General Info

URL

https://www.r-tt.com/downloads/RUndelete6.exe

Full analysis
https://app.any.run/tasks/5585403d-39f7-43d5-9413-725b64bf3b57
Verdict
Malicious activity
Analysis date
12/6/2018, 14:26:26
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • iexplore.exe (PID: 3484)
  • RUndelete32.exe (PID: 2324)
  • RUndelete6[1].exe (PID: 2904)
Application was dropped or rewritten from another process
  • RUndelete6[1].exe (PID: 2904)
  • RUndelete6[1].exe (PID: 3708)
  • RUndelete32.exe (PID: 2324)
  • R-Undelete.exe (PID: 1384)
Creates files in the user directory
  • RUndelete6[1].exe (PID: 2904)
Creates a software uninstall entry
  • RUndelete6[1].exe (PID: 2904)
Low-level read access rights to disk partition
  • RUndelete32.exe (PID: 2324)
Executable content was dropped or overwritten
  • RUndelete6[1].exe (PID: 2904)
Creates files in the program directory
  • RUndelete6[1].exe (PID: 2904)
Dropped object may contain Bitcoin addresses
  • RUndelete6[1].exe (PID: 2904)
Application launched itself
  • iexplore.exe (PID: 2864)
Creates files in the user directory
  • iexplore.exe (PID: 3484)
Reads Internet Cache Settings
  • iexplore.exe (PID: 2864)
  • iexplore.exe (PID: 3484)
Changes internet zones settings
  • iexplore.exe (PID: 2864)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
40
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

+
start drop and start iexplore.exe iexplore.exe rundelete6[1].exe no specs rundelete6[1].exe r-undelete.exe no specs rundelete32.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2864
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" https://www.r-tt.com/downloads/RUndelete6.exe
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\version.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mlang.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\userenv.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\r9zewh8d\rundelete6[1].exe
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll

PID
3484
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2864 CREDAT:71937
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll

PID
3708
CMD
"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\RUndelete6[1].exe"
Path
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\RUndelete6[1].exe
Indicators
No indicators
Parent process
iexplore.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
R-Tools Technology Inc.
Description
R-Undelete 6.5
Version
6.5.170.927.927
Modules
Image
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\r9zewh8d\rundelete6[1].exe
c:\systemroot\system32\ntdll.dll

PID
2904
CMD
"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\RUndelete6[1].exe"
Path
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\RUndelete6[1].exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
R-Tools Technology Inc.
Description
R-Undelete 6.5
Version
6.5.170.927.927
Modules
Image
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\r9zewh8d\rundelete6[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\uxtheme.dll
c:\users\admin\appdata\local\temp\nsed3b3.tmp\langdll.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nsed3b3.tmp\installoptions.dll
c:\windows\system32\comdlg32.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\users\admin\appdata\local\temp\nsed3b3.tmp\startmenu.dll
c:\windows\system32\profapi.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\r-undelete\r-undelete.exe
c:\program files\r-undelete\uninstall.exe
c:\windows\system32\dui70.dll
c:\windows\system32\duser.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll
c:\program files\r-undelete\helpview.exe
c:\windows\system32\apphelp.dll
c:\windows\system32\netutils.dll

PID
1384
CMD
"C:\Program Files\R-Undelete\R-Undelete.exe"
Path
C:\Program Files\R-Undelete\R-Undelete.exe
Indicators
No indicators
Parent process
RUndelete6[1].exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Copyright (c) 2001-2017 R-Tools Technology Inc.
Description
RUndelete
Version
6,5,170,927
Modules
Image
c:\program files\r-undelete\r-undelete.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\program files\r-undelete\x86\rundelete32.exe

PID
2324
CMD
"C:\Program Files\R-Undelete\x86\RUndelete32.exe"
Path
C:\Program Files\R-Undelete\x86\RUndelete32.exe
Indicators
Parent process
R-Undelete.exe
User
admin
Integrity Level
HIGH
Version:
Company
Copyright (c) 2001-2017 R-Tools Technology Inc.
Description
RUndelete
Version
6,5,170,927
Modules
Image
c:\program files\r-undelete\x86\rundelete32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\r-undelete\x86\qt5widgets.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\program files\r-undelete\x86\qt5gui.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\program files\r-undelete\x86\qt5core.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\mpr.dll
c:\program files\r-undelete\x86\msvcp140.dll
c:\program files\r-undelete\x86\vcruntime140.dll
c:\program files\r-undelete\x86\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\r-undelete\x86\ucrtbase.dll
c:\program files\r-undelete\x86\api-ms-win-core-timezone-l1-1-0.dll
c:\program files\r-undelete\x86\api-ms-win-core-file-l2-1-0.dll
c:\program files\r-undelete\x86\api-ms-win-core-localization-l1-2-0.dll
c:\program files\r-undelete\x86\api-ms-win-core-synch-l1-2-0.dll
c:\program files\r-undelete\x86\api-ms-win-core-processthreads-l1-1-1.dll
c:\program files\r-undelete\x86\api-ms-win-core-file-l1-2-0.dll
c:\program files\r-undelete\x86\api-ms-win-crt-string-l1-1-0.dll
c:\program files\r-undelete\x86\api-ms-win-crt-heap-l1-1-0.dll
c:\program files\r-undelete\x86\api-ms-win-crt-stdio-l1-1-0.dll
c:\program files\r-undelete\x86\api-ms-win-crt-convert-l1-1-0.dll
c:\program files\r-undelete\x86\api-ms-win-crt-locale-l1-1-0.dll
c:\program files\r-undelete\x86\api-ms-win-crt-math-l1-1-0.dll
c:\program files\r-undelete\x86\api-ms-win-crt-multibyte-l1-1-0.dll
c:\program files\r-undelete\x86\api-ms-win-crt-time-l1-1-0.dll
c:\program files\r-undelete\x86\api-ms-win-crt-filesystem-l1-1-0.dll
c:\program files\r-undelete\x86\api-ms-win-crt-environment-l1-1-0.dll
c:\program files\r-undelete\x86\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\r-undelete\x86\qt5winextras.dll
c:\program files\r-undelete\x86\qt5quick.dll
c:\program files\r-undelete\x86\qt5qml.dll
c:\program files\r-undelete\x86\qt5network.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\profapi.dll
c:\program files\r-undelete\x86\platforms\qwindows.dll
c:\windows\system32\winmm.dll
c:\windows\system32\uxtheme.dll
c:\program files\r-undelete\x86\imageformats\qico.dll
c:\windows\system32\psapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\program files\r-undelete\x86\imageformats\qdds.dll
c:\program files\r-undelete\x86\imageformats\qgif.dll
c:\program files\r-undelete\x86\imageformats\qicns.dll
c:\program files\r-undelete\x86\imageformats\qjpeg.dll
c:\program files\r-undelete\x86\imageformats\qsvg.dll
c:\program files\r-undelete\x86\qt5svg.dll
c:\program files\r-undelete\x86\imageformats\qtga.dll
c:\program files\r-undelete\x86\imageformats\qtiff.dll
c:\program files\r-undelete\x86\imageformats\qwbmp.dll
c:\program files\r-undelete\x86\imageformats\qwebp.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\program files\r-undelete\x86\qtquick.2\qtquick2plugin.dll
c:\program files\r-undelete\x86\qtquick\window.2\windowplugin.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\version.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\vga.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\program files\r-undelete\x86\libegl.dll
c:\program files\r-undelete\x86\libglesv2.dll
c:\program files\r-undelete\x86\d3dcompiler_47.dll
c:\program files\r-undelete\x86\opengl32sw.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\wintrust.dll
c:\program files\r-undelete\x86\qtquick\controls\qtquickcontrolsplugin.dll
c:\program files\r-undelete\x86\qtquick\layouts\qquicklayoutsplugin.dll
c:\program files\r-undelete\x86\qtquick\dialogs\dialogplugin.dll
c:\program files\r-undelete\x86\qt\labs\controls\qtlabscontrolsplugin.dll
c:\program files\r-undelete\x86\qt5labstemplates.dll
c:\program files\r-undelete\x86\qt\labs\templates\qtlabstemplatesplugin.dll
c:\program files\r-undelete\x86\qtgraphicaleffects\private\qtgraphicaleffectsprivate.dll

Registry activity

Total events
923
Read events
826
Write events
94
Delete events
3

Modification events

PID
Process
Operation
Key
Name
Value
2864
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018082720180903
2864
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018090920180910
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{98044673-F95A-11E8-BAD8-5254004A04AF}
0
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
3
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E2070C00040006000D001A0036001201
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
3
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E2070C00040006000D001A0036001201
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
3
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E2070C00040006000D001A003600ED01
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
13
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
3
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E2070C00040006000D001A0036001C02
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
36
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
3
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E2070C00040006000D001A0036006A02
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
51
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CACHE
LastScavenge
1
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CACHE
LastScavenge_TIMESTAMP
40D42C62678DD401
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E2070C00040006000D001B000700A50000000000
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
NotifyDownloadComplete
yes
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012018120620181207
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CachePrefix
:2018120620181207:
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CacheLimit
8192
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CacheOptions
11
2864
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CacheRepair
0
3484
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018082820180829
3484
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018120620181207
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012018120620181207
3484
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018120620181207
CachePrefix
:2018120620181207:
3484
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018120620181207
CacheLimit
8192
3484
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018120620181207
CacheOptions
11
3484
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018120620181207
CacheRepair
0
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\R-TT\R-Undelete\00000010
InstallPath
C:\Program Files\R-Undelete
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\R-TT\R-Undelete\00000010
InstalledVer
6.5
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\R-TT\R-Undelete\00000010
InstalledBuild
170927
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\R-TT\R-Undelete\00000010
LanguageCode
en
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\R-TT\R-Undelete\00000010
ProductName
R-Undelete
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\R-TT\R-Undelete\00000010
InstalledX64
1
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\R-TT\R-Undelete\00000010
SitePlatform
win32
2904
RUndelete6[1].exe
write
HKEY_CURRENT_USER\Software\R-TT\R-Undelete\00000010
SitePlatform
win32
2904
RUndelete6[1].exe
write
HKEY_CURRENT_USER\Software\R-TT\R-Undelete\00000010
L2
3295082210
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\R-TT\R-Undelete\00000010\GUI
Language
1033
2904
RUndelete6[1].exe
write
HKEY_CURRENT_USER\Software\R-TT\R-Undelete\00000010\GUI
Language
1033
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\R-TT\R-Undelete\00000010
lang_ids
en,de,fr,es,pt,ru,zh_HK,zh_CN,ja
2904
RUndelete6[1].exe
write
HKEY_CURRENT_USER\Software\R-TT\R-Undelete\00000010
lang_ids
en,de,fr,es,pt,ru,zh_HK,zh_CN,ja
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\R-TT\R-Undelete\00000010
selected_lang_id
en
2904
RUndelete6[1].exe
write
HKEY_CURRENT_USER\Software\R-TT\R-Undelete\00000010
selected_lang_id
en
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shell\RUndelete3Find
Find recently deleted files with R-Undelete
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shell\RUndelete3Find\command
"C:\Program Files\R-Undelete\R-Undelete.exe" "%1" -q
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shell\RUndelete3Scan
Perform exhaustive search (disc scan) on the disk with R-Undelete
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shell\RUndelete3Scan\command
"C:\Program Files\R-Undelete\R-Undelete.exe" "%1" -s
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shell\RUndelete3Find
Find recently deleted files with R-Undelete
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shell\RUndelete3Find\command
"C:\Program Files\R-Undelete\R-Undelete.exe" "%1" -q
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shell\RUndelete3Scan
Perform exhaustive search (disc scan) on the disk with R-Undelete
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shell\RUndelete3Scan\command
"C:\Program Files\R-Undelete\R-Undelete.exe" "%1" -s
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Undelete 6.5NSIS
DisplayName
R-Undelete 6.5
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Undelete 6.5NSIS
UninstallString
C:\Program Files\R-Undelete\Uninstall.exe
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Undelete 6.5NSIS
DisplayIcon
C:\Program Files\R-Undelete\R-Undelete.exe
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Undelete 6.5NSIS
NoModify
1
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Undelete 6.5NSIS
NoRepair
1
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Undelete 6.5NSIS
Publisher
R-Tools Technology Inc.
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Undelete 6.5NSIS
URLInfoAbout
http://www.r-undelete.com
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Undelete 6.5NSIS
DisplayVersion
6.5.170927
2904
RUndelete6[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\R-TT\R-Undelete\00000010
StartMenuFolder
R-Undelete
2904
RUndelete6[1].exe
write
HKEY_CURRENT_USER\Software\R-TT\R-Undelete\00000010
InstallerLanguage
1033
2324
RUndelete32.exe
write
HKEY_CURRENT_USER\Software\R-TT\R-Undelete\00000010
RunGuard
AF9B0200
2324
RUndelete32.exe
write
HKEY_CURRENT_USER\Software\R-TT\R-Undelete\00000010
lang_ids
en,de,fr,es,pt,ru,zh_HK,zh_CN,ja
2324
RUndelete32.exe
write
HKEY_CURRENT_USER\Software\R-TT\R-Undelete\00000010
selected_lang_id
en_US
2324
RUndelete32.exe
write
HKEY_CURRENT_USER\Software\R-TT
Language
1033
2324
RUndelete32.exe
write
HKEY_CURRENT_USER\Software\R-TT\R-Undelete\00000010
ProductName
R-Undelete Home
2324
RUndelete32.exe
write
HKEY_CURRENT_USER\Software\R-TT\R-Undelete\00000010
ProductName64
R-Undelete Home
2324
RUndelete32.exe
write
HKEY_CURRENT_USER\Software\R-TT\R-Undelete\00000010
RunGuard
AF9B0280
2324
RUndelete32.exe
write
HKEY_CURRENT_USER\Software\R-TT\R-Undelete\00000010
RunGuardStarts
01000000
2324
RUndelete32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
RUndelete32.exe

Files activity

Executable files
163
Suspicious files
3
Text files
94
Unknown types
27

Dropped files

PID
Process
Filename
Type
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-file-l1-2-0.dll
executable
MD5: 9d8413744097196f92327f632a85acee
SHA256: 6878d8168d5cc159efe58f14e5ba10310d99b53ab8495521e54c966994dac50b
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\QtAV1.dll
executable
MD5: 9d70b143da5db12d03c7acc92a156db2
SHA256: d8b6d171b5ce0e195933107ab655b177e821756d285a60a900a17d5fd872d889
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-util-l1-1-0.dll
executable
MD5: 1d9c2a07188ccfaf5e0f550abd56386a
SHA256: a6f1d195bbb68a168a07f95c273e89fe5a5eb02bac3ac76dbeb46ccd7b85ed72
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\_converter.dll
executable
MD5: 64598b044195050273da1f94dab42618
SHA256: eee270c18b8cb809bc07520a6e3afc75f316f26cd8282c75c4606829a0237630
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-timezone-l1-1-0.dll
executable
MD5: 4dab6a8fe6c24b68fb16a3a6b58c1faf
SHA256: cfcd287ced91a432b1b0f5f30eb4f9bf6409420b3994fb51c87b0b4ca21535b0
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-environment-l1-1-0.dll
executable
MD5: e5e1a3ef0c1cf856dca6f71c239bfcde
SHA256: 3c56a518dac09ff5dc34d99a97129051ddc93a1c907cca8274e8d08aa9f77e3c
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-convert-l1-1-0.dll
executable
MD5: c08072b6f3943d9695fff0be053b7296
SHA256: c580b0002cfcfaac2449085b26df4dc13fd92aac7edb580a9133f252534abbe7
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\swscale-4.dll
executable
MD5: fbe9635e47f7f600f2982c280e56048f
SHA256: 9f563f46628180c57be1a604f6826623f20037972d797bcd1fd2ec76bd0c4743
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-synch-l1-2-0.dll
executable
MD5: e38bd734e85d06860085772a7ceac43e
SHA256: e295a8633b5eaad0ab47707059bc5dc5da02dbea01b2d3c4bc8a19e466abddf4
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\_docx.dll
executable
MD5: 1fc812323b59bbd35e6e31d7d222c2ea
SHA256: b69054537e93dd7bdff5ad5b68f4322c7465d05e070991075bb866512d28c9a0
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-conio-l1-1-0.dll
executable
MD5: be3a982da0d0fd0b06d08ba4bb75e608
SHA256: 4ab9e0da1f2c4994b2f9c9debd4f543c3ab2404d13666816d7c4c74aa1ab2e2b
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\avutil-55.dll
executable
MD5: 840844c16af9924edd79e3dec9e9f76f
SHA256: ad1871a092768746f6205c130fbd8dc5450f889a0b525f04855bca7cdf5e23ab
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\_freeimage.dll
executable
MD5: 0c1dbaa35a4012d6f5841ee745ec7b9e
SHA256: ff45801c43d0b710470cb0134518fcec4d111a901ad4e38d80807766a3ef1f2f
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-heap-l1-1-0.dll
executable
MD5: b811b6df1b996ecb5bc65ccb5275e3ce
SHA256: 67a11355b9edc7cf9dd2e1e73ffbe00e00156926af8c93bcc1e254702b9ffa24
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-sysinfo-l1-1-0.dll
executable
MD5: f69d3b75d2becfc53a29ce3decf62fe7
SHA256: 460fa4cb795fab56d0949518d1c1d76d48dd55b3f9a02b3db421e79f98a64619
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\QtAVWidgets1.dll
executable
MD5: 4bb572569d1080bcdbf6142564abe75a
SHA256: 6b12c4f796ba95f2946a8498d8db37d2ef1523ad30437e8b4522e0f0ef8ecbf0
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\_gsf.dll
executable
MD5: fd9d7b806a876d67ba9945f76415ca59
SHA256: 9cff7983d3b8efa3ad87b0b4acefd927956eeeb828f1801bf87d9a82486b8adc
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-filesystem-l1-1-0.dll
executable
MD5: 4265854cf7082a0effaca9913ba1b584
SHA256: e861fbd1dd21bd09bede9ef4ced4fe32c1dd5e72f9d788cd41b7314290a638c5
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-profile-l1-1-0.dll
executable
MD5: d6f950aede59a00c9ae0affe0b63b6a4
SHA256: 8bfe8d485bf8e6bf91833f6cf61e5f054f6edbf5dfb2095967ab3db0759d59a6
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\avcodec-57.dll
executable
MD5: 956482fb13bf0a96fc5e20efaeaccae7
SHA256: 974e64cfeaa3f7eb0545e048a117e9201bb3d3573c83edf7b62b3d32ec7a06ca
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\_glib.dll
executable
MD5: ec8209a46e81b9804f4f95b37c840390
SHA256: ed434c52f1446bd51aeea968aabd3336309dceea61cee9b5925894699142bc64
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-locale-l1-1-0.dll
executable
MD5: 776384baba12ee60dd9caa8fc65ac017
SHA256: 54ad6fb80f28a8cd4424424f413c8f22a1cd6a617eb759aba2f7c2e90cbdc4f8
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-synch-l1-1-0.dll
executable
MD5: 230070639ef8c8833d67782526d9e8fc
SHA256: 139736ebca31050f4ed7339a6979595755df0acce0cf97097cdfc937de8d32e1
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\avformat-57.dll
executable
MD5: c7f278cb31020e1a17f078c93ef2d03b
SHA256: cd6cf9a42269940d0a74d2fc88fab382a956d6b1e4979579c4c94d77710644a7
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\_myio.dll
executable
MD5: 2b2e31fc14bb0b27c52c31f8c2f7b3a3
SHA256: 6b796e6aec60a706e80407b240378aaa2becd3bcab48cafbc9ba4c7e18911f03
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-math-l1-1-0.dll
executable
MD5: c45a47b83a34843225ecd6dda2114af4
SHA256: 101427a9f932d4160b3c9be04065d495576ab40a8109d9117a4d33f8b542a30d
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-processthreads-l1-1-1.dll
executable
MD5: 94015263f243bf376bf138dfb1cb7b46
SHA256: 85f410b3c539aaa2ac8b5be976af982a8765fea315671badf542c5a0c71d600d
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\avfilter-6.dll
executable
MD5: 5b2a396ba37016a8bdca080ffeabc7c4
SHA256: 266769059ab9f3af801f73f8a579df23764db38a3b6fbe23719fe8f06788d92a
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\_ppt.dll
executable
MD5: 7b94a900a3989601ec782aa0ec06797e
SHA256: e07336c7faf3c8c3da03191b0e0a7de5701f9e49d6459f8a594df570689b2b93
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-multibyte-l1-1-0.dll
executable
MD5: 94d26026d6b10f2cea7b6125813471ba
SHA256: f42cfc5cf9682e31404f262d9954f7e4ba6de35a510ea7d7683097663840cb45
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-rtlsupport-l1-1-0.dll
executable
MD5: e2dc3af0989b0f05159851ee4453cebd
SHA256: 6c14cdc684c2dff9170de29533c521f58c3501eb8cc088de9c9b930eee048c5f
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\QtXml4.dll
executable
MD5: 0b4b1d9d360d361dbbfbe54591dc653f
SHA256: 4064d189d7fb4a9c3a1d8baf50f3da3c67543f654330603efb6ab90ee669f508
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\_wv2.dll
executable
MD5: f137d8a740fc18b496c25e4633719fae
SHA256: a8b643e27196573e9b235e3e2c8b1d16557d774a204ec7885f265d092f187c6f
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-private-l1-1-0.dll
executable
MD5: d7d5dc0cc105ea8cf525862b4567637f
SHA256: 705e20df0cf4de0299072b7294ed57302b26ecb76d409ed7ecf2f2fea3d59947
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-string-l1-1-0.dll
executable
MD5: 1292ae17b93cc2f8504d025fd1b71a01
SHA256: a03360d7024a4aa1013cc2cca408c1343666c7dae6bff61501d0e80d44cfb759
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\QtWebKit4.dll
executable
MD5: 3deb3583b9fe45356163f2f7e221c43e
SHA256: 538fe3695d90cecbe47becbf6f82a794b701d001569fc2d0d9d7fe35d7a4d335
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\_pptx.dll
executable
MD5: a7ebeef75f333d405132b91afd12e8b9
SHA256: 6649b94b61e2b61b7bca6eb25e895854c99d29847f6ad269ac1d613d93c9b3c7
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-utility-l1-1-0.dll
executable
MD5: 156fb885f50d94624ca16289f21c1d66
SHA256: d793426ab222bdfc51f136f07663cdf34b31847ee32241e6f3589b3fc1886c22
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-namedpipe-l1-1-0.dll
executable
MD5: ebceb63468278a061ce4b95d12d723c5
SHA256: 082cff6fd2437f7208af7ebd56b8961bd16761255c6f1214499e93975301b300
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\QtGui4.dll
executable
MD5: 80357749ddebee8e7c726e5521ddaeb4
SHA256: 90eb6f66b31d7d1f9b41e9079805581e4981ef3192d1332c50b1f51493dd5088
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\_xls.dll
executable
MD5: e88621a96889c1ec01caea2b1b9ec1db
SHA256: e2f811c07aae5db2c7f86f1e2e3956689090c36b7834e576dab44e7994a2dc7d
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-time-l1-1-0.dll
executable
MD5: dfd30f7dd0c43184de48d97d16cd5b41
SHA256: 5baa7efce0f3739812913e1a24d1cd326cd1fb53058719b415c835ecd2840e8a
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-interlocked-l1-1-0.dll
executable
MD5: 86e369bd8455272049bb60a53624aeee
SHA256: fe8c2607e57e6779b6485ae08e658bd7b98d79147946f262d6b3699de9259d43
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\QtNetwork4.dll
executable
MD5: 959a49de88bef582f7bc9f4820d663ef
SHA256: d01d41bfb2f8e73ea34fee35f27b865a076ff51018c134bb2d63039c6939bf1a
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\_zlib.dll
executable
MD5: 1a2c217b0773ae94603f338c26e1d99a
SHA256: 9eb700e67b788d279cca688efeea4f59c5319f540a03b5d1750ed93dab2662f1
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-runtime-l1-1-0.dll
executable
MD5: fb2dc78b138f3fe4b7e5b3a3cf9760e4
SHA256: d92e0f00c59425e74ed419c158414e2c1e34047d10072dcb9215a5c91b4050e0
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-libraryloader-l1-1-0.dll
executable
MD5: f72de8f45343b9f0135f4d71a3b67fc2
SHA256: 307ac04192de5a107ee66c9a4bdc16f95cede35ff39f50d811a8d5defe6e044c
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\QtSql4.dll
executable
MD5: 3ae797c4b21e4b3e42620965db11c218
SHA256: 6c80adec263865c34497ecd33f311240a81f2e2a41af3e2489993f16f4e2fe4a
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\_xlsx.dll
executable
MD5: 61bc9bd188b45aaf7c9b848f58483d6f
SHA256: 3af89896b08fb461fd53aebe28b28dfb3da50963ba6af50e9c8ce2d309346b4f
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-process-l1-1-0.dll
executable
MD5: 0b21712051d25cc0666f5e6d41b64bb8
SHA256: 5ab5fc3ba961a43d6d100933178121a7d8486b936f5ebc5e276e739f2e1da5b9
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-memory-l1-1-0.dll
executable
MD5: ce7d62974e002ed7736117fce3d25b38
SHA256: 01eca7b03ce90601768acb131d61875e418197234891fb71a2695aaa2f13857a
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\QtCore4.dll
executable
MD5: 34e13d090fd30ee1cbae54c6e43bab88
SHA256: 20912177d5978cf3b7fd9fce3f5f5cab93c70c3ff83640dc7c2adf1734cc0551
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\_xml2.dll
executable
MD5: 4d06395f7036ded60371771ec71cd402
SHA256: 41e40e3ae24a0964f14f69739d21396f84a1e127cf05c5055174a05cd42520a0
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-stdio-l1-1-0.dll
executable
MD5: 125c4539da3d6aee3a2942bced7f06a3
SHA256: 4ba617cadc3806532eecd00957b2329ea8472224891228b99da3aacb002b75e9
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-processthreads-l1-1-0.dll
executable
MD5: 08d5b94e8b88fc6aaaa67969b03640e2
SHA256: 93bfe4c4663c0a2807f5cd3be67a8a21dc93c5b097b934c17aa3cb4c4374173c
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\plugins\sqldrivers\qsqlite4.dll
executable
MD5: 6dc0f043d6a5856aed8c1db7038ddc83
SHA256: 58a15669b579b9202c914a25bdf6267e27b80548df6ed3c13e762a9b6ecae464
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\QtHelp_.dll
executable
MD5: 73512c37a13a5550436d3e5249ca0344
SHA256: 3318045944d6949cf01f61006fa98dac35f95a50d3de39ba70be8f3bd57c59bc
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-crt-string-l1-1-0.dll
executable
MD5: 290a004945b199b2aed82959b1623626
SHA256: c6aff750c97c94a594f6cfd6db2998c45e3c0cd9b4f779df1e8e72dc7b606534
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-processenvironment-l1-1-0.dll
executable
MD5: 66012263fdc48ac26001f3814bcabf20
SHA256: a10d248ecd4a326912a390066bac1314715ee3801332f4a9c64b5cff264883b4
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\vcamp140.dll
executable
MD5: 280b0e79873353b5b22912b6931a0e45
SHA256: ad3451f3035a8606c9ba773df8bfa6d5434049babafc9755383d81fa43755065
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\QtCLucene_.dll
executable
MD5: 566245c397ad2b9b0d848f0ba1cb26dd
SHA256: f6087653189f034b8bd416ff9d02f9e1be02a1bec585131cdfbe5dc597986733
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\vcomp140.dll
executable
MD5: 49b855efea2ebe9e104fefa017cc9878
SHA256: ae780948e9ca4e6968dc72a2b32d55409b685e4326db735b0679e32512506cb3
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-localization-l1-2-0.dll
executable
MD5: a675093b0d146773b5a2010a0adfd021
SHA256: a6d2196e5c8b17851ea134f1ac02481846f78b0075860cb6eb4f90e0243449e6
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\vcruntime140.dll
executable
MD5: 238dae6c4bb494893d01b99f6effdb93
SHA256: da9d322ab2d891a83312f194e70060b1e2d1e6ecd87a4cff5a8f727453c1c4b8
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\ssleay32.dll
executable
MD5: 1f5ac888d8f9fd3106a3ce4c98b7094c
SHA256: b86cc02582ce3d69511fba73ce9edfca9ef483cb9ffb3bf7928c81034e659af8
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\concrt140.dll
executable
MD5: 092b95b9308e2827a3b1598add0e306d
SHA256: a3cdd51d7a6260e352ad6de5451f4164228ef8150c77c02e5dab3b38f964307f
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-file-l1-2-0.dll
executable
MD5: 856be91f8f44394cf92be1af50530521
SHA256: ad487c96c39271db2c3340bb106fa8f3f2b401b100b3d342813c09fbfbddbd05
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\vcomp140.dll
executable
MD5: 56ce9c075ec13cf3fdc23dd554a8ea25
SHA256: 1d480d651414304bddd0928b1c1563b4fb7f89b1c6ac30650c884150de0ec540
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\libeay32.dll
executable
MD5: ecf15924f1068987a1b9722950fe5774
SHA256: 6792788b37148ce5a706f2bb357f0aed417411327bcf20f4a339e7cc9b53cd7a
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\vcruntime140.dll
executable
MD5: 8e65e033799eb9fd46bc5c184e7d1b85
SHA256: be38a38e22128af9a529af33d1f02dd24b2a344d29175939e229cf3a280673e4
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-handle-l1-1-0.dll
executable
MD5: b801c68f8146904adb86869f5c3477a5
SHA256: d83d3edef8ddbecf31af7437653e66adeb303947ef3da31a1280a485422e475f
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\vccorlib140.dll
executable
MD5: 40da90c329fe23c4d016cdc92f53e7b6
SHA256: 384f46d4aa479e6a11b82de9daead805d588824b80da299c3d84fcfb2c7ff05e
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\libeay32.dll
executable
MD5: 47153e2b90961a614d7b99be6fc6a635
SHA256: 9427be7b399c255bc8c4dc9791144b90c2b2126791a6de061edc723cbe634ea8
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\vcamp140.dll
executable
MD5: f89482c2c8a495993e2117d5d1bdf442
SHA256: aaa4364b8fd322f8878d91f8b76319ed71357e2a7e91d0f732d7857d067ceb2d
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-file-l2-1-0.dll
executable
MD5: 15f59e829f9f2020e9c47a10deee718c
SHA256: 93b28bff2f9d64a02f8362224ca45bfe4d6bb7fa6f83403ba9adec300dc7904c
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\msvcp140.dll
executable
MD5: b9abe16b723ddd90fc612d0ddb0f7ab4
SHA256: 75fc76655631a4ae72d015b8e85f899537c603661ca35a3f29099b8e4c84716c
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-conio-l1-1-0.dll
executable
MD5: 84a950e3c162d67f98516bb1744139e0
SHA256: 91f4db05c69c58ecb2493e30acc5297043c41b1ce6db50cee4e2922cd4bcd7f2
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\vccorlib140.dll
executable
MD5: eb977a48cb599861361188190ae80e49
SHA256: 409b4ccaebcffbff0eb12a1a8da9a2affe488fcdbbad7e00d194ceec38e944bd
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-heap-l1-1-0.dll
executable
MD5: db5013d1a02d899314b9518da6d0b2e0
SHA256: 47adb171040b53b068e2dc259ebc75562dcec8811d68b7c4b0c16a797d7388ba
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\ucrtbase.dll
executable
MD5: 63413af8fe2c3fa45191345104b1e92b
SHA256: b2c226239b4581b5d21572e30073c0f2f85387b20ff27fff008060e0d72959ed
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\bearer\qnativewifibearer.dll
executable
MD5: 4d68be4e19d650743d6dbf2f6e66b254
SHA256: cb2dad0fe69b8c5718c74560d812d58faef181bf65a81042fc069c535058d5a3
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\msvcp140.dll
executable
MD5: cfbdf284c12056347e6773cb3949fbba
SHA256: bbecdfda2551b01aa16005c88305982c360a9fb9ba3d9be2fb15f2e9c6eb809f
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-file-l1-1-0.dll
executable
MD5: 350e52ba8f75e06b370e7d7b60c97c7f
SHA256: c332a484a959a2241c43767f7eff8067855dfaff6ced79f03de154de99269b34
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-utility-l1-1-0.dll
executable
MD5: 5cde35104a68606913af6e5bd3b1adea
SHA256: 111f6dd2e7247071a33d75bf98d521a8d09c4071f90483a82e6ed9af69bb52c4
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\ssleay32.dll
executable
MD5: 1cc094bea82e5305bf1d5685e8a57549
SHA256: b40f5c192f86dc29b88473a34684802785208475d3437749b1a205ba79f7dda3
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\ucrtbase.dll
executable
MD5: d0d8cf4e5302fdef07168d7ce184de5d
SHA256: 1ff49fa3db1b3aa78459544594f72f7aebf2ba285476c2c8a064bd887ea7f565
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-datetime-l1-1-0.dll
executable
MD5: aab52e0385a66e157bb440cb5e3cd3db
SHA256: baa6eae9e3742c736327da12c0e2e586e65a0b6d667547c638fd1287886f022e
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\concrt140.dll
executable
MD5: c8dc168d371bdea660abed609ac8e477
SHA256: 2d533faa5bada768bf645da22ab2fb0621399fccf9c2b34fcf37492e27c21796
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\imageformats\qgif.dll
executable
MD5: a9f3b87eeb13f1983d93ac30df5fb0f1
SHA256: 583174f61ee222b2d43c982e0d41b0dd37617b934ee56f94712e8dade2b45790
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-debug-l1-1-0.dll
executable
MD5: 4cb14835b061f42179d5251e744fd667
SHA256: f9aaaabf78feb39a1d8e971f5ce047d1c4a896a80409b800f1f7112cdce420ed
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-errorhandling-l1-1-0.dll
executable
MD5: 7c1f03e83bcafe58ff99b3abb9e7de43
SHA256: c8fc616e5591d0b77c592059e2fe2cecb54b1219a72d9a92fd09f396fd340cf7
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-string-l1-1-0.dll
executable
MD5: 7a2799f4bc45505e7104e06dc8e254f8
SHA256: 92f72f495a6897f7d7cf2c2064b2b65f6b4fbd4f30911a534a5cd0de73395ebe
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\d3dcompiler_47.dll
executable
MD5: c5b362bce86bb0ad3149c4540201331d
SHA256: efbdbbcd0d954f8fdc53467de5d89ad525e4e4a9cfff8a15d07c6fdb350c407f
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-errorhandling-l1-1-0.dll
executable
MD5: 6177998c2ce574a177e524746b77efe7
SHA256: a0aa340274d4bb46b6d9547d647ab7dc16c229577bbab836e6a4f3307f310332
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-debug-l1-1-0.dll
executable
MD5: f97b671fac0baebca98059a9b099c4f9
SHA256: d9b96b975a90b0a8c08ffe6d2185b6714d75bd8fd3d8346aff4a069d44960f73
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-stdio-l1-1-0.dll
executable
MD5: 4614d03a94d46c0e9d1c5d96a3fe1d78
SHA256: c7919be431ce2fa1906ff9eeb19e4cb19a30a4680107ef8737ce894654b21a5a
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\iconengines\qsvgicon.dll
executable
MD5: 5ff84097763a867bd174d6ec9506842a
SHA256: ca0497fc637d9c2c78c66943a14ff9c11ea70901d481b7967de5b9a60b1017f5
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-datetime-l1-1-0.dll
executable
MD5: 928be2a3fc2e88bda5ca0808324e97c4
SHA256: cc6c2fdf1c34fa82036165b111f91220bcf7e43aab79dfb284f982f0590bebb1
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\msvcr90.dll
executable
MD5: cdbe9690cf2b8409facad94fac9479c9
SHA256: 8e7fe1a1f3550c479ffd86a77bc9d10686d47f8727025bb891d8f4f0259354c8
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-time-l1-1-0.dll
executable
MD5: 38b633f132f8e2b3abc268537fa415ec
SHA256: 46cb7b3a9f8aac5adcdbe23494e458f3195adf4b8ed1c71f2d934ddde651e57e
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\imageformats\qdds.dll
executable
MD5: 75232648166f9e0c330e2e83fabd25ed
SHA256: 1fe15cd59c62f1dd36d6d0febb6f6bf70b59b23c7292ec87c71bf2c059d57019
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-console-l1-1-0.dll
executable
MD5: 7699c096202da0db6b07fafc914d60ed
SHA256: 0052515763a1a31d2527a2eb2523fb7b88d8e55c4e4da5ef352b565476bf21e0
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\api-ms-win-core-console-l1-1-0.dll
executable
MD5: bcbfcd896e50e591b22e237c903fb523
SHA256: 8f28bbea2ac836fe993c2fccbc7920c6e0fb5cd3fba7956a85273ebe2282fb15
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-runtime-l1-1-0.dll
executable
MD5: 55b80c522731ecb92914bf9cded028c2
SHA256: 4c787ff8d40bb803e75fe6218fec36a672cfa6cfc7f6e80e68a7eb0b77a10e5a
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\imageformats\qtiff.dll
executable
MD5: 161c5d241b1d8e789ee19ea9796b259c
SHA256: 85d63e5a2a7be965a098f69aebba412ae94b6992ab597cb0a8b7ac1fe31e5f64
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-file-l1-1-0.dll
executable
MD5: 33636552339a4a04d75b7c32dbec59d9
SHA256: 05b478718540a6f410a3ad859f7d5e56c223d6786eacc7e9bc80264f587fd0c7
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\msvcp90.dll
executable
MD5: 4c39358ebdd2ffcd9132a30e1ec31e16
SHA256: 06918cf99ad26cd6cf106881c0d5bdb212dc0bac4549805c9f5906e3d03d152c
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-process-l1-1-0.dll
executable
MD5: 9ee275466394a2088d7dfbbc0c716671
SHA256: c68a61c260454c0aeb051ddb2bed52cbca44b96d50046017cbc351b41f225dc0
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\imageformats\qjpeg.dll
executable
MD5: d9f7eaa8c02d91b4bd15f6a88f06445d
SHA256: 1d50ec4fac54fd1970b73816045f35b7d80176b4e1d0ebcfb03c46a43e9f9a91
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-file-l2-1-0.dll
executable
MD5: 361c6bcfcea263749419b0fbed7a0ce8
SHA256: b74aefd6fa638be3f415165c8109121a2093597421101abc312ee7ffa1130278
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\msvcm90.dll
executable
MD5: d34a527493f39af4491b3e909dc697ca
SHA256: 7a74da389fbd10a710c294c2e914dc6f18e05f028f07958a2fa53ac44f0e4b90
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-private-l1-1-0.dll
executable
MD5: ef1cb6df15b7fa7f818486b38b1d0cf4
SHA256: 8ae3cdfd38f36e3cb5f3924cdf4cc575491fb3c1cca927f8b320071081ba31b0
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\imageformats\qicns.dll
executable
MD5: e805e02b7269b42c71c4824274fd02c0
SHA256: 9960815b0b9ee5d917191579a7c59d5a983882deff4b27f12303faec4efc6ff4
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-handle-l1-1-0.dll
executable
MD5: c2cd29370b21c0361d7f79d248c05860
SHA256: 550b4f5ba95108b01a24f05496576a4e73642334a10dde61b09846e0efb9f260
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\helpview.exe
executable
MD5: 74658af7d210e9c064bc859f6b608968
SHA256: 34aa0f2705177408c64c26bdf4571c3b7113905fd954aaf8b745df45f0044116
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-multibyte-l1-1-0.dll
executable
MD5: accd87c328cd61d4100381ef48116b33
SHA256: ff7d27ac5b814308a6ed2b70283a2baeff7ad4865d5488377a757ba72a5fc719
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\imageformats\qsvg.dll
executable
MD5: 59967a1ca7f4f5c8c4a027f39fc412b0
SHA256: 0e03fe31b7f4e173e8d9d94c5d683c1a2d79bde15cbb12f90fbc893ae42c4896
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-heap-l1-1-0.dll
executable
MD5: e93f34fdcd8e5ffc34af48c90f6f95d1
SHA256: eca63fc5c873ce8b36c507e2b9a88caaea9617c84669886b15f6bc38bd0024c6
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\Restart.exe
executable
MD5: e620ab5cbd6ef621363da0804eb7d6fe
SHA256: 23e11964bebc17211028f49d8cb2c3cd598bc060bafbf94ef317f2a96f302995
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-math-l1-1-0.dll
executable
MD5: 85893a96a568ba9781f50f876ed303cd
SHA256: 08e34f12de24e89379a0533f21a23ce6fecbea05d4062796d4ffd4adc3012316
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\imageformats\qico.dll
executable
MD5: 7fc11df427e34ddfa4a548629d987616
SHA256: 6b8fb989d3a40a48c8505b43772632cd19d0be76e6333bb34c39574f4874ee93
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-interlocked-l1-1-0.dll
executable
MD5: 28fd20b58320f0ed023d9ca19da3a06d
SHA256: 2f2f9660f4ffa814f465676d5b9cb9bb70d0b7c5fc5eb14c34cfe94a50883b21
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\R-Viewer.exe
executable
MD5: 83246f879c08be547afb46ffc97a1758
SHA256: 43e44140caaceb50e616147c372d9cfa85c029e88e4e5cbbaa538e792d509170
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-filesystem-l1-1-0.dll
executable
MD5: 73e14d927d075ca273b3237116351e8f
SHA256: 966a7f15bfb2e0ff7888d583638ebd675d8f46b264194cf332f78140b7c129e1
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\imageformats\qwbmp.dll
executable
MD5: 5d0b141ad7c7157391fa96eac279a9fa
SHA256: 0e07e4d6ada0819abca455d6491dd4fd47f11235363238cc225ff1136fdcab4f
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-memory-l1-1-0.dll
executable
MD5: ca3906b115461654eed0db5933eef5d5
SHA256: 76a3aa52d49dd0d8e0451f4045f4d8ba05d2332d0db2a39408b85cd2e43b84a3
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\libgfl340.dll
executable
MD5: 5c429858d752010b291bbe79c010e975
SHA256: c27e483314213509eb0fa6b990fc21cd7a7c89a277d5ec68bdb205178cbdc06f
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-locale-l1-1-0.dll
executable
MD5: bacb72fa56de18d5ac63e4a0a3fe768f
SHA256: 25905676b543c4f05e9dae135f929c03a57686a6941ce59be2b3450521feb943
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\imageformats\qtga.dll
executable
MD5: fc09823e35d053f96303b7177f62d717
SHA256: 549dd801c4496012f33c7655382363b34fb35b00b7dc361c479a210e5cc13886
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-libraryloader-l1-1-0.dll
executable
MD5: b45f933a57e388cfc5399645cdb696f3
SHA256: 2f9c3b077da02c587964a59e9c4e2f383ff8357229eab4b4f04814df94d78ff0
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\libgfl340.dll
executable
MD5: 5c429858d752010b291bbe79c010e975
SHA256: c27e483314213509eb0fa6b990fc21cd7a7c89a277d5ec68bdb205178cbdc06f
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-heap-l1-1-0.dll
executable
MD5: 01370c79ebabd534e7b58d35072d2866
SHA256: 742bb9bf4c232f84ad8008af4af8eda7a1ec3eb76f05d9d7ebb95f6a5cabd2d8
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\imageformats\qwebp.dll
executable
MD5: b0a1b93e3c94aee254a5bab05e311fc2
SHA256: 7d464ed8eea47462380a2643ded649831c3c88e1ef2434d863825923553b8aca
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-localization-l1-2-0.dll
executable
MD5: b402ed77d6f31d825bda175dbc0c4f92
SHA256: 6ed17fb3ca5156b39fbc1ef7d1eefa95e739857607de4cd8d41cecfcd1350705
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\libgfl340.dll
executable
MD5: 8310be389603fa3fb419e8bc4b404391
SHA256: 2b209ec9980d05a41863022391e278b22b061c5df3310bcca3ffd9b95d79e09a
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-convert-l1-1-0.dll
executable
MD5: d749afffa2b3be4b2a9edac50c20b28b
SHA256: e64fbac3491b4693e79a3f7b0db1d788f93608d3fc82133edf25a868c80d2153
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\libEGL.dll
executable
MD5: 455f6735be50140f2ad4ba22ce85aee1
SHA256: 8c8c902c38c89e05571b0d662f8de539cfaf3dce86f93f339e16b1377d955ac2
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-processenvironment-l1-1-0.dll
executable
MD5: 04729245832e3bf24cb5b28f9c2e9c1c
SHA256: bf11319eb6be15633e47ab8f247d1acc9a9ecdf37181fc0ddfe9388ab82ac90a
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\RUndelete64.exe
executable
MD5: 53198adba7b87db28152f6f648af3b1a
SHA256: 6f18651883a8c642306a3fc1af434e176823c9b363ac99b473d2519afa6586d2
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-crt-environment-l1-1-0.dll
executable
MD5: 7a2874fe036f7dc86ed5f712adaa38e6
SHA256: dd054e4de84144c2130fa8d28d563252a7c4089a58872e49d63bc43c9a1a3cb8
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\libGLESV2.dll
executable
MD5: 9988803bdf61629b172e0122e40b6cd1
SHA256: a3357abc201416fb55720177242bbff3c11be32e2aa818bd1508044357145e80
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-namedpipe-l1-1-0.dll
executable
MD5: f24f386cfa5f097b523ccfba5c8cdca3
SHA256: b1b2595494072a52f1fc44586debf52312eab1a245a7a16185d7b1af37b159a6
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\RUndelete32.exe
executable
MD5: 6c0fa13196cbd3ba5ccb542eca4c2d77
SHA256: db944d47108fc581d9d6827e4d06a4769c4bd2400a11b77a258bf0681a1d334c
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-util-l1-1-0.dll
executable
MD5: 0c33a3762c1e583342d80e9b6483f74b
SHA256: 187d47ebcc1e96abe635f23c92d2c63fc8cd741fcb03fe2dd5fc3054cb3d6d92
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\Qt5WinExtras.dll
executable
MD5: a87b05256132f2f85d8467d21183fa9a
SHA256: 856013e6afd1712a6a4f516a86437b5475755e27ac95897fc53a19d63372d96a
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-processthreads-l1-1-1.dll
executable
MD5: 3d872be898581f00d0310d7ab9abaf2b
SHA256: 4de821884cbef4182b29d8c33cfe13e43e130ad58ee1281679e8d40a2edcb8ea
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\R-Undelete.exe
executable
MD5: c56c7d739bb7c7439097de877f3aef0e
SHA256: c120932a288d32f86a66b8aa4e21541aaac737a499cd85b215775d3db44bdef8
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-processthreads-l1-1-0.dll
executable
MD5: c9dbb0de9907bb628f5733c81f973462
SHA256: 7646eba0c683fc3e1b00f0b3b2b5912621b2016a6ceb7d53181cd1c3fa64785a
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\Qt5Widgets.dll
executable
MD5: 666709d029525e631a3682db00e59a46
SHA256: bc137eba82ae372592b1fbc9d465ef8989da7e663788c25dbfa1491de049f3ef
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-string-l1-1-0.dll
executable
MD5: 059bb41588d83c95caeac5d06cb0b59f
SHA256: 3eda46e395fad6ec222ab44188d6a46a468b0fd4aff28252938f4e6a9a3e3893
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\StartMenu.dll
executable
MD5: 478a402693c3aa2250bde4af2f0a1dc3
SHA256: f8f3c2ee3ba4a9701444c1b8b1807ef93711cf29b8c8464fdf002f1dc01d8ac3
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-rtlsupport-l1-1-0.dll
executable
MD5: b8cec282fb1491eb1d2be2d969e96fe2
SHA256: 09b7f0a7f68a12602e7f4dbd5a7f1cdfb3e93fd54326884e48f36e2e200acce9
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\Qt\labs\folderlistmodel\qmlfolderlistmodelplugin.dll
executable
MD5: 283bf91655d16160eadc421422e3cc66
SHA256: f8a5bdcc15ab347f75de3a5a04720f0dc1a482018f7d231109c477987c9f2b34
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-profile-l1-1-0.dll
executable
MD5: aec5ebac6404b541565026c3cb290e0b
SHA256: 4ca44ede30b46f1f23905cecfa27f0edb26ee960dba10f9bf8002d79ed77c3e5
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\InstallOptions.dll
executable
MD5: 67d8f4d5acdb722e9cb7a99570b3ded1
SHA256: fa8de036b1d9bb06be383a82041966c73473fc8382d041fb5c1758f991afeae7
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-timezone-l1-1-0.dll
executable
MD5: 6c180c8de3ecf27de7a5812ff055737e
SHA256: 630466fd77ac7009c947a8370a0d0c20652169824c54ddcb8c05e8df45e23197
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\Uninstall.exe
executable
MD5: 94e7190dfe52a183a1c49afbc0d20765
SHA256: e3daebfdd364b46e6efb851bb934d1007660b764e0f681a5ee7b86f697187c34
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-sysinfo-l1-1-0.dll
executable
MD5: 79b6580c25f8c572376cbf39bb41be05
SHA256: f5bf492fe568eb57d2e7111b1c3927f1ee897b5a1109bc68ebe011a2dfdef2fe
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\LangDLL.dll
executable
MD5: 410a586735f45164c86bda363ad8446f
SHA256: b15b1fc88d1b56088b2d3738d76772a91fa186a316a3e0a154358820d0fb9005
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-synch-l1-2-0.dll
executable
MD5: 1742da4d8df54767064bcb50b4b5c32d
SHA256: e000c6685719c2b07355c1eddbfdae7c6794aa6c0ac883d34af33dfc8bf40779
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\api-ms-win-core-synch-l1-1-0.dll
executable
MD5: 56be6b76756e6d4f81dfb8f251b63739
SHA256: 83c1df33df30df48ab161a5a1d6c3cb4bdaebff330ee6e81e871afe3990d7a65
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\swresample-2.dll
executable
MD5: b619d4c41b758d9e1c17dac86dce2f1b
SHA256: bfca70800ac170752d4d09b0b279a7a8fa7d9d9688fa8dd5dde14e0d74461096
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\bearer\qgenericbearer.dll
executable
MD5: b79e1dc815122ab262d77592b9b28444
SHA256: 4e85e81294c4b3f085ea691d76675f94303e1beb17067adb42248e8450e173ec
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\reg_key.ico
image
MD5: abd452dd7fd7ae34e200976b97126a54
SHA256: d120251aa351392804827eaec1c8ec067031eed7bf64cf8a6d8fd722ae72b7df
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\zhcn\helpview_zhcn.qm
qm
MD5: ade975512bd74cb4e931cc5de6b635b3
SHA256: 9e027b847f8a7998024d4886f3296896be22cf4076e81ca2488128bd1a14c3f7
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\zhhk\qt_help_zhhk.qm
qm
MD5: d6b901f4d2febee90f6227a0f92592a0
SHA256: 15994038f8a4086eead69bad8e7343e45c81c6358dd40862c449c49129374ad8
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nsoD393.tmp
––
MD5:  ––
SHA256:  ––
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\zhhk\qt_zhhk.qm
qm
MD5: 309c19a23ae0a868be6adf0890010ab1
SHA256: 7e4adbf70aca304f0336baab1e99d2aafcc8c27309e3debed4575f8ff4dc851f
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\ja\qt_ja.qm
qm
MD5: a9218080c2d1cb570b13941096ed2721
SHA256: b313fed8bf1695e148eaaa9c4a84b485181844af3eca808ffd43ddfe34fe5e12
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\pt\qt_pt.qm
qm
MD5: 6e81c9ddf21a28dcaac72adf87c8bc31
SHA256: 47415191558c4ee4f61010d15ede7bf46f9515db685f1e8858c12fd06e900083
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\ru\qt_ru.qm
qm
MD5: 3a2eb61a061d04e6caeb285ee63310db
SHA256: fdf613022503d3858e60f74627d7a9eae6cd8caf981eebb85eb4fca663d074f4
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\zhcn\qt_zhcn.qm
qm
MD5: 24f25891971cf25aa8230ba3f98c4c85
SHA256: 1e524b7aba1cbcd4df6519347701bcf771cf0ca7cbb1e053f0b3d65384281872
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\R-Undelete\R-Undelete.lnk
lnk
MD5: a02b2d25ca7e033dafdeefd9ef7c5b67
SHA256: dbcabc0e6d900202bdd1d58a4ea07d330ee53e016ff1f4f9bff8adf73726963f
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\zhcn\qt_help_zhcn.qm
qm
MD5: fab82e86bd52deb5677bd478e7688c2a
SHA256: c0ea34e5809061de1b153b511965da91c836097e03a0ccaaf2b137e7c6f8f12b
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\fr\qt_fr.qm
qm
MD5: 1a94279e1c21b0c7ef6dd4fabf143a23
SHA256: 02f2a3c2cde28945cafe349c2763d7c34ca0215ac12d6be2b8906018e9b5e3aa
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\de\qt_de.qm
qm
MD5: 2471f28aec9437725cc1580fce142037
SHA256: 10fa8dde9f4c9762e6ec20f71f863db44aca435aa1d46215f98f2cf9e88d84f7
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\es\qt_es.qm
qm
MD5: 2db9055a56027c4d0a5a29a4161a97ed
SHA256: 821c7f609c01435f38cc8e99b4ebcd9f2c4f52951e9e1051ad7927e745b62ba5
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\helpview.qrb
binary
MD5: 4ee4a58155f86d512c54aab888dfcbb6
SHA256: 629613c08265d02af0449b4dfc562c19b58462b9774a0c7ba04fecf331cbb116
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\Microsoft.VC90.CRT.manifest
xml
MD5: 587dbe91cf548669e8c8ec8f6d56ce47
SHA256: 0c838c4262f99f27495a7c2a1bf4ec8f482d1c9bc2493c3c19b9360f1a06b8eb
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\ru\helpview_ru.qm
qm
MD5: bae18e62f687a2e21c67fbafd961db9a
SHA256: c5311d6e4a9472f5d9aed62e4b52ce927d148d9fa36465a3d48e82939364e92d
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\rln_viewer.txt
text
MD5: 58d31facbfb66fb2e1831587d0188c7c
SHA256: 7566dd8ea5acf284036b7394fd806ecd790caacee29f310ef1ea2eb1d1e88c5d
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\ru\qt_help_ru.qm
qm
MD5: bf2fdcc77f883fbca3a826fedd6860d6
SHA256: cff33d450af6fc4aca24bee0aa2dda2d0cd815b0487bba2834e8766fee3fa114
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\pt\qt_help_pt.qm
qm
MD5: 4aef4415f2e976b2cc6f24b877804a57
SHA256: 307cef95dd5b36ff215055d427e1885b7fc3650c9224cf76d63056545996ff60
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\R-Viewer.qrb
binary
MD5: 03b6953b6f2a9ecca1f43fcb08cdb554
SHA256: b1b3c73b2b556096c587210c27231995b3fe71bb745d05182b71afa2866dd956
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\ja\qt_help_ja.qm
qm
MD5: 4ef6476052e2a832409e95c0d1851396
SHA256: d63c1c26d1a640dc62a8aa64871fa4467d847c516788277faddb98bbc2bf4028
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\fr\qt_help_fr.qm
qm
MD5: 05cef91bde72d4f460c7270ca129fd6d
SHA256: 107a086a2e8958233888bbf52766f906a8a8e14ad55dd06a981fbce7f6bb2610
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\fr\helpview_fr.qm
qm
MD5: 3b2125455075f19e25fc136a705ab139
SHA256: 4518af0c0674f73f9a40f328562436875390836dab629767b7701b891e3c3ec3
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x64\RttRes.rcc
––
MD5:  ––
SHA256:  ––
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\x86\RttRes.rcc
––
MD5:  ––
SHA256:  ––
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\pt\helpview_pt.qm
qm
MD5: 02b7aed6f197286c082496bad3be3218
SHA256: b4a51df016dc8af7b0d5af1061eb177f631ea1277fc33d776dfd696d35fa72c9
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\ja\helpview_ja.qm
qm
MD5: 45113145ad871666d810ba9fd39dcb70
SHA256: 6e354f0724e48ac297b8476fd6b65ffdf0b6f99cff60c5cd3724dc5421f0cec6
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\de\helpview_de.qm
qm
MD5: 3d378d1c7f54f650c95fb69d3b65007d
SHA256: 9f7deccde6b49a18f4bfe8b41e8bad8755905e82a07ab89425f864a950b4a2ae
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\es\helpview_es.qm
qm
MD5: 48b78bb131ae3559dae1869cf0b95c5a
SHA256: 03a3d87080a247bc4962f55ee1f68310e7017620ec09b72fe270f1f60e63b690
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_port_warn-ENGLISH.nsi
text
MD5: c61636963229141eba66b47a408d5b62
SHA256: c17d6b30fbff8b1bb982f1cb8072c0641c284f4a962336fe320b58d8138af37e
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_port_warn-ENGLISH.nsi
text
MD5: c46302952872d611cb3d5ea8e62ec23c
SHA256: d49846a658d8ad5eb6050fdebba20171c1fad0b278aa4d2f92067870af9f3642
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_port_warn-ENGLISH.nsi
text
MD5: 82ca518dcfd4d1ff9ca41f98bee4add8
SHA256: 1ae96ed9ff5a2f457623fff2e52f56bca93ea1743c6093cb4e8b3e6b2112a3a8
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\ioSpecial.ini
text
MD5: 06b2508219b7e1f9a7edc00b643df6d0
SHA256: 812d220c2668eb4968e09f30356da48e4c8ca470d6e6508a4a00dff5fac67c84
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\ioSpecial.ini
text
MD5: cce431943b145c1e3ab81b461c5c1f1e
SHA256: c542b70f77d5d7aa25289f09c743e2f454a4252f128ca30d6b6c4d9f05b4ae4d
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\es\qt_help_es.qm
qm
MD5: 4aef4415f2e976b2cc6f24b877804a57
SHA256: 307cef95dd5b36ff215055d427e1885b7fc3650c9224cf76d63056545996ff60
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\modern-header.bmp
image
MD5: ed5c0ad0a58dbace37bdfbfc2c68c401
SHA256: 53b109af72bb98c50f6f3f927a58ca212874bed769e4c11891f27e6524885a73
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\modern-wizard.bmp
image
MD5: 0e9910cf40f7083df9ab0f236defbf1a
SHA256: 7bacd1148f2a54fbfbd8b52fa91555f4abe670164aad48cb92b54cd85cd99b0d
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\usb.ico
image
MD5: db865f8b8e24873dd16c01b33a46b28b
SHA256: 433a51af2bac9fb1a716daddd0ae8768ddca2acfb84b2340753dc6febbaae6d8
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\zhhk\helpview_zhhk.qm
qm
MD5: e5d3b68d979558efc9cef72b9220a0ed
SHA256: 26948fdb3095dde9336ac1edb08ba183060e95789e216a3f0bf0de07bab5febd
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\hdd.ico
image
MD5: f43509df51a9972f22f892783a90a8d4
SHA256: 6c215f7fb49b329066e334b075b136dba52b0244d8924d302f1ecf979ca58da4
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_port_warn-TradChinese.nsi
text
MD5: 44cd5d808e0734894cb6dcebea2a9b9b
SHA256: 2b5edf55a91a3d085b6367ff1e6f83eccf938381b60027766ede6e815bc27d85
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\repair.ico
image
MD5: acc5421f1035e2734f44e9c10a5913ec
SHA256: b081f6e50a06b6bc947824adf50da8f0d591784d0d5857d7d6d96e1164779fa8
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_port_warn-JAPANESE.nsi
text
MD5: 7f257e85ecaa5b11ea511719e9227d51
SHA256: e9696554bfefd4138eb747c6215ab32ef7aa35aea911e0827212f4ef9f1b4a47
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_port_warn-RUSSIAN.nsi
text
MD5: 982eded17942d4f683a756cd19382bfc
SHA256: 1599a679f2249f2fc51fb24603647dde13b3adc247ab18b6c7d3f49f0d44c2d6
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_port_warn-PORTUGUESE.nsi
text
MD5: 57bb04cb18a7cdca85074ebbb657100c
SHA256: 5a1df05abeef4e0450a256d0ae9e8d3334977fff76e13871d872c5fdee194b91
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\uninstall.ico
image
MD5: b400b4ded185eae1598027158c62b03c
SHA256: 97563b54e455cf18769bb3e18b3a8f6d3e4c547aeb67006bb1a05cf8bd25deac
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_port_warn-SimpChinese.nsi
text
MD5: 000803caa243077a41fcab4081129ed6
SHA256: 3b29b0266ea7d7695da644c717b3dc61abe23540881b6cdd7bb3d431d7ef3605
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_port_warn-SPANISH.nsi
text
MD5: 9f685cb220a259cc25fdd30c002d90b0
SHA256: 081fb43c590779be0711efdec0c71b52d23b5a2d5f61b9bb07b1d300a757d4ed
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_port_warn-ENGLISH.nsi
text
MD5: ee5770b90096b4dc7f7314e9b29bbe97
SHA256: d15fcaa0f05eea4f45e3eed5205a07525e205390d7b4d1545bdc9af0dfe55cf8
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_repair-SimpChinese.nsi
text
MD5: 39ef6e1d34e5c026944cda007d985d54
SHA256: dce8cda55f487c7a5b00269062495a267b87a375ffeaee97e6967535d32761f5
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_repair-JAPANESE.nsi
text
MD5: 3d9d5653514bc7a88562cf597c737b9a
SHA256: 6c7bbd6dd27b9942f7dbbda9b920da38d790ed7795333b17e0f2619b69bfad29
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_port_warn-GERMAN.nsi
text
MD5: 40f6b3b215c2fad3d04d812e7f818811
SHA256: b83bb4d197804a813964c6db1d9d469856af9696e64f12a070a00487101c498b
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_port_warn-FRENCH.nsi
text
MD5: 9f230342d7d9c305d58c66e658d6e839
SHA256: 6c91c262e9eaa2de6738fa015c5f1ffc77a28f8e087e6171c26c81bbd15eabe3
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_repair-PORTUGUESE.nsi
text
MD5: 69c2569388fd321f34c2c1ca9a94ee82
SHA256: 335c0bafce5d8a30d81ace2f32d9f1511aca45053918e521a2ec83dcf39ba967
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_repair-FRENCH.nsi
text
MD5: 03aeac0a6b8be8c35ded781d24ff3660
SHA256: 2ff8cd86c62e3a1432e6c05b2c2b2947d6d7443c40358c5ec4745318ff10cc2d
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_repair-SPANISH.nsi
text
MD5: 364278de019f8fa5c35c3f1394e58d29
SHA256: 58e1e7008939721c1c9919ff267e2fa09864b24be68e11cf5509b1a8135a51f5
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_repair-TradChinese.nsi
text
MD5: ed51f8264890318ef0543cef354cc01c
SHA256: caf07b5e1d21132ce7bfc55029d906d1f906429a0489fe76690261a586ed0b7f
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_repair-GERMAN.nsi
text
MD5: 1580997bd9984d2eefb43e2d15d2c50b
SHA256: 7a77aadc0f4abeb3175ea720f5edf164c76466dd14283a0c2f0b9e250a05505d
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_repair-RUSSIAN.nsi
text
MD5: e54cec56972e99dd3d5b3dba6b79c726
SHA256: 478c5fe19d96366f4d880d5c1f8ef384509ea0fbb33534b2ab6de5f00f4e44e5
2904
RUndelete6[1].exe
C:\Users\admin\AppData\Local\Temp\nseD3B3.tmp\rs_tpl_repair-ENGLISH.nsi
text
MD5: c8a6ebef26128be0bd4778a6537544c9
SHA256: a727430910ef49f2bf789079e2b287a2d22e75fd7c079062c8f8547c57663e63
2904
RUndelete6[1].exe
C:\Program Files\R-Undelete\de\qt_help_de.qm
qm
MD5: 5412d139c44e0e472f03cc7efbdcbd76
SHA256: 2775864443d8670c61718f9af1931e6736f61dbda6384dd0100b2a93f32fba1b
2864
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{98044673-F95A-11E8-BAD8-5254004A04AF}.dat
––
MD5:  ––
SHA256:  ––
2864
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DFB84A6AF82E0D05C2.TMP
––
MD5:  ––
SHA256:  ––
3484
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Low\JavaDeployReg.log
text
MD5: b88bff6418ccac7c79292f88bbcb75d4
SHA256: c61596580664cfe98a51f9dc17a12ad06d8a5a49b91bb1211addc2d5ea1a3b25
2864
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012018120620181207\index.dat
dat
MD5: e1f2c7ce5d7bb32d93f12954e5e4f4d1
SHA256: c533770152f208fbdecf8d6f59f2ed72525701d9420864ad4006a595f9390e71
3484
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012018120620181207\index.dat
dat
MD5: 8ac17db370a803ed531ad57d6b9e3e66
SHA256: 619a37e15620dc443fb8306e4fa355cde309c67e203b5964bf0c460ae39e31f2
2864
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\RUndelete6[1].exe:Zone.Identifier
text
MD5: fbccf14d504b7b2dbcb5a5bda75bd93b
SHA256: eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
2864
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\RUndelete6[1].exe:Zone.Identifier
text
MD5: fbccf14d504b7b2dbcb5a5bda75bd93b
SHA256: eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
2864
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\RUndelete6[1].exe
––
MD5:  ––
SHA256:  ––
3484
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\RUndelete6[1].exe
––
MD5:  ––
SHA256:  ––
2864
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{98044674-F95A-11E8-BAD8-5254004A04AF}.dat
binary
MD5: 47e4530a2bac14b88c92290bd13170fd
SHA256: 88284931064a5b0ef538a741cd5a4acadc5065075a810afafe0f8fa3c611b789
2864
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DF3F09F95B9B03B199.TMP
––
MD5:  ––
SHA256:  ––
3484
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
text
MD5: 92ab78dfdc0d325f5a925782121970df
SHA256: 2928a32916c7f0b5827afbe2d5d1b42888a57c621e9151b8f32426bf3f70445e
3484
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
text
MD5: fb89c9b421057b366b90eb1045cc4079
SHA256: f3aeeba82bee1de12dc7a08605409a75642b917b856890dfb41399f6f5d0b09d
2864
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[3].png
image
MD5: 9fb559a691078558e77d6848202f6541
SHA256: 6d8a01dc7647bc218d003b58fe04049e24a9359900b7e0cebae76edf85b8b914
2864
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
––
MD5:  ––
SHA256:  ––
2864
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[1].ico
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
1
TCP/UDP connections
4
DNS requests
4
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2864 iexplore.exe GET 200 204.79.197.200:80 http://www.bing.com/favicon.ico US
image
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3484 iexplore.exe 162.250.175.198:443 1651884 Ontario Inc. CA unknown
2864 iexplore.exe 204.79.197.200:80 Microsoft Corporation US whitelisted
3484 iexplore.exe 162.250.175.201:443 1651884 Ontario Inc. CA unknown
–– –– 184.170.130.57:443 Netelligent Hosting Services Inc. CA unknown

DNS requests

Domain IP Reputation
www.r-tt.com 162.250.175.198
unknown
www.bing.com 204.79.197.200
13.107.21.200
whitelisted
www.r-undelete.com 162.250.175.201
unknown
secure.r-tt.com 184.170.130.57
unknown

Threats

No threats detected.

Debug output strings

Process Message
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,
RUndelete32.exe D drive id: 7, info:UID=405270577 dwIdx=7 Name=Empty Space7 Parents=2,