0
+0x8020000000000000
+
+1013
+
+
+Security
+informant-PC
+
+
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1014
+
+
+Security
+informant-PC
+
+
+-
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1015
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+admin11
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x00000000000007a0
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1016
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x0000000000094b57
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000007a0
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1017
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x0000000000094b71
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000007a0
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1018
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x0000000000094b57
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+1019
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x0000000000094b71
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1020
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+temporary
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x000000000000072c
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1021
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1003
+temporary
+informant-PC
+0x00000000000f2cd6
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x000000000000072c
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1022
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x0000000000094b71
+2
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1023
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x0000000000094b57
+2
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+1024
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1003
+temporary
+informant-PC
+0x00000000000f2cd6
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1025
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+admin11
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x0000000000000954
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1026
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x00000000001354b3
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000954
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1027
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x00000000001354c8
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000954
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1028
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x00000000001354b3
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+1029
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x00000000001354c8
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1030
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x0000000000000c1c
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1031
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157b62
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000c1c
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1032
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157b78
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000c1c
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1033
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157b62
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1034
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157b78
+2
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1035
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157b62
+2
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1036
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1003
+temporary
+informant-PC
+0x00000000000f2cd6
+2
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1037
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x00000000001354c8
+2
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1038
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x00000000001354b3
+2
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+1039
+
+
+Security
+informant-PC
+
+
+
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+1040
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000022517
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+1041
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1042
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+1043
+
+
+Security
+informant-PC
+
+
+0
+0x000000000000bac4
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1044
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1045
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1046
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1047
+
+
+Security
+informant-PC
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1048
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1049
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1050
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1051
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1052
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1053
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1054
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1055
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+1056
+
+
+Security
+informant-PC
+
+
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+1057
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1058
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x000000000001b9a4
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1059
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x00000000000001a8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1060
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000002359c
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001a8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1061
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000235cc
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001a8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1062
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000002359c
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1063
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1064
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+1065
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+2015-03-23 17:25:47.192598
+2015-03-23 17:25:47.191999
+0x0000000000000358
+C:\Windows\System32\svchost.exe
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1066
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1067
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1068
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1069
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+1070
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+2015-03-23 18:57:01.113134
+2015-03-23 19:08:15.571480
+0x0000000000000358
+C:\Windows\System32\svchost.exe
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+1071
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+2015-03-23 19:08:15.571480
+2015-03-23 19:08:15.570999
+0x0000000000000358
+C:\Windows\System32\svchost.exe
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+1072
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+2015-03-23 19:08:46.443419
+2015-03-23 19:08:46.442999
+0x0000000000000358
+C:\Windows\System32\svchost.exe
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1073
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1074
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1075
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1076
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1077
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1078
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1079
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1080
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4904
+0
+0
+13568
+0
+0x8020000000000000
+
+1081
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000002c2083
+0x0000000000000d40
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4905
+0
+0
+13568
+0
+0x8020000000000000
+
+1082
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000002c2083
+0x0000000000000d40
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1083
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000235cc
+{00000000-0000-0000-0000-000000000000}
+Company
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+Company-PC
+Company-PC
+0x0000000000000004
+
+-
+-
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+1084
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000235cc
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+1085
+
+
+Security
+informant-PC
+
+
+
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+1086
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1087
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+1088
+
+
+Security
+informant-PC
+
+
+0
+0x000000000000b683
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1089
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1090
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1091
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1092
+
+
+Security
+informant-PC
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1093
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1094
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1095
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1096
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1097
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1098
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1099
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1100
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+1101
+
+
+Security
+informant-PC
+
+
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+1102
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1103
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x000000000001c0ce
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1104
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1105
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000002269c
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1106
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000226c4
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1107
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000002269c
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1108
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1109
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1110
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1111
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1112
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000226c4
+{00000000-0000-0000-0000-000000000000}
+Company
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+Company-PC
+Company-PC
+0x0000000000000004
+
+-
+-
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1113
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1114
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1115
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1116
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1117
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1118
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1119
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1120
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1121
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1122
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1123
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1124
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000006cabcf
+7
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1125
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000006cabdd
+7
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1126
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000006cabcf
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1127
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000006cabdd
+7
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1128
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000006cabcf
+7
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1129
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1130
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+1131
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000226c4
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+1132
+
+
+Security
+informant-PC
+
+
+
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+1133
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1134
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+1135
+
+
+Security
+informant-PC
+
+
+0
+0x000000000000ba7d
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1136
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1137
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1138
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1139
+
+
+Security
+informant-PC
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1140
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1141
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1142
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1143
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1144
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1145
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1146
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1147
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+1148
+
+
+Security
+informant-PC
+
+
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+1149
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1150
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x000000000001c0d1
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1151
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1152
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000025465
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1153
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000025493
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1154
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000025465
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1155
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1156
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1157
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1158
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1159
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1160
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+1161
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+2015-03-25 13:29:46.566790
+2015-03-25 14:13:47.009901
+0x0000000000000330
+C:\Windows\System32\svchost.exe
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+1162
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+2015-03-25 14:13:47.025499
+2015-03-25 14:13:47.025000
+0x0000000000000330
+C:\Windows\System32\svchost.exe
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1163
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1164
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1165
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1166
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157773
+7
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1167
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000015777f
+7
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1168
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157773
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1169
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000015777f
+7
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1170
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157773
+7
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1171
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1172
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1173
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1174
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1175
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1176
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4904
+0
+0
+13568
+0
+0x8020000000000000
+
+1177
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000001aa8e7
+0x0000000000000934
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4905
+0
+0
+13568
+0
+0x8020000000000000
+
+1178
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000001aa8e7
+0x0000000000000934
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1179
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1180
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1181
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1182
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1183
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1184
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1185
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1186
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4904
+0
+0
+13568
+0
+0x8020000000000000
+
+1187
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x0000000000245dcb
+0x0000000000000aa4
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4905
+0
+0
+13568
+0
+0x8020000000000000
+
+1188
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x0000000000245dcb
+0x0000000000000aa4
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1189
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1190
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+1191
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000025493
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+1192
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+2015-03-25 15:31:00.240004
+2015-03-25 15:31:00.240000
+0x0000000000000330
+C:\Windows\System32\svchost.exe
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+1193
+
+
+Security
+informant-PC
+
+
+
+
+
+
+
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/SecurityEvt_ns_removed.xml b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/SecurityEvt_ns_removed.xml
new file mode 100644
index 0000000..cc35c57
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/SecurityEvt_ns_removed.xml
@@ -0,0 +1,36682 @@
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+1
+
+
+Security
+37L4247F27-25
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+2
+
+
+Security
+37L4247F27-25
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+3
+
+
+Security
+37L4247F27-25
+
+
+0
+0x0000000000035ce9
+
+
+
+
+4731
+0
+0
+13826
+0
+0x8020000000000000
+
+4
+
+
+Security
+37L4247F27-25
+
+
+Backup Operators
+Builtin
+S-1-5-32-551
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+Backup Operators
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+5
+
+
+Security
+37L4247F27-25
+
+
+Backup Operators
+Builtin
+S-1-5-32-551
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4731
+0
+0
+13826
+0
+0x8020000000000000
+
+6
+
+
+Security
+37L4247F27-25
+
+
+Replicator
+Builtin
+S-1-5-32-552
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+Replicator
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+7
+
+
+Security
+37L4247F27-25
+
+
+Replicator
+Builtin
+S-1-5-32-552
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4731
+0
+0
+13826
+0
+0x8020000000000000
+
+8
+
+
+Security
+37L4247F27-25
+
+
+Remote Desktop Users
+Builtin
+S-1-5-32-555
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+Remote Desktop Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+9
+
+
+Security
+37L4247F27-25
+
+
+Remote Desktop Users
+Builtin
+S-1-5-32-555
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4731
+0
+0
+13826
+0
+0x8020000000000000
+
+10
+
+
+Security
+37L4247F27-25
+
+
+Network Configuration Operators
+Builtin
+S-1-5-32-556
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+Network Configuration Operators
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+11
+
+
+Security
+37L4247F27-25
+
+
+Network Configuration Operators
+Builtin
+S-1-5-32-556
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4731
+0
+0
+13826
+0
+0x8020000000000000
+
+12
+
+
+Security
+37L4247F27-25
+
+
+Power Users
+Builtin
+S-1-5-32-547
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+Power Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+13
+
+
+Security
+37L4247F27-25
+
+
+Power Users
+Builtin
+S-1-5-32-547
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4731
+0
+0
+13826
+0
+0x8020000000000000
+
+14
+
+
+Security
+37L4247F27-25
+
+
+Cryptographic Operators
+Builtin
+S-1-5-32-569
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+Cryptographic Operators
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+15
+
+
+Security
+37L4247F27-25
+
+
+Cryptographic Operators
+Builtin
+S-1-5-32-569
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+16
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+17
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+18
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+19
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+20
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+21
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+22
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+23
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+24
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+25
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+26
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+27
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+28
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+29
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+30
+
+
+Security
+37L4247F27-25
+
+
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+31
+
+
+Security
+37L4247F27-25
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+32
+
+
+Security
+37L4247F27-25
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x00000000000454a7
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+33
+
+
+Security
+37L4247F27-25
+
+
+-
+Administrator
+37L4247F27-25
+S-1-5-21-2425377081-3129163575-2985601102-500
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+0x211
+0x211
+-
+-
+-
+-
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+34
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+35
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+36
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+37
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+38
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+39
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+40
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+37L4247F27-25$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+41
+
+
+Security
+37L4247F27-25
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+42
+
+
+Security
+37L4247F27-25
+
+
+
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+43
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+44
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+45
+
+
+Security
+informant-PC
+
+
+0
+0x000000000000d031
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+46
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+47
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+48
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+49
+
+
+Security
+informant-PC
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+50
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+51
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+52
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+53
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+54
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+55
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+56
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+57
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+58
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+59
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+60
+
+
+Security
+informant-PC
+
+
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+61
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+62
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x0000000000028c63
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+63
+
+
+Security
+informant-PC
+
+
+Administrators
+Builtin
+S-1-5-32-544
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+64
+
+
+Security
+informant-PC
+
+
+Administrators
+Administrators
+Builtin
+S-1-5-32-544
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+65
+
+
+Security
+informant-PC
+
+
+Administrators
+Builtin
+S-1-5-32-544
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Administrators
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+66
+
+
+Security
+informant-PC
+
+
+Users
+Builtin
+S-1-5-32-545
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+67
+
+
+Security
+informant-PC
+
+
+Users
+Users
+Builtin
+S-1-5-32-545
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+68
+
+
+Security
+informant-PC
+
+
+Users
+Builtin
+S-1-5-32-545
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+69
+
+
+Security
+informant-PC
+
+
+Guests
+Builtin
+S-1-5-32-546
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+70
+
+
+Security
+informant-PC
+
+
+Guests
+Guests
+Builtin
+S-1-5-32-546
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+71
+
+
+Security
+informant-PC
+
+
+Guests
+Builtin
+S-1-5-32-546
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Guests
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+72
+
+
+Security
+informant-PC
+
+
+Backup Operators
+Builtin
+S-1-5-32-551
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+73
+
+
+Security
+informant-PC
+
+
+Backup Operators
+Backup Operators
+Builtin
+S-1-5-32-551
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+74
+
+
+Security
+informant-PC
+
+
+Backup Operators
+Builtin
+S-1-5-32-551
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Backup Operators
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+75
+
+
+Security
+informant-PC
+
+
+Replicator
+Builtin
+S-1-5-32-552
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+76
+
+
+Security
+informant-PC
+
+
+Replicator
+Replicator
+Builtin
+S-1-5-32-552
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+77
+
+
+Security
+informant-PC
+
+
+Replicator
+Builtin
+S-1-5-32-552
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Replicator
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+78
+
+
+Security
+informant-PC
+
+
+Remote Desktop Users
+Builtin
+S-1-5-32-555
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+79
+
+
+Security
+informant-PC
+
+
+Remote Desktop Users
+Remote Desktop Users
+Builtin
+S-1-5-32-555
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+80
+
+
+Security
+informant-PC
+
+
+Remote Desktop Users
+Builtin
+S-1-5-32-555
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Remote Desktop Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+81
+
+
+Security
+informant-PC
+
+
+Network Configuration Operators
+Builtin
+S-1-5-32-556
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+82
+
+
+Security
+informant-PC
+
+
+Network Configuration Operators
+Network Configuration Operators
+Builtin
+S-1-5-32-556
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+83
+
+
+Security
+informant-PC
+
+
+Network Configuration Operators
+Builtin
+S-1-5-32-556
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Network Configuration Operators
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+84
+
+
+Security
+informant-PC
+
+
+Power Users
+Builtin
+S-1-5-32-547
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+85
+
+
+Security
+informant-PC
+
+
+Power Users
+Power Users
+Builtin
+S-1-5-32-547
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+86
+
+
+Security
+informant-PC
+
+
+Power Users
+Builtin
+S-1-5-32-547
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Power Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+87
+
+
+Security
+informant-PC
+
+
+Performance Monitor Users
+Builtin
+S-1-5-32-558
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+88
+
+
+Security
+informant-PC
+
+
+Performance Monitor Users
+Performance Monitor Users
+Builtin
+S-1-5-32-558
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+89
+
+
+Security
+informant-PC
+
+
+Performance Monitor Users
+Builtin
+S-1-5-32-558
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Performance Monitor Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+90
+
+
+Security
+informant-PC
+
+
+Performance Log Users
+Builtin
+S-1-5-32-559
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+91
+
+
+Security
+informant-PC
+
+
+Performance Log Users
+Performance Log Users
+Builtin
+S-1-5-32-559
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+92
+
+
+Security
+informant-PC
+
+
+Performance Log Users
+Builtin
+S-1-5-32-559
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Performance Log Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+93
+
+
+Security
+informant-PC
+
+
+Distributed COM Users
+Builtin
+S-1-5-32-562
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+94
+
+
+Security
+informant-PC
+
+
+Distributed COM Users
+Distributed COM Users
+Builtin
+S-1-5-32-562
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+95
+
+
+Security
+informant-PC
+
+
+Distributed COM Users
+Builtin
+S-1-5-32-562
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Distributed COM Users
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+96
+
+
+Security
+informant-PC
+
+
+IIS_IUSRS
+Builtin
+S-1-5-32-568
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+97
+
+
+Security
+informant-PC
+
+
+IIS_IUSRS
+IIS_IUSRS
+Builtin
+S-1-5-32-568
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+98
+
+
+Security
+informant-PC
+
+
+IIS_IUSRS
+Builtin
+S-1-5-32-568
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+IIS_IUSRS
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+99
+
+
+Security
+informant-PC
+
+
+Cryptographic Operators
+Builtin
+S-1-5-32-569
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+100
+
+
+Security
+informant-PC
+
+
+Cryptographic Operators
+Cryptographic Operators
+Builtin
+S-1-5-32-569
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+101
+
+
+Security
+informant-PC
+
+
+Cryptographic Operators
+Builtin
+S-1-5-32-569
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Cryptographic Operators
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+102
+
+
+Security
+informant-PC
+
+
+Event Log Readers
+Builtin
+S-1-5-32-573
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+
+
+
+
+4781
+0
+0
+13824
+0
+0x8020000000000000
+
+103
+
+
+Security
+informant-PC
+
+
+Event Log Readers
+Event Log Readers
+Builtin
+S-1-5-32-573
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4735
+0
+0
+13826
+0
+0x8020000000000000
+
+104
+
+
+Security
+informant-PC
+
+
+Event Log Readers
+Builtin
+S-1-5-32-573
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Event Log Readers
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+105
+
+
+Security
+informant-PC
+
+
+-
+Administrator
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-500
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Administrator
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+11/20/2010 8:57:24 PM
+%%1794
+513
+-
+0x211
+0x211
+-
+%%1793
+-
+%%1797
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+106
+
+
+Security
+informant-PC
+
+
+-
+Administrator
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-500
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Administrator
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+11/20/2010 8:57:24 PM
+%%1794
+513
+-
+0x211
+0x211
+-
+%%1793
+-
+%%1797
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+107
+
+
+Security
+informant-PC
+
+
+-
+Guest
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-501
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Guest
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x215
+0x215
+-
+%%1793
+-
+%%1797
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+108
+
+
+Security
+informant-PC
+
+
+-
+Guest
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-501
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+Guest
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x215
+0x215
+-
+%%1793
+-
+%%1797
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+109
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+2015-03-25 10:34:25.685648
+2015-03-22 14:33:53.237000
+0x0000000000000340
+C:\Windows\System32\oobe\msoobe.exe
+
+
+
+
+4728
+0
+0
+13826
+0
+0x8020000000000000
+
+110
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1000
+None
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-513
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4720
+0
+0
+13824
+0
+0x8020000000000000
+
+111
+
+
+Security
+informant-PC
+
+
+informant
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1000
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+informant
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x0
+0x15
+
+ %%2080
+ %%2082
+ %%2084
+%%1793
+-
+%%1797
+
+
+
+
+4732
+0
+0
+13826
+0
+0x8020000000000000
+
+112
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1000
+Users
+Builtin
+S-1-5-32-545
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4722
+0
+0
+13824
+0
+0x8020000000000000
+
+113
+
+
+Security
+informant-PC
+
+
+informant
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1000
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+114
+
+
+Security
+informant-PC
+
+
+-
+informant
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1000
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+informant
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x15
+0x14
+
+ %%2048
+%%1793
+-
+%%1797
+
+
+
+
+4732
+0
+0
+13826
+0
+0x8020000000000000
+
+115
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1000
+Administrators
+Builtin
+S-1-5-32-544
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4733
+0
+0
+13826
+0
+0x8020000000000000
+
+116
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1000
+Users
+Builtin
+S-1-5-32-545
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+117
+
+
+Security
+informant-PC
+
+
+-
+informant
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1000
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+informant
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+3/22/2015 10:33:54 AM
+%%1794
+513
+-
+0x14
+0x214
+
+ %%2089
+-
+-
+%%1797
+
+
+
+
+4724
+0
+0
+13824
+0
+0x8020000000000000
+
+118
+
+
+Security
+informant-PC
+
+
+informant
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1000
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+119
+
+
+Security
+informant-PC
+
+
+-
+informant
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1000
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+120
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+121
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+122
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+123
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000003be29
+2
+User32
+Negotiate
+WIN-D9RGPJQ68G8
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+124
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000003db0a
+2
+User32
+Negotiate
+WIN-D9RGPJQ68G8
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+125
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000003be29
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+126
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+WIN-D9RGPJQ68G8$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+127
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+128
+
+
+Security
+informant-PC
+
+
+
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+129
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000003db0a
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+130
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+131
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+132
+
+
+Security
+informant-PC
+
+
+0
+0x000000000000b8dc
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+133
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+134
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+135
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+136
+
+
+Security
+informant-PC
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+137
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+138
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+139
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+140
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+141
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+142
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+143
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+144
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+145
+
+
+Security
+informant-PC
+
+
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+146
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+147
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x000000000001a667
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+148
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+149
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+150
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+151
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+152
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x0000000000000184
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+153
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000026923
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000184
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+154
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000026951
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000184
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+155
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000026923
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+156
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+157
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+158
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+159
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+160
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+161
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4904
+0
+0
+13568
+0
+0x8020000000000000
+
+162
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x0000000000069adb
+0x0000000000000bc0
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4905
+0
+0
+13568
+0
+0x8020000000000000
+
+163
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x0000000000069adb
+0x0000000000000bc0
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4904
+0
+0
+13568
+0
+0x8020000000000000
+
+164
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000000835e3
+0x0000000000000bc0
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4905
+0
+0
+13568
+0
+0x8020000000000000
+
+165
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000000835e3
+0x0000000000000bc0
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+166
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+167
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+168
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+169
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+170
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+171
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+172
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+173
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4904
+0
+0
+13568
+0
+0x8020000000000000
+
+174
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000001fa262
+0x0000000000000e6c
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4905
+0
+0
+13568
+0
+0x8020000000000000
+
+175
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000001fa262
+0x0000000000000e6c
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+176
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+177
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+178
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\winsxs\Temp\PendingRenames\a86dcf49b364d00184220000f80e440b.install.ins
+0x00000000000086e8
+
+S:ARAI
+0x0000000000000ef8
+C:\Windows\servicing\TrustedInstaller.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+179
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\winsxs\Temp\PendingRenames\08cfd149b364d00185220000f80e440b.install.ins
+0x00000000000088b0
+
+S:ARAI
+0x0000000000000ef8
+C:\Windows\servicing\TrustedInstaller.exe
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+180
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000026951
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+181
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\DWrite.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+182
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d2d1.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+183
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\msmpeg2vdec.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+184
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+185
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d3d10core.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+186
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+187
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+188
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\XpsGdiConverter.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+189
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+190
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d3d10warp.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+191
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+192
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\dxgi.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+193
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\WMPhoto.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+194
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\FntCache.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+195
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+196
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d3d10_1.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+197
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\WindowsCodecsExt.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+198
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+199
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d3d10level9.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+200
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\UIAnimation.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+201
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+202
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d3d10_1core.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+203
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\XpsPrint.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+204
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+205
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d3d10.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+206
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\WindowsCodecs.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+207
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\d3d11.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+208
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+209
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+210
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+211
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+212
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+213
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\da-DK\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+214
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\da-DK\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+215
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\da-DK\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+216
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\da-DK\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+217
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nb-NO\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+218
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nb-NO\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+219
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nb-NO\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+220
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nb-NO\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+221
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\spp\tokens\ppdlic\msmpeg2vdec-ppdlic.xrm-ms
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+222
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ru-RU\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+223
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ru-RU\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+224
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ru-RU\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+225
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ru-RU\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+226
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ja-JP\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+227
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ja-JP\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+228
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ja-JP\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+229
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ja-JP\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+230
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ja-JP\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+231
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-CN\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+232
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-CN\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+233
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-CN\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+234
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-CN\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+235
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\cs-CZ\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+236
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\cs-CZ\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+237
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\cs-CZ\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+238
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\cs-CZ\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+239
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\de-DE\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+240
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\de-DE\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+241
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\de-DE\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+242
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\de-DE\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+243
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\de-DE\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+244
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-TW\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+245
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-TW\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+246
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-TW\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+247
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-TW\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+248
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\es-ES\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+249
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\es-ES\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+250
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\es-ES\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+251
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\es-ES\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+252
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\es-ES\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+253
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\sv-SE\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+254
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\sv-SE\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+255
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\sv-SE\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+256
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\sv-SE\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+257
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\tr-TR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+258
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\tr-TR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+259
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\tr-TR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+260
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\tr-TR\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+261
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fi-FI\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+262
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fi-FI\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+263
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fi-FI\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+264
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fi-FI\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+265
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fr-FR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+266
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fr-FR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+267
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fr-FR\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+268
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fr-FR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+269
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\fr-FR\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+270
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nl-NL\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+271
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nl-NL\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+272
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nl-NL\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+273
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nl-NL\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+274
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\nl-NL\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+275
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\el-GR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+276
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\el-GR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+277
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\el-GR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+278
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\el-GR\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+279
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-HK\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+280
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-HK\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+281
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-HK\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+282
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\zh-HK\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+283
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\hu-HU\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+284
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\hu-HU\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+285
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\hu-HU\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+286
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\hu-HU\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+287
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ko-KR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+288
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ko-KR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+289
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ko-KR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+290
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ko-KR\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+291
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pl-PL\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+292
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pl-PL\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+293
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pl-PL\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+294
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pl-PL\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+295
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-PT\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+296
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-PT\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+297
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-PT\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+298
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-PT\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+299
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\it-IT\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+300
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\it-IT\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+301
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\it-IT\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+302
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\it-IT\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+303
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\it-IT\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+304
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-BR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+305
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-BR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+306
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-BR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+307
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pt-BR\FntCache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+308
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\DWrite.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+309
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d2d1.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+310
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\msmpeg2vdec.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+311
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+312
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d3d10core.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+313
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+314
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+315
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\XpsGdiConverter.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+316
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+317
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d3d10warp.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+318
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\dxgi.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+319
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+320
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\WMPhoto.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+321
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+322
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d3d10_1.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+323
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d3d10level9.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+324
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\WindowsCodecsExt.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+325
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+326
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+327
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\UIAnimation.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+328
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d3d10_1core.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+329
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\XpsPrint.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+330
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+331
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d3d10.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+332
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\WindowsCodecs.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+333
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\d3d11.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+334
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+335
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+336
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+337
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+338
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\da-DK\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+339
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\da-DK\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+340
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\da-DK\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+341
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\nb-NO\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+342
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\nb-NO\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+343
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\nb-NO\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+344
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\spp\tokens\ppdlic\msmpeg2vdec-ppdlic.xrm-ms
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+345
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ru-RU\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+346
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ru-RU\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+347
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ru-RU\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+348
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ja-JP\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+349
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ja-JP\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+350
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ja-JP\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+351
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ja-JP\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+352
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-CN\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+353
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-CN\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+354
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-CN\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+355
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\cs-CZ\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+356
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\cs-CZ\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+357
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\cs-CZ\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+358
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\de-DE\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+359
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\de-DE\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+360
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\de-DE\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+361
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\de-DE\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+362
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-TW\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+363
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-TW\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+364
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-TW\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+365
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\es-ES\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+366
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\es-ES\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+367
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\es-ES\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+368
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\es-ES\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+369
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\sv-SE\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+370
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\sv-SE\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+371
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\sv-SE\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+372
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\tr-TR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+373
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\tr-TR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+374
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\tr-TR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+375
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\fi-FI\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+376
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\fi-FI\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+377
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\fi-FI\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+378
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\fr-FR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+379
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\fr-FR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+380
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\fr-FR\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+381
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\fr-FR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+382
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\nl-NL\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+383
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\nl-NL\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+384
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\nl-NL\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+385
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\nl-NL\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+386
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\el-GR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+387
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\el-GR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+388
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\el-GR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+389
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-HK\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+390
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-HK\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+391
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\zh-HK\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+392
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\hu-HU\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+393
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\hu-HU\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+394
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\hu-HU\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+395
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ko-KR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+396
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ko-KR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+397
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ko-KR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+398
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pl-PL\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+399
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pl-PL\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+400
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pl-PL\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+401
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pt-PT\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+402
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pt-PT\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+403
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pt-PT\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+404
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\it-IT\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+405
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\it-IT\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+406
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\it-IT\UIAnimation.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+407
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\it-IT\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+408
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pt-BR\WMPhoto.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+409
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pt-BR\d2d1.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+410
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pt-BR\DWrite.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+411
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ntoskrnl.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+412
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntoskrnl.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+413
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntkrnlpa.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+414
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\AppPatch\acwow64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+415
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+416
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+417
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+418
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+419
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+420
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64cpu.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+421
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+422
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+423
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+424
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+425
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+426
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+427
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+428
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ntvdm64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+429
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+430
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+431
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+432
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+433
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+434
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+435
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\conhost.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+436
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+437
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+438
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+439
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64win.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+440
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+441
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\kernel32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+442
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\KernelBase.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+443
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+444
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+445
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+446
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+447
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\winsrv.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+448
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+449
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+450
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+451
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+452
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+453
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\setup16.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+454
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\user.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+455
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+456
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntvdm64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+457
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+458
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+459
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+460
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+461
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+462
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+463
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+464
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+465
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+466
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\instnm.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+467
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+468
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+469
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+470
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+471
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+472
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+473
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\kernel32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+474
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+475
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+476
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+477
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+478
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+479
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\KernelBase.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+480
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+481
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+482
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+483
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+484
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+485
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\wow32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+486
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\AppPatch\acwow64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+487
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+488
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+489
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+490
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+491
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+492
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64cpu.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+493
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+494
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+495
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+496
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+497
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+498
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+499
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+500
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ntvdm64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+501
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+502
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+503
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+504
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+505
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+506
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+507
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\conhost.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+508
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+509
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+510
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+511
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64win.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+512
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+513
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\kernel32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+514
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\KernelBase.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+515
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+516
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+517
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+518
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+519
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\winsrv.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+520
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+521
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+522
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+523
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\KernelBase.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+524
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\instnm.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+525
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+526
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+527
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+528
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+529
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\user.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+530
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+531
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+532
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+533
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+534
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+535
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+536
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+537
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntvdm64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+538
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+539
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+540
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+541
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+542
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+543
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+544
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\wow32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+545
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+546
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+547
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+548
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+549
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\kernel32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+550
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\KernelBase.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+551
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+552
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+553
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+554
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+555
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+556
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\setup16.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+557
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+558
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+559
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\KernelBase.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+560
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Fonts\seguisym.ttf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+561
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Fonts\segoeui.ttf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+562
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Fonts\segoeuiz.ttf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+563
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Fonts\segoeuib.ttf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+564
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Fonts\segoeuii.ttf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+565
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\taskhost.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+566
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\drivers\afd.sys
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+567
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\drivers\FWPKCLNT.SYS
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+568
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\drivers\tcpip.sys
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+569
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\drivers\netio.sys
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+570
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\mswsock.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+571
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\mswsock.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+572
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\smss.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+573
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\csrsrv.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+574
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ntdll.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+575
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ntoskrnl.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+576
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\apisetschema.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+577
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntdll.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+578
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntoskrnl.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+579
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntkrnlpa.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+580
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\AppPatch\acwow64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+581
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\tdh.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+582
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+583
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+584
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+585
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+586
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+587
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64cpu.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+588
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+589
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+590
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+591
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+592
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+593
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+594
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+595
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ntvdm64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+596
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+597
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+598
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+599
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+600
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+601
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+602
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\conhost.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+603
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+604
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\advapi32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+605
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+606
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+607
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wow64win.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+608
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+609
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\kernel32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+610
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\KernelBase.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+611
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+612
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+613
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+614
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+615
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\winsrv.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+616
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+617
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+618
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+619
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\instnm.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+620
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\tdh.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+621
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+622
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+623
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+624
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+625
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\user.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+626
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+627
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+628
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+629
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+630
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+631
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+632
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+633
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ntvdm64.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+634
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+635
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+636
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+637
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+638
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+639
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+640
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\wow32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+641
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+642
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\advapi32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+643
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+644
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+645
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+646
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\KernelBase.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+647
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\kernel32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+648
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+649
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+650
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+651
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+652
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+653
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\setup16.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+654
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+655
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+656
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Common Files\microsoft shared\VGX\VGX.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+657
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\D3DCompiler_47.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+658
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\iexplore.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+659
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\ie9props.propdesc
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+660
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\JSProfilerCore.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+661
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\jsprofilerui.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+662
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\pdm.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+663
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\pdmproxy100.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+664
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\DiagnosticsTap.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+665
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\ExtExport.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+666
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\sqmapi.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+667
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\jsdebuggeride.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+668
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\jsdbgui.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+669
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\msdbg2.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+670
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\networkinspection.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+671
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\iedvtool.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+672
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\ielowutil.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+673
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\ieproxy.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+674
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\ieinstal.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+675
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\F12Tools.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+676
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\IEShims.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+677
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\SIGNUP\install.ins
+0x000000000000001c
+S:AI
+
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+678
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\F12Tools.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+679
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\jsprofilerui.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+680
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\jsdbgui.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+681
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\iedvtool.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+682
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\DiagnosticsTap.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+683
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\ieinstal.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+684
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\eula.rtf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+685
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\networkinspection.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+686
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+687
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+688
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\iexplore.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+689
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\Timeline_is.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+690
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\pdm.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+691
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\msdbg2.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+692
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\Timeline.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+693
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\JSProfilerCore.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+694
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\ielowutil.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+695
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\ieinstal.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+696
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\IEShims.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+697
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\pdmproxy100.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+698
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\perfcore.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+699
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\D3DCompiler_47.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+700
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\iedvtool.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+701
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\ieproxy.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+702
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\DiagnosticsTap.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+703
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\iediagcmd.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+704
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\perf_nt.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+705
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\DiagnosticsHub.DataWarehouse.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+706
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\F12Tools.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+707
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\jsdebuggeride.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+708
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\networkinspection.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+709
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\jsprofilerui.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+710
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\DiagnosticsHub.ScriptedSandboxPlugin.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+711
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\MemoryAnalyzer.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+712
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\F12Resources.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+713
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\ie9props.propdesc
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+714
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\jsdbgui.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+715
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\F12.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+716
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\DiagnosticsHub_is.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+717
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\Timeline.cpu.xml
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+718
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\sqmapi.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+719
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\jsprofilerui.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+720
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\F12Tools.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+721
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\F12.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+722
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\jsdbgui.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+723
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\iedvtool.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+724
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\F12Resources.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+725
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\ieinstal.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+726
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\DiagnosticsTap.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+727
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\networkinspection.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+728
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\eula.rtf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+729
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+730
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\images\bing.ico
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+731
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Program Files\Internet Explorer\SIGNUP\install.ins
+0x000000000000001c
+S:AI
+
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+732
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieapfltr.dat
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+733
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\url.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+734
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\mshta.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+735
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\jsproxy.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+736
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieUnatt.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+737
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieui.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+738
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\mshtmlmedia.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+739
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieetwproxystub.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+740
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\jsIntl.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+741
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\RegisterIEPKEYs.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+742
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\iepeers.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+743
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\elshyph.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+744
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieframe.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+745
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ie4uinit.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+746
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\licmgr10.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+747
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\mshtmler.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+748
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\iexpress.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+749
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\IEAdvpack.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+750
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\dxtrans.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+751
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wextract.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+752
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieetwcollectorres.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+753
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\SetIEInstalledDate.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+754
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wininet.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+755
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\MshtmlDac.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+756
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\jscript.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+757
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\JavaScriptCollectionAgent.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+758
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\msfeedssync.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+759
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\webcheck.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+760
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\MsSpellCheckingFacility.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+761
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\icardie.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+762
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\iertutil.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+763
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\pngfilt.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+764
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\msls31.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+765
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieetwcollector.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+766
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\jscript9diag.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+767
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\iedkcs32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+768
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\iesetup.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+769
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\iernonce.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+770
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\vbscript.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+771
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\inseng.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+772
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\iesysprep.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+773
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\inetcpl.cpl
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+774
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\jscript9.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+775
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\occache.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+776
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieapfltr.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+777
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\html.iec
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+778
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\imgutil.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+779
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\msfeeds.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+780
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\ieuinit.inf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+781
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\tdc.ocx
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+782
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\mshtml.tlb
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+783
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\mshtml.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+784
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\mshtmled.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+785
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\urlmon.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+786
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\msfeedsbs.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+787
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\msrating.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+788
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\dxtmsft.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+789
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\iesetup.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+790
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\mshtmlmedia.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+791
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\icardie.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+792
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\iepeers.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+793
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\IEAdvpack.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+794
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\jsIntl.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+795
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\occache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+796
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\MsSpellCheckingFacility.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+797
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\wextract.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+798
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\ieunatt.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+799
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\ie4uinit.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+800
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\iernonce.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+801
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\elshyph.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+802
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\jscript.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+803
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\msrating.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+804
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\ieframe.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+805
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\msfeedsbs.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+806
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\vbscript.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+807
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\ieui.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+808
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\html.iec.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+809
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\iexpress.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+810
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\mshtmler.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+811
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\urlmon.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+812
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\jscript9.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+813
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\iedkcs32.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+814
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\webcheck.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+815
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\wininet.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+816
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\mshta.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+817
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\licmgr10.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+818
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\mshtml.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+819
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\inseng.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+820
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\inetcpl.cpl.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+821
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\en-US\ieetwcollectorres.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+822
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\spp\tokens\ppdlic\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+823
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wdi\perftrack\Microsoft-Windows-IE-HTMLRendering.ptxml
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+824
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wdi\perftrack\ieframe.ptxml
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+825
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\wdi\perftrack\Microsoft-Windows-IE-F12-Provider.ptxml
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+826
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\System32\migration\WininetPlugin.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+827
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\PolicyDefinitions\inetres.admx
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+828
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\PolicyDefinitions\en-US\InetRes.adml
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+829
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ieapfltr.dat
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+830
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\mshta.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+831
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\jsproxy.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+832
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\url.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+833
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ieUnatt.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+834
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ieui.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+835
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\mshtmlmedia.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+836
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\jsIntl.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+837
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ieetwproxystub.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+838
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\RegisterIEPKEYs.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+839
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\elshyph.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+840
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\iepeers.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+841
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ieframe.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+842
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\licmgr10.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+843
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\mshtmler.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+844
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\iexpress.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+845
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\IEAdvpack.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+846
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\wextract.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+847
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\dxtrans.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+848
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\wininet.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+849
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\SetIEInstalledDate.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+850
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\MshtmlDac.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+851
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\jscript.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+852
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+853
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\msfeedssync.exe
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+854
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\webcheck.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+855
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\icardie.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+856
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\iertutil.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+857
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\pngfilt.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+858
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\jscript9diag.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+859
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\msls31.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+860
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\iedkcs32.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+861
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\iesetup.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+862
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\iernonce.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+863
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\vbscript.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+864
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\iesysprep.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+865
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\inseng.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+866
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\jscript9.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+867
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\occache.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+868
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\inetcpl.cpl
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+869
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ieapfltr.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+870
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\html.iec
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+871
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\imgutil.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+872
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\msfeeds.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+873
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\ieuinit.inf
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+874
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\tdc.ocx
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+875
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\mshtml.tlb
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+876
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\mshtml.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+877
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\mshtmled.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+878
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\urlmon.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+879
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\msfeedsbs.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+880
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\msrating.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+881
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\dxtmsft.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+882
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\webcheck.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+883
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\iernonce.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+884
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\inseng.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+885
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\html.iec.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+886
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\msrating.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+887
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\wininet.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+888
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\ieui.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+889
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\elshyph.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+890
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\iexpress.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+891
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\ieetwcollectorres.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+892
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\occache.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+893
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\ieframe.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+894
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\mshta.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+895
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\mshtml.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+896
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\wextract.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+897
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\iesetup.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+898
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\ieunatt.exe.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+899
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\licmgr10.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+900
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\mshtmler.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+901
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\jscript.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+902
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\vbscript.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+903
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\iepeers.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+904
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\IEAdvpack.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+905
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\msfeedsbs.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+906
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\mshtmlmedia.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+907
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\iedkcs32.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+908
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\urlmon.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+909
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\inetcpl.cpl.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+910
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\jscript9.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+911
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\en-US\icardie.dll.mui
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+912
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\wdi\perftrack\wow64_ieframe.ptxml
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+913
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\wdi\perftrack\wow64_Microsoft-Windows-IE-HTMLRendering.ptxml
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+914
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\SysWOW64\migration\WininetPlugin.dll
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+915
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.acl
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+916
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.dub
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+917
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.lex
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+918
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Globalization\ELS\HyphenationDictionaries\MsHy7en.lex
+0x000000000000001c
+
+S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+0x0000000000000cdc
+C:\Windows\System32\poqexec.exe
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+919
+
+
+Security
+informant-PC
+
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+920
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001c0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+921
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+922
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+923
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+924
+
+
+Security
+informant-PC
+
+
+0
+0x000000000000c957
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+925
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+926
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+927
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+928
+
+
+Security
+informant-PC
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+929
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+930
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+931
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+932
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+933
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+934
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+935
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+936
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+937
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+938
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+939
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+940
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x000000000001a427
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+941
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+942
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+943
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+944
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Globalization\ELS\HyphenationDictionaries
+0x00000000000002d4
+
+S:ARAI(AU;SAFA;0x1f0116;;;WD)
+0x00000000000003e8
+C:\Windows\servicing\TrustedInstaller.exe
+
+
+
+
+4907
+0
+0
+13568
+0
+0x8020000000000000
+
+945
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+Security
+File
+C:\Windows\Globalization\ELS\SpellDictionaries
+0x00000000000002d0
+
+S:ARAI(AU;SAFA;0x1f0116;;;WD)
+0x00000000000003e8
+C:\Windows\servicing\TrustedInstaller.exe
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+946
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+947
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000056f8b
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+948
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000056fb9
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+949
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000056f8b
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+950
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+951
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+952
+
+
+Security
+informant-PC
+
+
+
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+953
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000056fb9
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+954
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+955
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+956
+
+
+Security
+informant-PC
+
+
+0
+0x000000000000c54c
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+957
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+958
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+959
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+960
+
+
+Security
+informant-PC
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+961
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+962
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+963
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+964
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+965
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+966
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+967
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+968
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+969
+
+
+Security
+informant-PC
+
+
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+970
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+971
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x000000000001c185
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+972
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+973
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+974
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000022517
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+975
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+976
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+977
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+978
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+979
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+980
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+981
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+982
+
+
+Security
+informant-PC
+
+
+-
+informant
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1000
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000022517
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4728
+0
+0
+13826
+0
+0x8020000000000000
+
+983
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1001
+None
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-513
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4720
+0
+0
+13824
+0
+0x8020000000000000
+
+984
+
+
+Security
+informant-PC
+
+
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+admin11
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x0
+0x15
+
+ %%2080
+ %%2082
+ %%2084
+%%1793
+-
+%%1797
+
+
+
+
+4722
+0
+0
+13824
+0
+0x8020000000000000
+
+985
+
+
+Security
+informant-PC
+
+
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+986
+
+
+Security
+informant-PC
+
+
+-
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+admin11
+admin11
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x15
+0x210
+
+ %%2048
+ %%2050
+ %%2089
+%%1793
+-
+%%1797
+
+
+
+
+4732
+0
+0
+13826
+0
+0x8020000000000000
+
+987
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1001
+Users
+Builtin
+S-1-5-32-545
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+988
+
+
+Security
+informant-PC
+
+
+-
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4732
+0
+0
+13826
+0
+0x8020000000000000
+
+989
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1001
+Administrators
+Builtin
+S-1-5-32-544
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+990
+
+
+Security
+informant-PC
+
+
+-
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+admin11
+admin11
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x210
+0x210
+-
+%%1793
+-
+%%1797
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+991
+
+
+Security
+informant-PC
+
+
+-
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+admin11
+admin11
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+3/22/2015 11:52:10 AM
+%%1794
+513
+-
+0x210
+0x210
+-
+-
+-
+%%1797
+
+
+
+
+4724
+0
+0
+13824
+0
+0x8020000000000000
+
+992
+
+
+Security
+informant-PC
+
+
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+993
+
+
+Security
+informant-PC
+
+
+-
+admin11
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1001
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4728
+0
+0
+13826
+0
+0x8020000000000000
+
+994
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1002
+None
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-513
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4720
+0
+0
+13824
+0
+0x8020000000000000
+
+995
+
+
+Security
+informant-PC
+
+
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+ITechTeam
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x0
+0x15
+
+ %%2080
+ %%2082
+ %%2084
+%%1793
+-
+%%1797
+
+
+
+
+4722
+0
+0
+13824
+0
+0x8020000000000000
+
+996
+
+
+Security
+informant-PC
+
+
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+997
+
+
+Security
+informant-PC
+
+
+-
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+ITechTeam
+ITechTeam
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x15
+0x210
+
+ %%2048
+ %%2050
+ %%2089
+%%1793
+-
+%%1797
+
+
+
+
+4732
+0
+0
+13826
+0
+0x8020000000000000
+
+998
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1002
+Users
+Builtin
+S-1-5-32-545
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+999
+
+
+Security
+informant-PC
+
+
+-
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4732
+0
+0
+13826
+0
+0x8020000000000000
+
+1000
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1002
+Administrators
+Builtin
+S-1-5-32-544
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1001
+
+
+Security
+informant-PC
+
+
+-
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+ITechTeam
+ITechTeam
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x210
+0x210
+-
+%%1793
+-
+%%1797
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1002
+
+
+Security
+informant-PC
+
+
+-
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+ITechTeam
+ITechTeam
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+3/22/2015 11:52:45 AM
+%%1794
+513
+-
+0x210
+0x210
+-
+-
+-
+%%1797
+
+
+
+
+4724
+0
+0
+13824
+0
+0x8020000000000000
+
+1003
+
+
+Security
+informant-PC
+
+
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1004
+
+
+Security
+informant-PC
+
+
+-
+ITechTeam
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1002
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4728
+0
+0
+13826
+0
+0x8020000000000000
+
+1005
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1003
+None
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-513
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4720
+0
+0
+13824
+0
+0x8020000000000000
+
+1006
+
+
+Security
+informant-PC
+
+
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+temporary
+%%1793
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x0
+0x15
+
+ %%2080
+ %%2082
+ %%2084
+%%1793
+-
+%%1797
+
+
+
+
+4722
+0
+0
+13824
+0
+0x8020000000000000
+
+1007
+
+
+Security
+informant-PC
+
+
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1008
+
+
+Security
+informant-PC
+
+
+-
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+temporary
+temporary
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x15
+0x210
+
+ %%2048
+ %%2050
+ %%2089
+%%1793
+-
+%%1797
+
+
+
+
+4732
+0
+0
+13826
+0
+0x8020000000000000
+
+1009
+
+
+Security
+informant-PC
+
+
+-
+S-1-5-21-2425377081-3129163575-2985601102-1003
+Users
+Builtin
+S-1-5-32-545
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1010
+
+
+Security
+informant-PC
+
+
+-
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1011
+
+
+Security
+informant-PC
+
+
+-
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+temporary
+temporary
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+%%1794
+%%1794
+513
+-
+0x210
+0x210
+-
+%%1793
+-
+%%1797
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1012
+
+
+Security
+informant-PC
+
+
+-
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+temporary
+temporary
+-
+%%1793
+%%1793
+%%1793
+%%1793
+%%1793
+3/22/2015 11:53:11 AM
+%%1794
+513
+-
+0x210
+0x210
+-
+-
+-
+%%1797
+
+
+
+
+4724
+0
+0
+13824
+0
+0x8020000000000000
+
+1013
+
+
+Security
+informant-PC
+
+
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+
+
+
+
+4738
+0
+0
+13824
+0
+0x8020000000000000
+
+1014
+
+
+Security
+informant-PC
+
+
+-
+temporary
+informant-PC
+S-1-5-21-2425377081-3129163575-2985601102-1003
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000224e3
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1015
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+admin11
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x00000000000007a0
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1016
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x0000000000094b57
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000007a0
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1017
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x0000000000094b71
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000007a0
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1018
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x0000000000094b57
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+1019
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x0000000000094b71
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1020
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+temporary
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x000000000000072c
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1021
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1003
+temporary
+informant-PC
+0x00000000000f2cd6
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x000000000000072c
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1022
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x0000000000094b71
+2
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1023
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x0000000000094b57
+2
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+1024
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1003
+temporary
+informant-PC
+0x00000000000f2cd6
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1025
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+admin11
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x0000000000000954
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1026
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x00000000001354b3
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000954
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1027
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x00000000001354c8
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000954
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1028
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x00000000001354b3
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+1029
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x00000000001354c8
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1030
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x0000000000000c1c
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1031
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157b62
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000c1c
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1032
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157b78
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000c1c
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1033
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157b62
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1034
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157b78
+2
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1035
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157b62
+2
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1036
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1003
+temporary
+informant-PC
+0x00000000000f2cd6
+2
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1037
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x00000000001354c8
+2
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1038
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1001
+admin11
+informant-PC
+0x00000000001354b3
+2
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+1039
+
+
+Security
+informant-PC
+
+
+
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+1040
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000022517
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+1041
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1042
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+1043
+
+
+Security
+informant-PC
+
+
+0
+0x000000000000bac4
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1044
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1045
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1046
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1047
+
+
+Security
+informant-PC
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1048
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1049
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1050
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1051
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1052
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1053
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1054
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1055
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+1056
+
+
+Security
+informant-PC
+
+
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+1057
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1058
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x000000000001b9a4
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1059
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x00000000000001a8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1060
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000002359c
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001a8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1061
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000235cc
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001a8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1062
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000002359c
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1063
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1064
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+1065
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+2015-03-23 17:25:47.192598
+2015-03-23 17:25:47.191999
+0x0000000000000358
+C:\Windows\System32\svchost.exe
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1066
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1067
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1068
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1069
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+1070
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+2015-03-23 18:57:01.113134
+2015-03-23 19:08:15.571480
+0x0000000000000358
+C:\Windows\System32\svchost.exe
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+1071
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+2015-03-23 19:08:15.571480
+2015-03-23 19:08:15.570999
+0x0000000000000358
+C:\Windows\System32\svchost.exe
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+1072
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+2015-03-23 19:08:46.443419
+2015-03-23 19:08:46.442999
+0x0000000000000358
+C:\Windows\System32\svchost.exe
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1073
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1074
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1075
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1076
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1077
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1078
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1079
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e4
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1080
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4904
+0
+0
+13568
+0
+0x8020000000000000
+
+1081
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000002c2083
+0x0000000000000d40
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4905
+0
+0
+13568
+0
+0x8020000000000000
+
+1082
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000002c2083
+0x0000000000000d40
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1083
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000235cc
+{00000000-0000-0000-0000-000000000000}
+Company
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+Company-PC
+Company-PC
+0x0000000000000004
+
+-
+-
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+1084
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000235cc
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+1085
+
+
+Security
+informant-PC
+
+
+
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+1086
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1087
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+1088
+
+
+Security
+informant-PC
+
+
+0
+0x000000000000b683
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1089
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1090
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1091
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1092
+
+
+Security
+informant-PC
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1093
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1094
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1095
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1096
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1097
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1098
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1099
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1100
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+1101
+
+
+Security
+informant-PC
+
+
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+1102
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1103
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x000000000001c0ce
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1104
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1105
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000002269c
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1106
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000226c4
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1107
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000002269c
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1108
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1109
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1110
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1111
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1112
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000226c4
+{00000000-0000-0000-0000-000000000000}
+Company
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+Company-PC
+Company-PC
+0x0000000000000004
+
+-
+-
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1113
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1114
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1115
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1116
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1117
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1118
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1119
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1120
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1121
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1122
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1123
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1124
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000006cabcf
+7
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1125
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000006cabdd
+7
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001b8
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1126
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000006cabcf
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1127
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000006cabdd
+7
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1128
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000006cabcf
+7
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1129
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001e8
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1130
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+1131
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x00000000000226c4
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+1132
+
+
+Security
+informant-PC
+
+
+
+
+
+
+
+4608
+0
+0
+12288
+0
+0x8020000000000000
+
+1133
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1134
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+0
+-
+-
+-
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000004
+
+-
+-
+
+
+
+
+4902
+0
+0
+13568
+0
+0x8020000000000000
+
+1135
+
+
+Security
+informant-PC
+
+
+0
+0x000000000000ba7d
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1136
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1137
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1138
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1139
+
+
+Security
+informant-PC
+
+
+S-1-5-20
+NETWORK SERVICE
+NT AUTHORITY
+0x00000000000003e4
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1140
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1141
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1142
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1143
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1144
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1145
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1146
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1147
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+5033
+0
+0
+12292
+0
+0x8020000000000000
+
+1148
+
+
+Security
+informant-PC
+
+
+
+
+
+
+5024
+0
+0
+12292
+0
+0x8020000000000000
+
+1149
+
+
+Security
+informant-PC
+
+
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1150
+
+
+Security
+informant-PC
+
+
+S-1-0-0
+-
+-
+0x0000000000000000
+S-1-5-7
+ANONYMOUS LOGON
+NT AUTHORITY
+0x000000000001c0d1
+3
+NtLmSsp
+NTLM
+
+{00000000-0000-0000-0000-000000000000}
+-
+NTLM V1
+0
+0x0000000000000000
+-
+-
+-
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1151
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1152
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000025465
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1153
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000025493
+2
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1154
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000025465
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1155
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1156
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1157
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1158
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1159
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1160
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+1161
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+2015-03-25 13:29:46.566790
+2015-03-25 14:13:47.009901
+0x0000000000000330
+C:\Windows\System32\svchost.exe
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+1162
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+2015-03-25 14:13:47.025499
+2015-03-25 14:13:47.025000
+0x0000000000000330
+C:\Windows\System32\svchost.exe
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1163
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1164
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4648
+0
+0
+12544
+0
+0x8020000000000000
+
+1165
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+{00000000-0000-0000-0000-000000000000}
+informant
+informant-PC
+{00000000-0000-0000-0000-000000000000}
+localhost
+localhost
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1166
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157773
+7
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1167
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000015777f
+7
+User32
+Negotiate
+INFORMANT-PC
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x0000000000000194
+C:\Windows\System32\winlogon.exe
+127.0.0.1
+0
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1168
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157773
+SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1169
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x000000000015777f
+7
+
+
+
+
+4634
+0
+0
+12545
+0
+0x8020000000000000
+
+1170
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000157773
+7
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1171
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1172
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1173
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1174
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1175
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1176
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4904
+0
+0
+13568
+0
+0x8020000000000000
+
+1177
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000001aa8e7
+0x0000000000000934
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4905
+0
+0
+13568
+0
+0x8020000000000000
+
+1178
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x00000000001aa8e7
+0x0000000000000934
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1179
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1180
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1181
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1182
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1183
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1184
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1185
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1186
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4904
+0
+0
+13568
+0
+0x8020000000000000
+
+1187
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x0000000000245dcb
+0x0000000000000aa4
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4905
+0
+0
+13568
+0
+0x8020000000000000
+
+1188
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+VSSAudit
+0x0000000000245dcb
+0x0000000000000aa4
+C:\Windows\System32\VSSVC.exe
+
+
+
+
+4624
+0
+0
+12544
+0
+0x8020000000000000
+
+1189
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+INFORMANT-PC$
+WORKGROUP
+0x00000000000003e7
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+5
+Advapi
+Negotiate
+
+{00000000-0000-0000-0000-000000000000}
+-
+-
+0
+0x00000000000001d0
+C:\Windows\System32\services.exe
+-
+-
+
+
+
+
+4672
+0
+0
+12548
+0
+0x8020000000000000
+
+1190
+
+
+Security
+informant-PC
+
+
+S-1-5-18
+SYSTEM
+NT AUTHORITY
+0x00000000000003e7
+SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+4647
+0
+0
+12545
+0
+0x8020000000000000
+
+1191
+
+
+Security
+informant-PC
+
+
+S-1-5-21-2425377081-3129163575-2985601102-1000
+informant
+informant-PC
+0x0000000000025493
+
+
+
+
+4616
+1
+0
+12288
+0
+0x8020000000000000
+
+1192
+
+
+Security
+informant-PC
+
+
+S-1-5-19
+LOCAL SERVICE
+NT AUTHORITY
+0x00000000000003e5
+2015-03-25 15:31:00.240004
+2015-03-25 15:31:00.240000
+0x0000000000000330
+C:\Windows\System32\svchost.exe
+
+
+
+
+1100
+0
+4
+103
+0
+0x4020000000000000
+
+1193
+
+
+Security
+informant-PC
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore.xml b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore.xml
new file mode 100644
index 0000000..3f0376a
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore.xml
@@ -0,0 +1,21 @@
+
+
+
+ Everyday Italian
+ Giada De Laurentiis
+ 2005
+ 30.00
+
+
+ Harry Potter
+ J K. Rowling
+ 2005
+ 29.99
+
+
+ Learning XML
+ Erik T. Ray
+ 2003
+ 39.95
+
+
\ No newline at end of file
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_book_category_attrib.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_book_category_attrib.py
new file mode 100644
index 0000000..36e0a1f
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_book_category_attrib.py
@@ -0,0 +1,10 @@
+import xml.etree.ElementTree as ET
+
+tree = ET.parse("bookstore_removed_ns.xml")
+root = tree.getroot()
+
+# Iterate through the book elements and print their category attributes
+for book in root.findall(".//book"): # Find all 'book' elements at any depth
+ # Get book category attribute
+ cate = book.attrib.get("category")
+ print("book category: {}".format(cate))
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_tags.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_tags.py
new file mode 100644
index 0000000..b760977
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_tags.py
@@ -0,0 +1,16 @@
+import xml.etree.ElementTree as ET
+
+tree = ET.parse("bookstore.xml")
+root = tree.getroot()
+
+# Create an empty set to store unique tag names
+tag_names = set()
+
+# Iterate through the elements and collect unique tag names
+for element in root.iter():
+ tag_names.add(element.tag)
+
+# Convert the set to a sorted list and print the tag names
+tag_list = sorted(tag_names)
+for tag in tag_list:
+ print(tag)
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_titles_v1.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_titles_v1.py
new file mode 100644
index 0000000..93914fc
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_titles_v1.py
@@ -0,0 +1,11 @@
+import xml.etree.ElementTree as ET
+
+tree = ET.parse("bookstore.xml")
+root = tree.getroot()
+
+# Iterate through the book elements and print their titles
+for book in root.findall(".//book"): # Find all 'book' elements at any depth
+ # Find the first 'title' elements at current depth
+ title_element = book.find("title")
+ if title_element is not None:
+ print("Book Title: {}".format(title_element.text))
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_titles_v2.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_titles_v2.py
new file mode 100644
index 0000000..5dd52b2
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_list_titles_v2.py
@@ -0,0 +1,8 @@
+import xml.etree.ElementTree as ET
+
+tree = ET.parse("bookstore.xml")
+root = tree.getroot()
+
+# Find and print all the "year" elements
+for title_element in root.findall(".//title"):
+ print(title_element.text)
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_ns.xml b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_ns.xml
new file mode 100644
index 0000000..faba862
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_ns.xml
@@ -0,0 +1,21 @@
+
+
+
+ Everyday Italian
+ Giada De Laurentiis
+ 2005
+ 30.00
+
+
+ Harry Potter
+ J K. Rowling
+ 2005
+ 29.99
+
+
+ Learning XML
+ Erik T. Ray
+ 2003
+ 39.95
+
+
\ No newline at end of file
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_remove_ns.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_remove_ns.py
new file mode 100644
index 0000000..a6b4da7
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_remove_ns.py
@@ -0,0 +1,23 @@
+import xml.etree.ElementTree as ET
+
+tree = ET.parse("bookstore.xml")
+root = tree.getroot()
+
+
+# Define a function to recursively remove all namespace prefixes
+def remove_namespace_prefix(element):
+ print(element.tag)
+ element.tag = element.tag.split("}", 1)[-1] # Remove namespace prefix
+ for child in element:
+ remove_namespace_prefix(child)
+
+
+# Remove namespace prefixes from the root element and its descendants
+remove_namespace_prefix(root)
+
+# Convert the modified XML tree to a string
+modified_xml = ET.tostring(root, encoding="utf-8")
+
+# Save the updated XML to a new file
+with open("bookstore_removed_ns.xml", "wb") as f:
+ f.write(modified_xml)
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_removed_ns.xml b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_removed_ns.xml
new file mode 100644
index 0000000..92266b6
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_removed_ns.xml
@@ -0,0 +1,20 @@
+
+
+ Everyday Italian
+ Giada De Laurentiis
+ 2005
+ 30.00
+
+
+ Harry Potter
+ J K. Rowling
+ 2005
+ 29.99
+
+
+ Learning XML
+ Erik T. Ray
+ 2003
+ 39.95
+
+
\ No newline at end of file
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_show_first_book.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_show_first_book.py
new file mode 100644
index 0000000..baceb9c
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_show_first_book.py
@@ -0,0 +1,12 @@
+import xml.etree.ElementTree as ET
+
+tree = ET.parse("bookstore.xml")
+root = tree.getroot()
+
+# Access the first child element of the root directly using indexing
+first_element = root[0]
+
+# Print the tag name and text content of the first element
+print("Tag Name:", first_element.tag)
+for child in first_element:
+ print(f"{child.tag}: {child.text}")
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_update_one_author.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_update_one_author.py
new file mode 100644
index 0000000..c5afd4e
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_update_one_author.py
@@ -0,0 +1,15 @@
+import xml.etree.ElementTree as ET
+
+tree = ET.parse("bookstore.xml")
+root = tree.getroot()
+
+# Find the "author" element with the current name and update it
+for author_element in root.findall(".//author"):
+ if author_element.text == "Giada De Laurentiis":
+ author_element.text = "Giada Laurentiis"
+
+# Serialize the updated XML to a string
+updated_xml_content = ET.tostring(root, encoding="utf-8")
+
+# Print the updated XML content
+print(updated_xml_content.decode("utf-8"))
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_update_price_plus1.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_update_price_plus1.py
new file mode 100644
index 0000000..f3f381d
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/bookstore_update_price_plus1.py
@@ -0,0 +1,17 @@
+import xml.etree.ElementTree as ET
+
+tree = ET.parse("bookstore.xml")
+root = tree.getroot()
+
+# Find and update all the "price" elements
+for price_element in root.findall(".//price"):
+ current_price = float(price_element.text)
+ new_price = current_price + 1
+ price_element.text = str(new_price)
+
+# Serialize the updated XML to a string
+updated_xml_content = ET.tostring(root, encoding="utf-8")
+
+# Save the updated XML to a new file
+with open("bookstore_updated.xml", "wb") as f:
+ f.write(updated_xml_content)
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityEvt_formatted.xml b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityEvt_formatted.xml
new file mode 100644
index 0000000..a046350
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityEvt_formatted.xml
@@ -0,0 +1,39045 @@
+
+
+
+
+
+ 4608
+ 0
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 1
+
+
+ Security
+ 37L4247F27-25
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 2
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 0
+ -
+ -
+ -
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000004
+
+ -
+ -
+
+
+
+
+
+ 4902
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 3
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ 0
+ 0x0000000000035ce9
+
+
+
+
+
+ 4731
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 4
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ Backup Operators
+ Builtin
+ S-1-5-32-551
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Backup Operators
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 5
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ Backup Operators
+ Builtin
+ S-1-5-32-551
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4731
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 6
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ Replicator
+ Builtin
+ S-1-5-32-552
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Replicator
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 7
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ Replicator
+ Builtin
+ S-1-5-32-552
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4731
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 8
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ Remote Desktop Users
+ Builtin
+ S-1-5-32-555
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Remote Desktop Users
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 9
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ Remote Desktop Users
+ Builtin
+ S-1-5-32-555
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4731
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 10
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ Network Configuration Operators
+ Builtin
+ S-1-5-32-556
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Network Configuration Operators
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 11
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ Network Configuration Operators
+ Builtin
+ S-1-5-32-556
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4731
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 12
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ Power Users
+ Builtin
+ S-1-5-32-547
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Power Users
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 13
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ Power Users
+ Builtin
+ S-1-5-32-547
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4731
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 14
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ Cryptographic Operators
+ Builtin
+ S-1-5-32-569
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Cryptographic Operators
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 15
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ Cryptographic Operators
+ Builtin
+ S-1-5-32-569
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 16
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 17
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 18
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 19
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 20
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 21
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 22
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 23
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 24
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 25
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 26
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 27
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 28
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 29
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 5033
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 30
+
+
+ Security
+ 37L4247F27-25
+
+
+
+
+
+
+
+ 5024
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 31
+
+
+ Security
+ 37L4247F27-25
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 32
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-7
+ ANONYMOUS LOGON
+ NT AUTHORITY
+ 0x00000000000454a7
+ 3
+ NtLmSsp
+ NTLM
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ NTLM V1
+ 0
+ 0x0000000000000000
+ -
+ -
+ -
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 33
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ -
+ Administrator
+ 37L4247F27-25
+ S-1-5-21-2425377081-3129163575-2985601102-500
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ 0x211
+ 0x211
+ -
+ -
+ -
+ -
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 34
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 35
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 36
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 37
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 38
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 39
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 40
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ 37L4247F27-25$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 41
+
+
+ Security
+ 37L4247F27-25
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 1100
+ 0
+ 4
+ 103
+ 0
+ 0x4020000000000000
+
+ 42
+
+
+ Security
+ 37L4247F27-25
+
+
+
+
+
+
+
+
+
+ 4608
+ 0
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 43
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 44
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 0
+ -
+ -
+ -
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000004
+
+ -
+ -
+
+
+
+
+
+ 4902
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 45
+
+
+ Security
+ informant-PC
+
+
+
+ 0
+ 0x000000000000d031
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 46
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 47
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 48
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 49
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 50
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 51
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 52
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 53
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 54
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 55
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 56
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 57
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 58
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 59
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 5033
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 60
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 5024
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 61
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 62
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-7
+ ANONYMOUS LOGON
+ NT AUTHORITY
+ 0x0000000000028c63
+ 3
+ NtLmSsp
+ NTLM
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ NTLM V1
+ 0
+ 0x0000000000000000
+ -
+ -
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 63
+
+
+ Security
+ informant-PC
+
+
+
+ Administrators
+ Builtin
+ S-1-5-32-544
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4781
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 64
+
+
+ Security
+ informant-PC
+
+
+
+ Administrators
+ Administrators
+ Builtin
+ S-1-5-32-544
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 65
+
+
+ Security
+ informant-PC
+
+
+
+ Administrators
+ Builtin
+ S-1-5-32-544
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Administrators
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 66
+
+
+ Security
+ informant-PC
+
+
+
+ Users
+ Builtin
+ S-1-5-32-545
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4781
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 67
+
+
+ Security
+ informant-PC
+
+
+
+ Users
+ Users
+ Builtin
+ S-1-5-32-545
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 68
+
+
+ Security
+ informant-PC
+
+
+
+ Users
+ Builtin
+ S-1-5-32-545
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Users
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 69
+
+
+ Security
+ informant-PC
+
+
+
+ Guests
+ Builtin
+ S-1-5-32-546
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4781
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 70
+
+
+ Security
+ informant-PC
+
+
+
+ Guests
+ Guests
+ Builtin
+ S-1-5-32-546
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 71
+
+
+ Security
+ informant-PC
+
+
+
+ Guests
+ Builtin
+ S-1-5-32-546
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Guests
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 72
+
+
+ Security
+ informant-PC
+
+
+
+ Backup Operators
+ Builtin
+ S-1-5-32-551
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4781
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 73
+
+
+ Security
+ informant-PC
+
+
+
+ Backup Operators
+ Backup Operators
+ Builtin
+ S-1-5-32-551
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 74
+
+
+ Security
+ informant-PC
+
+
+
+ Backup Operators
+ Builtin
+ S-1-5-32-551
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Backup Operators
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 75
+
+
+ Security
+ informant-PC
+
+
+
+ Replicator
+ Builtin
+ S-1-5-32-552
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4781
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 76
+
+
+ Security
+ informant-PC
+
+
+
+ Replicator
+ Replicator
+ Builtin
+ S-1-5-32-552
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 77
+
+
+ Security
+ informant-PC
+
+
+
+ Replicator
+ Builtin
+ S-1-5-32-552
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Replicator
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 78
+
+
+ Security
+ informant-PC
+
+
+
+ Remote Desktop Users
+ Builtin
+ S-1-5-32-555
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4781
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 79
+
+
+ Security
+ informant-PC
+
+
+
+ Remote Desktop Users
+ Remote Desktop Users
+ Builtin
+ S-1-5-32-555
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 80
+
+
+ Security
+ informant-PC
+
+
+
+ Remote Desktop Users
+ Builtin
+ S-1-5-32-555
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Remote Desktop Users
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 81
+
+
+ Security
+ informant-PC
+
+
+
+ Network Configuration Operators
+ Builtin
+ S-1-5-32-556
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4781
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 82
+
+
+ Security
+ informant-PC
+
+
+
+ Network Configuration Operators
+ Network Configuration Operators
+ Builtin
+ S-1-5-32-556
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 83
+
+
+ Security
+ informant-PC
+
+
+
+ Network Configuration Operators
+ Builtin
+ S-1-5-32-556
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Network Configuration Operators
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 84
+
+
+ Security
+ informant-PC
+
+
+
+ Power Users
+ Builtin
+ S-1-5-32-547
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4781
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 85
+
+
+ Security
+ informant-PC
+
+
+
+ Power Users
+ Power Users
+ Builtin
+ S-1-5-32-547
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 86
+
+
+ Security
+ informant-PC
+
+
+
+ Power Users
+ Builtin
+ S-1-5-32-547
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Power Users
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 87
+
+
+ Security
+ informant-PC
+
+
+
+ Performance Monitor Users
+ Builtin
+ S-1-5-32-558
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4781
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 88
+
+
+ Security
+ informant-PC
+
+
+
+ Performance Monitor Users
+ Performance Monitor Users
+ Builtin
+ S-1-5-32-558
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 89
+
+
+ Security
+ informant-PC
+
+
+
+ Performance Monitor Users
+ Builtin
+ S-1-5-32-558
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Performance Monitor Users
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 90
+
+
+ Security
+ informant-PC
+
+
+
+ Performance Log Users
+ Builtin
+ S-1-5-32-559
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4781
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 91
+
+
+ Security
+ informant-PC
+
+
+
+ Performance Log Users
+ Performance Log Users
+ Builtin
+ S-1-5-32-559
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 92
+
+
+ Security
+ informant-PC
+
+
+
+ Performance Log Users
+ Builtin
+ S-1-5-32-559
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Performance Log Users
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 93
+
+
+ Security
+ informant-PC
+
+
+
+ Distributed COM Users
+ Builtin
+ S-1-5-32-562
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4781
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 94
+
+
+ Security
+ informant-PC
+
+
+
+ Distributed COM Users
+ Distributed COM Users
+ Builtin
+ S-1-5-32-562
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 95
+
+
+ Security
+ informant-PC
+
+
+
+ Distributed COM Users
+ Builtin
+ S-1-5-32-562
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Distributed COM Users
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 96
+
+
+ Security
+ informant-PC
+
+
+
+ IIS_IUSRS
+ Builtin
+ S-1-5-32-568
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4781
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 97
+
+
+ Security
+ informant-PC
+
+
+
+ IIS_IUSRS
+ IIS_IUSRS
+ Builtin
+ S-1-5-32-568
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 98
+
+
+ Security
+ informant-PC
+
+
+
+ IIS_IUSRS
+ Builtin
+ S-1-5-32-568
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ IIS_IUSRS
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 99
+
+
+ Security
+ informant-PC
+
+
+
+ Cryptographic Operators
+ Builtin
+ S-1-5-32-569
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4781
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 100
+
+
+ Security
+ informant-PC
+
+
+
+ Cryptographic Operators
+ Cryptographic Operators
+ Builtin
+ S-1-5-32-569
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 101
+
+
+ Security
+ informant-PC
+
+
+
+ Cryptographic Operators
+ Builtin
+ S-1-5-32-569
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Cryptographic Operators
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 102
+
+
+ Security
+ informant-PC
+
+
+
+ Event Log Readers
+ Builtin
+ S-1-5-32-573
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+
+
+
+
+
+ 4781
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 103
+
+
+ Security
+ informant-PC
+
+
+
+ Event Log Readers
+ Event Log Readers
+ Builtin
+ S-1-5-32-573
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4735
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 104
+
+
+ Security
+ informant-PC
+
+
+
+ Event Log Readers
+ Builtin
+ S-1-5-32-573
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Event Log Readers
+ -
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 105
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ Administrator
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-500
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Administrator
+ %%1793
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ 11/20/2010 8:57:24 PM
+ %%1794
+ 513
+ -
+ 0x211
+ 0x211
+ -
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 106
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ Administrator
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-500
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Administrator
+ %%1793
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ 11/20/2010 8:57:24 PM
+ %%1794
+ 513
+ -
+ 0x211
+ 0x211
+ -
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 107
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ Guest
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-501
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Guest
+ %%1793
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1794
+ %%1794
+ 513
+ -
+ 0x215
+ 0x215
+ -
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 108
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ Guest
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-501
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ Guest
+ %%1793
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1794
+ %%1794
+ 513
+ -
+ 0x215
+ 0x215
+ -
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4616
+ 1
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 109
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ 2015-03-25 10:34:25.685648
+ 2015-03-22 14:33:53.237000
+ 0x0000000000000340
+ C:\Windows\System32\oobe\msoobe.exe
+
+
+
+
+
+ 4728
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 110
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ None
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-513
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4720
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 111
+
+
+ Security
+ informant-PC
+
+
+
+ informant
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ informant
+ %%1793
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1794
+ %%1794
+ 513
+ -
+ 0x0
+ 0x15
+
+ %%2080
+ %%2082
+ %%2084
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4732
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 112
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ Users
+ Builtin
+ S-1-5-32-545
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4722
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 113
+
+
+ Security
+ informant-PC
+
+
+
+ informant
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 114
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ informant
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ informant
+ %%1793
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1794
+ %%1794
+ 513
+ -
+ 0x15
+ 0x14
+
+ %%2048
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4732
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 115
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ Administrators
+ Builtin
+ S-1-5-32-544
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4733
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 116
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ Users
+ Builtin
+ S-1-5-32-545
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 117
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ informant
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ informant
+ %%1793
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ 3/22/2015 10:33:54 AM
+ %%1794
+ 513
+ -
+ 0x14
+ 0x214
+
+ %%2089
+ -
+ -
+ %%1797
+
+
+
+
+
+ 4724
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 118
+
+
+ Security
+ informant-PC
+
+
+
+ informant
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 119
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ informant
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 120
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 121
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 122
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ {00000000-0000-0000-0000-000000000000}
+ informant
+ informant-PC
+ {00000000-0000-0000-0000-000000000000}
+ localhost
+ localhost
+ 0x0000000000000194
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 123
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x000000000003be29
+ 2
+ User32
+ Negotiate
+ WIN-D9RGPJQ68G8
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000194
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 124
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x000000000003db0a
+ 2
+ User32
+ Negotiate
+ WIN-D9RGPJQ68G8
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000194
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 125
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x000000000003be29
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 126
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ WIN-D9RGPJQ68G8$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 127
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 1100
+ 0
+ 4
+ 103
+ 0
+ 0x4020000000000000
+
+ 128
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+
+
+ 4647
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 129
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x000000000003db0a
+
+
+
+
+
+ 4608
+ 0
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 130
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 131
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 0
+ -
+ -
+ -
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000004
+
+ -
+ -
+
+
+
+
+
+ 4902
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 132
+
+
+ Security
+ informant-PC
+
+
+
+ 0
+ 0x000000000000b8dc
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 133
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 134
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 135
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 136
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 137
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 138
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 139
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 140
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 141
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 142
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 143
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 144
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 5033
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 145
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 5024
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 146
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 147
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-7
+ ANONYMOUS LOGON
+ NT AUTHORITY
+ 0x000000000001a667
+ 3
+ NtLmSsp
+ NTLM
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ NTLM V1
+ 0
+ 0x0000000000000000
+ -
+ -
+ -
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 148
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 149
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 150
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 151
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 152
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ {00000000-0000-0000-0000-000000000000}
+ informant
+ informant-PC
+ {00000000-0000-0000-0000-000000000000}
+ localhost
+ localhost
+ 0x0000000000000184
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 153
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000026923
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000184
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 154
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000026951
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000184
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 155
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000026923
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 156
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 157
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 158
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 159
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 160
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 161
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4904
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 162
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ VSSAudit
+ 0x0000000000069adb
+ 0x0000000000000bc0
+ C:\Windows\System32\VSSVC.exe
+
+
+
+
+
+ 4905
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 163
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ VSSAudit
+ 0x0000000000069adb
+ 0x0000000000000bc0
+ C:\Windows\System32\VSSVC.exe
+
+
+
+
+
+ 4904
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 164
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ VSSAudit
+ 0x00000000000835e3
+ 0x0000000000000bc0
+ C:\Windows\System32\VSSVC.exe
+
+
+
+
+
+ 4905
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 165
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ VSSAudit
+ 0x00000000000835e3
+ 0x0000000000000bc0
+ C:\Windows\System32\VSSVC.exe
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 166
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 167
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 168
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 169
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 170
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 171
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 172
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 173
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4904
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 174
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ VSSAudit
+ 0x00000000001fa262
+ 0x0000000000000e6c
+ C:\Windows\System32\VSSVC.exe
+
+
+
+
+
+ 4905
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 175
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ VSSAudit
+ 0x00000000001fa262
+ 0x0000000000000e6c
+ C:\Windows\System32\VSSVC.exe
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 176
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 177
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 178
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\winsxs\Temp\PendingRenames\a86dcf49b364d00184220000f80e440b.install.ins
+ 0x00000000000086e8
+
+ S:ARAI
+ 0x0000000000000ef8
+ C:\Windows\servicing\TrustedInstaller.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 179
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\winsxs\Temp\PendingRenames\08cfd149b364d00185220000f80e440b.install.ins
+ 0x00000000000088b0
+
+ S:ARAI
+ 0x0000000000000ef8
+ C:\Windows\servicing\TrustedInstaller.exe
+
+
+
+
+
+ 4647
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 180
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000026951
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 181
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\DWrite.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 182
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\d2d1.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 183
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\msmpeg2vdec.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 184
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 185
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\d3d10core.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 186
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 187
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 188
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\XpsGdiConverter.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 189
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 190
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\d3d10warp.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 191
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 192
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\dxgi.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 193
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\WMPhoto.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 194
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\FntCache.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 195
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 196
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\d3d10_1.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 197
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\WindowsCodecsExt.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 198
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 199
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\d3d10level9.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 200
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\UIAnimation.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 201
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 202
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\d3d10_1core.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 203
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\XpsPrint.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 204
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 205
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\d3d10.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 206
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\WindowsCodecs.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 207
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\d3d11.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 208
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 209
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 210
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\UIAnimation.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 211
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 212
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 213
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\da-DK\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 214
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\da-DK\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 215
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\da-DK\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 216
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\da-DK\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 217
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\nb-NO\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 218
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\nb-NO\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 219
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\nb-NO\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 220
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\nb-NO\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 221
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\spp\tokens\ppdlic\msmpeg2vdec-ppdlic.xrm-ms
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 222
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ru-RU\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 223
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ru-RU\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 224
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ru-RU\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 225
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ru-RU\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 226
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ja-JP\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 227
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ja-JP\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 228
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ja-JP\UIAnimation.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 229
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ja-JP\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 230
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ja-JP\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 231
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\zh-CN\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 232
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\zh-CN\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 233
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\zh-CN\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 234
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\zh-CN\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 235
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\cs-CZ\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 236
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\cs-CZ\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 237
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\cs-CZ\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 238
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\cs-CZ\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 239
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\de-DE\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 240
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\de-DE\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 241
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\de-DE\UIAnimation.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 242
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\de-DE\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 243
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\de-DE\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 244
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\zh-TW\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 245
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\zh-TW\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 246
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\zh-TW\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 247
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\zh-TW\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 248
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\es-ES\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 249
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\es-ES\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 250
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\es-ES\UIAnimation.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 251
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\es-ES\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 252
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\es-ES\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 253
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\sv-SE\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 254
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\sv-SE\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 255
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\sv-SE\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 256
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\sv-SE\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 257
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\tr-TR\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 258
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\tr-TR\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 259
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\tr-TR\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 260
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\tr-TR\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 261
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\fi-FI\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 262
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\fi-FI\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 263
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\fi-FI\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 264
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\fi-FI\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 265
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\fr-FR\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 266
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\fr-FR\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 267
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\fr-FR\UIAnimation.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 268
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\fr-FR\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 269
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\fr-FR\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 270
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\nl-NL\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 271
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\nl-NL\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 272
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\nl-NL\UIAnimation.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 273
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\nl-NL\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 274
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\nl-NL\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 275
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\el-GR\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 276
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\el-GR\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 277
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\el-GR\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 278
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\el-GR\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 279
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\zh-HK\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 280
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\zh-HK\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 281
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\zh-HK\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 282
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\zh-HK\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 283
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\hu-HU\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 284
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\hu-HU\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 285
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\hu-HU\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 286
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\hu-HU\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 287
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ko-KR\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 288
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ko-KR\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 289
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ko-KR\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 290
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ko-KR\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 291
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\pl-PL\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 292
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\pl-PL\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 293
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\pl-PL\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 294
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\pl-PL\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 295
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\pt-PT\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 296
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\pt-PT\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 297
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\pt-PT\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 298
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\pt-PT\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 299
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\it-IT\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 300
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\it-IT\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 301
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\it-IT\UIAnimation.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 302
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\it-IT\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 303
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\it-IT\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 304
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\pt-BR\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 305
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\pt-BR\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 306
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\pt-BR\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 307
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\pt-BR\FntCache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 308
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\DWrite.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 309
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\d2d1.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 310
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\msmpeg2vdec.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 311
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 312
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\d3d10core.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 313
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 314
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 315
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\XpsGdiConverter.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 316
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 317
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\d3d10warp.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 318
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\dxgi.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 319
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 320
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\WMPhoto.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 321
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 322
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\d3d10_1.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 323
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\d3d10level9.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 324
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\WindowsCodecsExt.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 325
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 326
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 327
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\UIAnimation.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 328
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\d3d10_1core.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 329
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\XpsPrint.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 330
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 331
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\d3d10.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 332
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\WindowsCodecs.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 333
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\d3d11.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 334
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 335
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 336
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\UIAnimation.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 337
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 338
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\da-DK\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 339
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\da-DK\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 340
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\da-DK\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 341
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\nb-NO\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 342
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\nb-NO\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 343
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\nb-NO\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 344
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\spp\tokens\ppdlic\msmpeg2vdec-ppdlic.xrm-ms
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 345
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ru-RU\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 346
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ru-RU\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 347
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ru-RU\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 348
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ja-JP\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 349
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ja-JP\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 350
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ja-JP\UIAnimation.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 351
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ja-JP\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 352
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\zh-CN\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 353
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\zh-CN\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 354
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\zh-CN\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 355
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\cs-CZ\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 356
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\cs-CZ\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 357
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\cs-CZ\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 358
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\de-DE\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 359
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\de-DE\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 360
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\de-DE\UIAnimation.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 361
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\de-DE\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 362
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\zh-TW\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 363
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\zh-TW\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 364
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\zh-TW\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 365
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\es-ES\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 366
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\es-ES\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 367
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\es-ES\UIAnimation.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 368
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\es-ES\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 369
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\sv-SE\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 370
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\sv-SE\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 371
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\sv-SE\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 372
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\tr-TR\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 373
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\tr-TR\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 374
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\tr-TR\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 375
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\fi-FI\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 376
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\fi-FI\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 377
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\fi-FI\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 378
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\fr-FR\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 379
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\fr-FR\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 380
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\fr-FR\UIAnimation.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 381
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\fr-FR\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 382
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\nl-NL\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 383
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\nl-NL\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 384
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\nl-NL\UIAnimation.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 385
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\nl-NL\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 386
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\el-GR\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 387
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\el-GR\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 388
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\el-GR\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 389
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\zh-HK\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 390
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\zh-HK\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 391
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\zh-HK\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 392
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\hu-HU\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 393
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\hu-HU\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 394
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\hu-HU\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 395
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ko-KR\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 396
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ko-KR\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 397
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ko-KR\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 398
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\pl-PL\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 399
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\pl-PL\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 400
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\pl-PL\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 401
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\pt-PT\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 402
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\pt-PT\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 403
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\pt-PT\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 404
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\it-IT\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 405
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\it-IT\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 406
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\it-IT\UIAnimation.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 407
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\it-IT\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 408
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\pt-BR\WMPhoto.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 409
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\pt-BR\d2d1.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 410
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\pt-BR\DWrite.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 411
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ntoskrnl.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 412
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ntoskrnl.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 413
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ntkrnlpa.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 414
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\AppPatch\acwow64.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 415
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 416
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 417
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 418
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 419
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\wow64.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 420
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\wow64cpu.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 421
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 422
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 423
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 424
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 425
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 426
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 427
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 428
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ntvdm64.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 429
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 430
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 431
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 432
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 433
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 434
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 435
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\conhost.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 436
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 437
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 438
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 439
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\wow64win.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 440
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 441
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\kernel32.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 442
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\KernelBase.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 443
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 444
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 445
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 446
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 447
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\winsrv.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 448
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 449
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 450
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 451
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 452
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 453
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\setup16.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 454
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\user.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 455
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 456
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ntvdm64.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 457
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 458
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 459
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 460
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 461
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 462
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 463
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 464
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 465
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 466
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\instnm.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 467
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 468
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 469
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 470
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 471
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 472
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 473
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\kernel32.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 474
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 475
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 476
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 477
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 478
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 479
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\KernelBase.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 480
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 481
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 482
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 483
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 484
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 485
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\wow32.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 486
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\AppPatch\acwow64.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 487
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 488
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 489
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 490
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 491
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\wow64.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 492
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\wow64cpu.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 493
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 494
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 495
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 496
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 497
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 498
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 499
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 500
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ntvdm64.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 501
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 502
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 503
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 504
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 505
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 506
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 507
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\conhost.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 508
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 509
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 510
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 511
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\wow64win.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 512
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 513
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\kernel32.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 514
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\KernelBase.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 515
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 516
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 517
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 518
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 519
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\winsrv.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 520
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 521
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 522
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 523
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\KernelBase.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 524
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\instnm.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 525
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 526
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 527
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 528
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 529
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\user.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 530
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 531
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 532
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 533
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 534
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 535
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 536
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 537
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ntvdm64.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 538
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 539
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 540
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 541
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 542
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 543
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 544
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\wow32.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 545
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 546
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 547
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 548
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 549
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\kernel32.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 550
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\KernelBase.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 551
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 552
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 553
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 554
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 555
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 556
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\setup16.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 557
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 558
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 559
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\KernelBase.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 560
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\Fonts\seguisym.ttf
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 561
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\Fonts\segoeui.ttf
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 562
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\Fonts\segoeuiz.ttf
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 563
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\Fonts\segoeuib.ttf
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 564
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\Fonts\segoeuii.ttf
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 565
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\taskhost.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 566
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\drivers\afd.sys
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 567
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\drivers\FWPKCLNT.SYS
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 568
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\drivers\tcpip.sys
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 569
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\drivers\netio.sys
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 570
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\mswsock.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 571
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\mswsock.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 572
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\smss.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 573
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\csrsrv.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 574
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ntdll.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 575
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ntoskrnl.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 576
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\apisetschema.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 577
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ntdll.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 578
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ntoskrnl.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 579
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ntkrnlpa.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 580
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\AppPatch\acwow64.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 581
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\tdh.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 582
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 583
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 584
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 585
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 586
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\wow64.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 587
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\wow64cpu.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 588
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 589
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 590
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 591
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 592
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 593
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 594
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 595
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ntvdm64.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 596
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 597
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 598
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 599
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 600
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 601
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 602
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\conhost.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 603
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 604
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\advapi32.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 605
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 606
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 607
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\wow64win.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 608
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 609
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\kernel32.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 610
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\KernelBase.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 611
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 612
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 613
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 614
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 615
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\winsrv.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 616
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 617
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 618
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 619
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\instnm.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 620
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\tdh.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 621
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 622
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 623
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 624
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 625
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\user.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 626
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 627
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 628
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 629
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 630
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 631
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 632
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 633
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ntvdm64.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 634
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 635
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 636
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 637
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 638
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 639
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 640
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\wow32.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 641
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 642
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\advapi32.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 643
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 644
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 645
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 646
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\KernelBase.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 647
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\kernel32.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 648
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 649
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 650
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 651
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 652
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 653
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\setup16.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 654
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 655
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 656
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Common Files\microsoft shared\VGX\VGX.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 657
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\D3DCompiler_47.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 658
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\iexplore.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 659
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\ie9props.propdesc
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 660
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\JSProfilerCore.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 661
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\jsprofilerui.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 662
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\pdm.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 663
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\pdmproxy100.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 664
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\DiagnosticsTap.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 665
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\ExtExport.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 666
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\sqmapi.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 667
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\jsdebuggeride.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 668
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\jsdbgui.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 669
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\msdbg2.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 670
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\networkinspection.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 671
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\iedvtool.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 672
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\ielowutil.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 673
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\ieproxy.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 674
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\ieinstal.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 675
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\F12Tools.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 676
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\IEShims.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 677
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\SIGNUP\install.ins
+ 0x000000000000001c
+ S:AI
+
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 678
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\en-US\F12Tools.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 679
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\en-US\jsprofilerui.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 680
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\en-US\jsdbgui.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 681
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\en-US\iedvtool.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 682
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\en-US\DiagnosticsTap.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 683
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\en-US\ieinstal.exe.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 684
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\en-US\eula.rtf
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 685
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\en-US\networkinspection.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 686
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 687
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 688
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\iexplore.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 689
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\Timeline_is.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 690
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\pdm.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 691
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\msdbg2.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 692
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\Timeline.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 693
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\JSProfilerCore.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 694
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\ielowutil.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 695
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\ieinstal.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 696
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\IEShims.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 697
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\pdmproxy100.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 698
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\perfcore.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 699
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\D3DCompiler_47.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 700
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\iedvtool.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 701
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\ieproxy.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 702
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\DiagnosticsTap.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 703
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\iediagcmd.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 704
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\perf_nt.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 705
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\DiagnosticsHub.DataWarehouse.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 706
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\F12Tools.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 707
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\jsdebuggeride.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 708
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\networkinspection.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 709
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\jsprofilerui.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 710
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\DiagnosticsHub.ScriptedSandboxPlugin.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 711
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\MemoryAnalyzer.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 712
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\F12Resources.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 713
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\ie9props.propdesc
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 714
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\jsdbgui.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 715
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\F12.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 716
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\DiagnosticsHub_is.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 717
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\Timeline.cpu.xml
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 718
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\sqmapi.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 719
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\en-US\jsprofilerui.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 720
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\en-US\F12Tools.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 721
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\en-US\F12.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 722
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\en-US\jsdbgui.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 723
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\en-US\iedvtool.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 724
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\en-US\F12Resources.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 725
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\en-US\ieinstal.exe.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 726
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\en-US\DiagnosticsTap.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 727
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\en-US\networkinspection.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 728
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\en-US\eula.rtf
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 729
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 730
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\images\bing.ico
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 731
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Program Files\Internet Explorer\SIGNUP\install.ins
+ 0x000000000000001c
+ S:AI
+
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 732
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ieapfltr.dat
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 733
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\url.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 734
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\mshta.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 735
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\jsproxy.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 736
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ieUnatt.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 737
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ieui.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 738
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\mshtmlmedia.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 739
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ieetwproxystub.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 740
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\jsIntl.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 741
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\RegisterIEPKEYs.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 742
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\iepeers.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 743
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\elshyph.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 744
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ieframe.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 745
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ie4uinit.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 746
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\licmgr10.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 747
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\mshtmler.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 748
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\iexpress.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 749
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\IEAdvpack.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 750
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\dxtrans.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 751
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\wextract.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 752
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ieetwcollectorres.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 753
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\SetIEInstalledDate.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 754
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\wininet.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 755
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\MshtmlDac.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 756
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\jscript.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 757
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\JavaScriptCollectionAgent.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 758
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\msfeedssync.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 759
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\webcheck.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 760
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\MsSpellCheckingFacility.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 761
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\icardie.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 762
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\iertutil.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 763
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\pngfilt.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 764
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\msls31.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 765
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ieetwcollector.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 766
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\jscript9diag.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 767
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\iedkcs32.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 768
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\iesetup.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 769
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\iernonce.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 770
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\vbscript.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 771
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\inseng.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 772
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\iesysprep.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 773
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\inetcpl.cpl
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 774
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\jscript9.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 775
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\occache.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 776
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ieapfltr.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 777
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\html.iec
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 778
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\imgutil.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 779
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\msfeeds.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 780
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\ieuinit.inf
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 781
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\tdc.ocx
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 782
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\mshtml.tlb
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 783
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\mshtml.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 784
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\mshtmled.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 785
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\urlmon.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 786
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\msfeedsbs.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 787
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\msrating.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 788
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\dxtmsft.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 789
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\iesetup.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 790
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\mshtmlmedia.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 791
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\icardie.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 792
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\iepeers.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 793
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\IEAdvpack.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 794
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\jsIntl.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 795
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\occache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 796
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\MsSpellCheckingFacility.exe.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 797
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\wextract.exe.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 798
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\ieunatt.exe.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 799
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\ie4uinit.exe.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 800
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\iernonce.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 801
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\elshyph.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 802
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\jscript.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 803
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\msrating.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 804
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\ieframe.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 805
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\msfeedsbs.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 806
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\vbscript.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 807
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\ieui.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 808
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\html.iec.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 809
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\iexpress.exe.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 810
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\mshtmler.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 811
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\urlmon.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 812
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\jscript9.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 813
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\iedkcs32.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 814
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\webcheck.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 815
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\wininet.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 816
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\mshta.exe.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 817
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\licmgr10.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 818
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\mshtml.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 819
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\inseng.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 820
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\inetcpl.cpl.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 821
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\en-US\ieetwcollectorres.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 822
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\spp\tokens\ppdlic\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 823
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\wdi\perftrack\Microsoft-Windows-IE-HTMLRendering.ptxml
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 824
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\wdi\perftrack\ieframe.ptxml
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 825
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\wdi\perftrack\Microsoft-Windows-IE-F12-Provider.ptxml
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 826
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\System32\migration\WininetPlugin.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 827
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\PolicyDefinitions\inetres.admx
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 828
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\PolicyDefinitions\en-US\InetRes.adml
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 829
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ieapfltr.dat
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 830
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\mshta.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 831
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\jsproxy.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 832
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\url.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 833
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ieUnatt.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 834
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ieui.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 835
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\mshtmlmedia.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 836
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\jsIntl.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 837
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ieetwproxystub.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 838
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\RegisterIEPKEYs.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 839
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\elshyph.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 840
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\iepeers.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 841
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ieframe.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 842
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\licmgr10.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 843
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\mshtmler.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 844
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\iexpress.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 845
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\IEAdvpack.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 846
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\wextract.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 847
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\dxtrans.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 848
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\wininet.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 849
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\SetIEInstalledDate.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 850
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\MshtmlDac.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 851
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\jscript.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 852
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 853
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\msfeedssync.exe
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 854
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\webcheck.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 855
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\icardie.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 856
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\iertutil.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 857
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\pngfilt.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 858
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\jscript9diag.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 859
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\msls31.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 860
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\iedkcs32.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 861
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\iesetup.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 862
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\iernonce.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 863
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\vbscript.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 864
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\iesysprep.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 865
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\inseng.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 866
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\jscript9.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 867
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\occache.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 868
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\inetcpl.cpl
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 869
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ieapfltr.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 870
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\html.iec
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 871
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\imgutil.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 872
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\msfeeds.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 873
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\ieuinit.inf
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 874
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\tdc.ocx
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 875
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\mshtml.tlb
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 876
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\mshtml.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 877
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\mshtmled.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 878
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\urlmon.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 879
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\msfeedsbs.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 880
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\msrating.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 881
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\dxtmsft.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 882
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\webcheck.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 883
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\iernonce.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 884
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\inseng.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 885
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\html.iec.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 886
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\msrating.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 887
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\wininet.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 888
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\ieui.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 889
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\elshyph.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 890
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\iexpress.exe.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 891
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\ieetwcollectorres.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 892
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\occache.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 893
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\ieframe.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 894
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\mshta.exe.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 895
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\mshtml.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 896
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\wextract.exe.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 897
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\iesetup.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 898
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\ieunatt.exe.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 899
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\licmgr10.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 900
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\mshtmler.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 901
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\jscript.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 902
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\vbscript.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 903
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\iepeers.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 904
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\IEAdvpack.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 905
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\msfeedsbs.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 906
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\mshtmlmedia.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 907
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\iedkcs32.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 908
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\urlmon.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 909
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\inetcpl.cpl.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 910
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\jscript9.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 911
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\en-US\icardie.dll.mui
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 912
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\wdi\perftrack\wow64_ieframe.ptxml
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 913
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\wdi\perftrack\wow64_Microsoft-Windows-IE-HTMLRendering.ptxml
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 914
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\SysWOW64\migration\WininetPlugin.dll
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 915
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.acl
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 916
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.dub
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 917
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\Globalization\ELS\SpellDictionaries\MsSp7en.lex
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 918
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\Globalization\ELS\HyphenationDictionaries\MsHy7en.lex
+ 0x000000000000001c
+
+ S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
+ 0x0000000000000cdc
+ C:\Windows\System32\poqexec.exe
+
+
+
+
+
+ 1100
+ 0
+ 4
+ 103
+ 0
+ 0x4020000000000000
+
+ 919
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 920
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001c0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 921
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4608
+ 0
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 922
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 923
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 0
+ -
+ -
+ -
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000004
+
+ -
+ -
+
+
+
+
+
+ 4902
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 924
+
+
+ Security
+ informant-PC
+
+
+
+ 0
+ 0x000000000000c957
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 925
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 926
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 927
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 928
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 929
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 930
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 931
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 932
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 933
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 934
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 935
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 936
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 937
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 938
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 5033
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 939
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 940
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-7
+ ANONYMOUS LOGON
+ NT AUTHORITY
+ 0x000000000001a427
+ 3
+ NtLmSsp
+ NTLM
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ NTLM V1
+ 0
+ 0x0000000000000000
+ -
+ -
+ -
+
+
+
+
+
+ 5024
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 941
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 942
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 943
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 944
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\Globalization\ELS\HyphenationDictionaries
+ 0x00000000000002d4
+
+ S:ARAI(AU;SAFA;0x1f0116;;;WD)
+ 0x00000000000003e8
+ C:\Windows\servicing\TrustedInstaller.exe
+
+
+
+
+
+ 4907
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 945
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ Security
+ File
+ C:\Windows\Globalization\ELS\SpellDictionaries
+ 0x00000000000002d0
+
+ S:ARAI(AU;SAFA;0x1f0116;;;WD)
+ 0x00000000000003e8
+ C:\Windows\servicing\TrustedInstaller.exe
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 946
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ {00000000-0000-0000-0000-000000000000}
+ informant
+ informant-PC
+ {00000000-0000-0000-0000-000000000000}
+ localhost
+ localhost
+ 0x00000000000001b8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 947
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000056f8b
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001b8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 948
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000056fb9
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001b8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 949
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000056f8b
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 950
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 951
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 1100
+ 0
+ 4
+ 103
+ 0
+ 0x4020000000000000
+
+ 952
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+
+
+ 4647
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 953
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000056fb9
+
+
+
+
+
+ 4608
+ 0
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 954
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 955
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 0
+ -
+ -
+ -
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000004
+
+ -
+ -
+
+
+
+
+
+ 4902
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 956
+
+
+ Security
+ informant-PC
+
+
+
+ 0
+ 0x000000000000c54c
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 957
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 958
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 959
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 960
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 961
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 962
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 963
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 964
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 965
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 966
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 967
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 968
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 5033
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 969
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 5024
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 970
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 971
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-7
+ ANONYMOUS LOGON
+ NT AUTHORITY
+ 0x000000000001c185
+ 3
+ NtLmSsp
+ NTLM
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ NTLM V1
+ 0
+ 0x0000000000000000
+ -
+ -
+ -
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 972
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ {00000000-0000-0000-0000-000000000000}
+ informant
+ informant-PC
+ {00000000-0000-0000-0000-000000000000}
+ localhost
+ localhost
+ 0x00000000000001b8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 973
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001b8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 974
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000022517
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001b8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 975
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 976
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 977
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 978
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 979
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 980
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 981
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 982
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ informant
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000022517
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+
+
+
+
+
+ 4728
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 983
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ None
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-513
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+
+
+
+
+
+ 4720
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 984
+
+
+ Security
+ informant-PC
+
+
+
+ admin11
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ admin11
+ %%1793
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1794
+ %%1794
+ 513
+ -
+ 0x0
+ 0x15
+
+ %%2080
+ %%2082
+ %%2084
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4722
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 985
+
+
+ Security
+ informant-PC
+
+
+
+ admin11
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 986
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ admin11
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ admin11
+ admin11
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1794
+ %%1794
+ 513
+ -
+ 0x15
+ 0x210
+
+ %%2048
+ %%2050
+ %%2089
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4732
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 987
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ Users
+ Builtin
+ S-1-5-32-545
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 988
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ admin11
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+
+
+
+
+
+ 4732
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 989
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ Administrators
+ Builtin
+ S-1-5-32-544
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 990
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ admin11
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ admin11
+ admin11
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1794
+ %%1794
+ 513
+ -
+ 0x210
+ 0x210
+ -
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 991
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ admin11
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ admin11
+ admin11
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ 3/22/2015 11:52:10 AM
+ %%1794
+ 513
+ -
+ 0x210
+ 0x210
+ -
+ -
+ -
+ %%1797
+
+
+
+
+
+ 4724
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 992
+
+
+ Security
+ informant-PC
+
+
+
+ admin11
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 993
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ admin11
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+
+
+
+
+
+ 4728
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 994
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ S-1-5-21-2425377081-3129163575-2985601102-1002
+ None
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-513
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+
+
+
+
+
+ 4720
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 995
+
+
+ Security
+ informant-PC
+
+
+
+ ITechTeam
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1002
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ ITechTeam
+ %%1793
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1794
+ %%1794
+ 513
+ -
+ 0x0
+ 0x15
+
+ %%2080
+ %%2082
+ %%2084
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4722
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 996
+
+
+ Security
+ informant-PC
+
+
+
+ ITechTeam
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1002
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 997
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ ITechTeam
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1002
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ ITechTeam
+ ITechTeam
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1794
+ %%1794
+ 513
+ -
+ 0x15
+ 0x210
+
+ %%2048
+ %%2050
+ %%2089
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4732
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 998
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ S-1-5-21-2425377081-3129163575-2985601102-1002
+ Users
+ Builtin
+ S-1-5-32-545
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 999
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ ITechTeam
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1002
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+
+
+
+
+
+ 4732
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 1000
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ S-1-5-21-2425377081-3129163575-2985601102-1002
+ Administrators
+ Builtin
+ S-1-5-32-544
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 1001
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ ITechTeam
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1002
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ ITechTeam
+ ITechTeam
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1794
+ %%1794
+ 513
+ -
+ 0x210
+ 0x210
+ -
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 1002
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ ITechTeam
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1002
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ ITechTeam
+ ITechTeam
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ 3/22/2015 11:52:45 AM
+ %%1794
+ 513
+ -
+ 0x210
+ 0x210
+ -
+ -
+ -
+ %%1797
+
+
+
+
+
+ 4724
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 1003
+
+
+ Security
+ informant-PC
+
+
+
+ ITechTeam
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1002
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 1004
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ ITechTeam
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1002
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+
+
+
+
+
+ 4728
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 1005
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ S-1-5-21-2425377081-3129163575-2985601102-1003
+ None
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-513
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+
+
+
+
+
+ 4720
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 1006
+
+
+ Security
+ informant-PC
+
+
+
+ temporary
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1003
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ temporary
+ %%1793
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1794
+ %%1794
+ 513
+ -
+ 0x0
+ 0x15
+
+ %%2080
+ %%2082
+ %%2084
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4722
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 1007
+
+
+ Security
+ informant-PC
+
+
+
+ temporary
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1003
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 1008
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ temporary
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1003
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ temporary
+ temporary
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1794
+ %%1794
+ 513
+ -
+ 0x15
+ 0x210
+
+ %%2048
+ %%2050
+ %%2089
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4732
+ 0
+ 0
+ 13826
+ 0
+ 0x8020000000000000
+
+ 1009
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ S-1-5-21-2425377081-3129163575-2985601102-1003
+ Users
+ Builtin
+ S-1-5-32-545
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 1010
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ temporary
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1003
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 1011
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ temporary
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1003
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ temporary
+ temporary
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1794
+ %%1794
+ 513
+ -
+ 0x210
+ 0x210
+ -
+ %%1793
+ -
+ %%1797
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 1012
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ temporary
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1003
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ temporary
+ temporary
+ -
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ %%1793
+ 3/22/2015 11:53:11 AM
+ %%1794
+ 513
+ -
+ 0x210
+ 0x210
+ -
+ -
+ -
+ %%1797
+
+
+
+
+
+ 4724
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 1013
+
+
+ Security
+ informant-PC
+
+
+
+ temporary
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1003
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+
+
+
+
+
+ 4738
+ 0
+ 0
+ 13824
+ 0
+ 0x8020000000000000
+
+ 1014
+
+
+ Security
+ informant-PC
+
+
+
+ -
+ temporary
+ informant-PC
+ S-1-5-21-2425377081-3129163575-2985601102-1003
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000224e3
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+ -
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1015
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ {00000000-0000-0000-0000-000000000000}
+ admin11
+ informant-PC
+ {00000000-0000-0000-0000-000000000000}
+ localhost
+ localhost
+ 0x00000000000007a0
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1016
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ admin11
+ informant-PC
+ 0x0000000000094b57
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000007a0
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1017
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ admin11
+ informant-PC
+ 0x0000000000094b71
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000007a0
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1018
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ admin11
+ informant-PC
+ 0x0000000000094b57
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4647
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1019
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ admin11
+ informant-PC
+ 0x0000000000094b71
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1020
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ {00000000-0000-0000-0000-000000000000}
+ temporary
+ informant-PC
+ {00000000-0000-0000-0000-000000000000}
+ localhost
+ localhost
+ 0x000000000000072c
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1021
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1003
+ temporary
+ informant-PC
+ 0x00000000000f2cd6
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x000000000000072c
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4634
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1022
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ admin11
+ informant-PC
+ 0x0000000000094b71
+ 2
+
+
+
+
+
+ 4634
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1023
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ admin11
+ informant-PC
+ 0x0000000000094b57
+ 2
+
+
+
+
+
+ 4647
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1024
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1003
+ temporary
+ informant-PC
+ 0x00000000000f2cd6
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1025
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ {00000000-0000-0000-0000-000000000000}
+ admin11
+ informant-PC
+ {00000000-0000-0000-0000-000000000000}
+ localhost
+ localhost
+ 0x0000000000000954
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1026
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ admin11
+ informant-PC
+ 0x00000000001354b3
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000954
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1027
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ admin11
+ informant-PC
+ 0x00000000001354c8
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000954
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1028
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ admin11
+ informant-PC
+ 0x00000000001354b3
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4647
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1029
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ admin11
+ informant-PC
+ 0x00000000001354c8
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1030
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ {00000000-0000-0000-0000-000000000000}
+ informant
+ informant-PC
+ {00000000-0000-0000-0000-000000000000}
+ localhost
+ localhost
+ 0x0000000000000c1c
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1031
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000157b62
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000c1c
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1032
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000157b78
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000c1c
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1033
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000157b62
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4634
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1034
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000157b78
+ 2
+
+
+
+
+
+ 4634
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1035
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000157b62
+ 2
+
+
+
+
+
+ 4634
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1036
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1003
+ temporary
+ informant-PC
+ 0x00000000000f2cd6
+ 2
+
+
+
+
+
+ 4634
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1037
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ admin11
+ informant-PC
+ 0x00000000001354c8
+ 2
+
+
+
+
+
+ 4634
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1038
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1001
+ admin11
+ informant-PC
+ 0x00000000001354b3
+ 2
+
+
+
+
+
+ 1100
+ 0
+ 4
+ 103
+ 0
+ 0x4020000000000000
+
+ 1039
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+
+
+ 4647
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1040
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000022517
+
+
+
+
+
+ 4608
+ 0
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 1041
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1042
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 0
+ -
+ -
+ -
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000004
+
+ -
+ -
+
+
+
+
+
+ 4902
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 1043
+
+
+ Security
+ informant-PC
+
+
+
+ 0
+ 0x000000000000bac4
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1044
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1045
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1046
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1047
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1048
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1049
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1050
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1051
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1052
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1053
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1054
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1055
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 5033
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 1056
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 5024
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 1057
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1058
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-7
+ ANONYMOUS LOGON
+ NT AUTHORITY
+ 0x000000000001b9a4
+ 3
+ NtLmSsp
+ NTLM
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ NTLM V1
+ 0
+ 0x0000000000000000
+ -
+ -
+ -
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1059
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ {00000000-0000-0000-0000-000000000000}
+ informant
+ informant-PC
+ {00000000-0000-0000-0000-000000000000}
+ localhost
+ localhost
+ 0x00000000000001a8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1060
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x000000000002359c
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001a8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1061
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000235cc
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001a8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1062
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x000000000002359c
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1063
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1064
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4616
+ 1
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 1065
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 2015-03-23 17:25:47.192598
+ 2015-03-23 17:25:47.191999
+ 0x0000000000000358
+ C:\Windows\System32\svchost.exe
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1066
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1067
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1068
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1069
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4616
+ 1
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 1070
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 2015-03-23 18:57:01.113134
+ 2015-03-23 19:08:15.571480
+ 0x0000000000000358
+ C:\Windows\System32\svchost.exe
+
+
+
+
+
+ 4616
+ 1
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 1071
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 2015-03-23 19:08:15.571480
+ 2015-03-23 19:08:15.570999
+ 0x0000000000000358
+ C:\Windows\System32\svchost.exe
+
+
+
+
+
+ 4616
+ 1
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 1072
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 2015-03-23 19:08:46.443419
+ 2015-03-23 19:08:46.442999
+ 0x0000000000000358
+ C:\Windows\System32\svchost.exe
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1073
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1074
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1075
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1076
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1077
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1078
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1079
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e4
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1080
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4904
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 1081
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ VSSAudit
+ 0x00000000002c2083
+ 0x0000000000000d40
+ C:\Windows\System32\VSSVC.exe
+
+
+
+
+
+ 4905
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 1082
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ VSSAudit
+ 0x00000000002c2083
+ 0x0000000000000d40
+ C:\Windows\System32\VSSVC.exe
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1083
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000235cc
+ {00000000-0000-0000-0000-000000000000}
+ Company
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ Company-PC
+ Company-PC
+ 0x0000000000000004
+
+ -
+ -
+
+
+
+
+
+ 4647
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1084
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000235cc
+
+
+
+
+
+ 1100
+ 0
+ 4
+ 103
+ 0
+ 0x4020000000000000
+
+ 1085
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+
+
+ 4608
+ 0
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 1086
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1087
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 0
+ -
+ -
+ -
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000004
+
+ -
+ -
+
+
+
+
+
+ 4902
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 1088
+
+
+ Security
+ informant-PC
+
+
+
+ 0
+ 0x000000000000b683
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1089
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e8
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1090
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1091
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e8
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1092
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1093
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e8
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1094
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1095
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e8
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1096
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1097
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e8
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1098
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1099
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e8
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1100
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 5033
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 1101
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 5024
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 1102
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1103
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-7
+ ANONYMOUS LOGON
+ NT AUTHORITY
+ 0x000000000001c0ce
+ 3
+ NtLmSsp
+ NTLM
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ NTLM V1
+ 0
+ 0x0000000000000000
+ -
+ -
+ -
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1104
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ {00000000-0000-0000-0000-000000000000}
+ informant
+ informant-PC
+ {00000000-0000-0000-0000-000000000000}
+ localhost
+ localhost
+ 0x00000000000001b8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1105
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x000000000002269c
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001b8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1106
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000226c4
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001b8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1107
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x000000000002269c
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1108
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e8
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1109
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1110
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e8
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1111
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1112
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000226c4
+ {00000000-0000-0000-0000-000000000000}
+ Company
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ Company-PC
+ Company-PC
+ 0x0000000000000004
+
+ -
+ -
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1113
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e8
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1114
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1115
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e8
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1116
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1117
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e8
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1118
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1119
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e8
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1120
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1121
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e8
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1122
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1123
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ {00000000-0000-0000-0000-000000000000}
+ informant
+ informant-PC
+ {00000000-0000-0000-0000-000000000000}
+ localhost
+ localhost
+ 0x00000000000001b8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1124
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000006cabcf
+ 7
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001b8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1125
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000006cabdd
+ 7
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001b8
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1126
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000006cabcf
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4634
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1127
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000006cabdd
+ 7
+
+
+
+
+
+ 4634
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1128
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000006cabcf
+ 7
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1129
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001e8
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1130
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4647
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1131
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x00000000000226c4
+
+
+
+
+
+ 1100
+ 0
+ 4
+ 103
+ 0
+ 0x4020000000000000
+
+ 1132
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+
+
+ 4608
+ 0
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 1133
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1134
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 0
+ -
+ -
+ -
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000004
+
+ -
+ -
+
+
+
+
+
+ 4902
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 1135
+
+
+ Security
+ informant-PC
+
+
+
+ 0
+ 0x000000000000ba7d
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1136
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1137
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1138
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1139
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-20
+ NETWORK SERVICE
+ NT AUTHORITY
+ 0x00000000000003e4
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1140
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1141
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ SeAssignPrimaryTokenPrivilege
+ SeAuditPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1142
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1143
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1144
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1145
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1146
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1147
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 5033
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 1148
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 5024
+ 0
+ 0
+ 12292
+ 0
+ 0x8020000000000000
+
+ 1149
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1150
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-0-0
+ -
+ -
+ 0x0000000000000000
+ S-1-5-7
+ ANONYMOUS LOGON
+ NT AUTHORITY
+ 0x000000000001c0d1
+ 3
+ NtLmSsp
+ NTLM
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ NTLM V1
+ 0
+ 0x0000000000000000
+ -
+ -
+ -
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1151
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ {00000000-0000-0000-0000-000000000000}
+ informant
+ informant-PC
+ {00000000-0000-0000-0000-000000000000}
+ localhost
+ localhost
+ 0x0000000000000194
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1152
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000025465
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000194
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1153
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000025493
+ 2
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000194
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1154
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000025465
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1155
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1156
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1157
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1158
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1159
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1160
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4616
+ 1
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 1161
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 2015-03-25 13:29:46.566790
+ 2015-03-25 14:13:47.009901
+ 0x0000000000000330
+ C:\Windows\System32\svchost.exe
+
+
+
+
+
+ 4616
+ 1
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 1162
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 2015-03-25 14:13:47.025499
+ 2015-03-25 14:13:47.025000
+ 0x0000000000000330
+ C:\Windows\System32\svchost.exe
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1163
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1164
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4648
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1165
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ {00000000-0000-0000-0000-000000000000}
+ informant
+ informant-PC
+ {00000000-0000-0000-0000-000000000000}
+ localhost
+ localhost
+ 0x0000000000000194
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1166
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000157773
+ 7
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000194
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1167
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x000000000015777f
+ 7
+ User32
+ Negotiate
+ INFORMANT-PC
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x0000000000000194
+ C:\Windows\System32\winlogon.exe
+ 127.0.0.1
+ 0
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1168
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000157773
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4634
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1169
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x000000000015777f
+ 7
+
+
+
+
+
+ 4634
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1170
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000157773
+ 7
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1171
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1172
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1173
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1174
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1175
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1176
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4904
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 1177
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ VSSAudit
+ 0x00000000001aa8e7
+ 0x0000000000000934
+ C:\Windows\System32\VSSVC.exe
+
+
+
+
+
+ 4905
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 1178
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ VSSAudit
+ 0x00000000001aa8e7
+ 0x0000000000000934
+ C:\Windows\System32\VSSVC.exe
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1179
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1180
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1181
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1182
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1183
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1184
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1185
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1186
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4904
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 1187
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ VSSAudit
+ 0x0000000000245dcb
+ 0x0000000000000aa4
+ C:\Windows\System32\VSSVC.exe
+
+
+
+
+
+ 4905
+ 0
+ 0
+ 13568
+ 0
+ 0x8020000000000000
+
+ 1188
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ VSSAudit
+ 0x0000000000245dcb
+ 0x0000000000000aa4
+ C:\Windows\System32\VSSVC.exe
+
+
+
+
+
+ 4624
+ 0
+ 0
+ 12544
+ 0
+ 0x8020000000000000
+
+ 1189
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ INFORMANT-PC$
+ WORKGROUP
+ 0x00000000000003e7
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ 5
+ Advapi
+ Negotiate
+
+ {00000000-0000-0000-0000-000000000000}
+ -
+ -
+ 0
+ 0x00000000000001d0
+ C:\Windows\System32\services.exe
+ -
+ -
+
+
+
+
+
+ 4672
+ 0
+ 0
+ 12548
+ 0
+ 0x8020000000000000
+
+ 1190
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-18
+ SYSTEM
+ NT AUTHORITY
+ 0x00000000000003e7
+ SeAssignPrimaryTokenPrivilege
+ SeTcbPrivilege
+ SeSecurityPrivilege
+ SeTakeOwnershipPrivilege
+ SeLoadDriverPrivilege
+ SeBackupPrivilege
+ SeRestorePrivilege
+ SeDebugPrivilege
+ SeAuditPrivilege
+ SeSystemEnvironmentPrivilege
+ SeImpersonatePrivilege
+
+
+
+
+
+ 4647
+ 0
+ 0
+ 12545
+ 0
+ 0x8020000000000000
+
+ 1191
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-21-2425377081-3129163575-2985601102-1000
+ informant
+ informant-PC
+ 0x0000000000025493
+
+
+
+
+
+ 4616
+ 1
+ 0
+ 12288
+ 0
+ 0x8020000000000000
+
+ 1192
+
+
+ Security
+ informant-PC
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x00000000000003e5
+ 2015-03-25 15:31:00.240004
+ 2015-03-25 15:31:00.240000
+ 0x0000000000000330
+ C:\Windows\System32\svchost.exe
+
+
+
+
+
+ 1100
+ 0
+ 4
+ 103
+ 0
+ 0x4020000000000000
+
+ 1193
+
+
+ Security
+ informant-PC
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_findall_eventid_time.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_findall_eventid_time.py
new file mode 100644
index 0000000..f178e39
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_findall_eventid_time.py
@@ -0,0 +1,22 @@
+import xml.etree.ElementTree as ET
+import xml.dom.minidom as minidom
+
+tree = ET.parse("SecurityEvt_ns_removed.xml")
+root = tree.getroot()
+
+# Iterate through all System elements
+for system_element in root.findall(".//System"):
+ event_id_element = system_element.find("EventID")
+ time_created_element = system_element.find("TimeCreated")
+
+ # Check if EventID and TimeCreated elements exist
+ if (
+ event_id_element is not None
+ and event_id_element.text == "4608"
+ and time_created_element is not None
+ ):
+ event_id = event_id_element.text
+ system_time = time_created_element.get("SystemTime")
+
+ # Print the lists of EventID and TimeCreated values
+ print("EventIDs: {} and SystemTimes: {}".format(event_id, system_time))
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_format.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_format.py
new file mode 100644
index 0000000..1e80eca
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_format.py
@@ -0,0 +1,26 @@
+import xml.etree.ElementTree as ET
+import xml.dom.minidom as minidom
+
+tree = ET.parse("SecurityEvt_ns_removed.xml")
+root = tree.getroot()
+
+# Convert the entire XML to a string with pretty formatting
+formatted_xml_str = ET.tostring(root, encoding="utf-8", method="xml").decode("utf-8")
+
+# Parse the formatted XML content
+dom = minidom.parseString(formatted_xml_str)
+
+# Pretty print the XML content
+pretty_xml = dom.toprettyxml(indent=" ")
+
+# Remove extra blank lines
+non_empty_pretty_lines = [line for line in pretty_xml.splitlines() if line.strip()]
+
+# Join the lines to get the final XML content
+formatted_xml = "\n".join(non_empty_pretty_lines)
+
+# Save the nicely formatted XML to a new file
+with open("securityEvt_formatted.xml", "w") as file:
+ file.write(formatted_xml)
+
+print("Formatted XML saved to 'securityEvt_formatted.xml'.")
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_list_tags.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_list_tags.py
new file mode 100644
index 0000000..bed55e8
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_list_tags.py
@@ -0,0 +1,16 @@
+import xml.etree.ElementTree as ET
+
+tree = ET.parse("SecurityEvt.xml")
+root = tree.getroot()
+
+# Create an empty set to store unique tag names
+tag_names = set()
+
+# Iterate through the elements and collect unique tag names
+for element in root.iter():
+ tag_names.add(element.tag)
+
+# Convert the set to a sorted list and print the tag names
+tag_list = sorted(tag_names)
+for tag in tag_list:
+ print(tag)
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_ns_remove.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_ns_remove.py
new file mode 100644
index 0000000..87de7db
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_ns_remove.py
@@ -0,0 +1,23 @@
+import xml.etree.ElementTree as ET
+
+tree = ET.parse("SecurityEvt.xml")
+root = tree.getroot()
+
+
+# Define a function to recursively remove all namespace prefixes
+def remove_namespace_prefix(element):
+ # print(element.tag)
+ element.tag = element.tag.split("}", 1)[-1] # Remove namespace prefix
+ for child in element:
+ remove_namespace_prefix(child)
+
+
+# Remove namespace prefixes from the root element and its descendants
+remove_namespace_prefix(root)
+
+# Convert the modified XML tree to a string
+modified_xml = ET.tostring(root, encoding="utf-8")
+
+# Save the updated XML to a new file
+with open("SecurityEvt_ns_removed.xml", "wb") as f:
+ f.write(modified_xml)
diff --git a/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_show_first_event.py b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_show_first_event.py
new file mode 100644
index 0000000..9dc05c0
--- /dev/null
+++ b/NIST_Data_Leakage_Case/py_version/pycode/security_evt_xml/securityevt_show_first_event.py
@@ -0,0 +1,24 @@
+import xml.etree.ElementTree as ET
+import xml.dom.minidom as minidom
+
+tree = ET.parse("SecurityEvt_ns_removed.xml")
+root = tree.getroot()
+
+# Find the first Event element
+first_event = root.find(".//Event")
+
+# Check if a Event element was found
+if first_event is not None:
+ # Convert the first Event element to a string with pretty formatting
+ first_event_str = ET.tostring(first_event, encoding="unicode", method="xml")
+
+ # Parse the XML content
+ dom = minidom.parseString(first_event_str)
+
+ # Pretty print the XML content
+ pretty_xml = dom.toprettyxml(indent=" ")
+
+ # Print the nicely formatted XML
+ print(pretty_xml)
+else:
+ print("No Event elements found in the XML.")