VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Variant.Mikey.113920
|
PnbkiTYYJ8UbA9a3.exe
Windows Exe (x86-32)
Created at 2020-06-30T14:16:00
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\PnbkiTYYJ8UbA9a3.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x5bd850 |
Size Of Code | 0x1bec00 |
Size Of Initialized Data | 0x42600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2013-06-30 11:55:33+00:00 |
Version Information (10)
»
Comments | Part of Auslogics Programs |
CompanyName | Auslogics |
FileDescription | SendDebugLog |
FileVersion | 1.0.1.105 |
InternalName | senddebuglog |
LegalCopyright | 2007-2010@Auslogics Software Pty Ltd |
LegalTrademarks | 2007-2010@Auslogics Software Pty Ltd |
OriginalFilename | SendDebugLog.exe |
ProductName | Shared Library |
ProductVersion | 1.x |
Sections (7)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1bea70 | 0x1bec00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.52 |
.rdata4 | 0x5c0000 | 0x9c40 | 0x9e00 | 0x1bf000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.77 |
.rdata3 | 0x5ca000 | 0x4e20 | 0x5000 | 0x1c8e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.88 |
.rdata2 | 0x5cf000 | 0xa4f4 | 0xa600 | 0x1cde00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.98 |
.rdata | 0x5da000 | 0x95 | 0x200 | 0x1d8400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.63 |
.data | 0x5db000 | 0xa67c | 0xa800 | 0x1d8600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.6 |
.rsrc | 0x5e6000 | 0x1e6e4 | 0x1e800 | 0x1e2e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.6 |
Imports (8)
»
KERNEL32.dll (151)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetLastError | 0x0 | 0x5e2a68 | 0x1e2270 | 0x1df870 | 0x1e6 |
SetPriorityClass | 0x0 | 0x5e2a6c | 0x1e2274 | 0x1df874 | 0x3f6 |
GetPriorityClass | 0x0 | 0x5e2a70 | 0x1e2278 | 0x1df878 | 0x215 |
GetCurrentProcess | 0x0 | 0x5e2a74 | 0x1e227c | 0x1df87c | 0x1a9 |
IsDebuggerPresent | 0x0 | 0x5e2a78 | 0x1e2280 | 0x1df880 | 0x2d1 |
UnhandledExceptionFilter | 0x0 | 0x5e2a7c | 0x1e2284 | 0x1df884 | 0x43e |
TerminateProcess | 0x0 | 0x5e2a80 | 0x1e2288 | 0x1df888 | 0x42d |
GetSystemTimeAsFileTime | 0x0 | 0x5e2a84 | 0x1e228c | 0x1df88c | 0x24f |
GetCurrentProcessId | 0x0 | 0x5e2a88 | 0x1e2290 | 0x1df890 | 0x1aa |
GetCurrentThreadId | 0x0 | 0x5e2a8c | 0x1e2294 | 0x1df894 | 0x1ad |
GetTickCount | 0x0 | 0x5e2a90 | 0x1e2298 | 0x1df898 | 0x266 |
QueryPerformanceCounter | 0x0 | 0x5e2a94 | 0x1e229c | 0x1df89c | 0x354 |
SetUnhandledExceptionFilter | 0x0 | 0x5e2a98 | 0x1e22a0 | 0x1df8a0 | 0x415 |
InterlockedCompareExchange | 0x0 | 0x5e2a9c | 0x1e22a4 | 0x1df8a4 | 0x2ba |
Sleep | 0x0 | 0x5e2aa0 | 0x1e22a8 | 0x1df8a8 | 0x421 |
InterlockedExchange | 0x0 | 0x5e2aa4 | 0x1e22ac | 0x1df8ac | 0x2bd |
GetWindowsDirectoryA | 0x0 | 0x5e2aa8 | 0x1e22b0 | 0x1df8b0 | 0x280 |
DeleteFileA | 0x0 | 0x5e2aac | 0x1e22b4 | 0x1df8b4 | 0xc0 |
CopyFileExW | 0x0 | 0x5e2ab0 | 0x1e22b8 | 0x1df8b8 | 0x62 |
GetDateFormatA | 0x0 | 0x5e2ab4 | 0x1e22bc | 0x1df8bc | 0x1ae |
OpenProcess | 0x0 | 0x5e2ab8 | 0x1e22c0 | 0x1df8c0 | 0x333 |
GetPrivateProfileIntA | 0x0 | 0x5e2abc | 0x1e22c4 | 0x1df8c4 | 0x216 |
SetMessageWaitingIndicator | 0x0 | 0x5e2ac0 | 0x1e22c8 | 0x1df8c8 | 0x3f3 |
IsDBCSLeadByteEx | 0x0 | 0x5e2ac4 | 0x1e22cc | 0x1df8cc | 0x2d0 |
BuildCommDCBAndTimeoutsW | 0x0 | 0x5e2ac8 | 0x1e22d0 | 0x1df8d0 | 0x2d |
OutputDebugStringW | 0x0 | 0x5e2acc | 0x1e22d4 | 0x1df8d4 | 0x33b |
RtlMoveMemory | 0x0 | 0x5e2ad0 | 0x1e22d8 | 0x1df8d8 | 0x391 |
GetDiskFreeSpaceW | 0x0 | 0x5e2ad4 | 0x1e22dc | 0x1df8dc | 0x1b7 |
DeleteAtom | 0x0 | 0x5e2ad8 | 0x1e22e0 | 0x1df8e0 | 0xbc |
Module32FirstW | 0x0 | 0x5e2adc | 0x1e22e4 | 0x1df8e4 | 0x30e |
GetDefaultCommConfigA | 0x0 | 0x5e2ae0 | 0x1e22e8 | 0x1df8e8 | 0x1b1 |
IsValidLanguageGroup | 0x0 | 0x5e2ae4 | 0x1e22ec | 0x1df8ec | 0x2dc |
SetInformationJobObject | 0x0 | 0x5e2ae8 | 0x1e22f0 | 0x1df8f0 | 0x3ea |
GetThreadPriorityBoost | 0x0 | 0x5e2aec | 0x1e22f4 | 0x1df8f4 | 0x262 |
CreateDirectoryA | 0x0 | 0x5e2af0 | 0x1e22f8 | 0x1df8f8 | 0x6c |
GetExitCodeThread | 0x0 | 0x5e2af4 | 0x1e22fc | 0x1df8fc | 0x1c6 |
GetProfileSectionA | 0x0 | 0x5e2af8 | 0x1e2300 | 0x1df900 | 0x231 |
RequestDeviceWakeup | 0x0 | 0x5e2afc | 0x1e2304 | 0x1df904 | 0x388 |
GetProfileIntW | 0x0 | 0x5e2b00 | 0x1e2308 | 0x1df908 | 0x230 |
WritePrivateProfileSectionA | 0x0 | 0x5e2b04 | 0x1e230c | 0x1df90c | 0x490 |
SetConsoleTextAttribute | 0x0 | 0x5e2b08 | 0x1e2310 | 0x1df910 | 0x3c0 |
WaitForMultipleObjects | 0x0 | 0x5e2b0c | 0x1e2314 | 0x1df914 | 0x462 |
VirtualProtectEx | 0x0 | 0x5e2b10 | 0x1e2318 | 0x1df918 | 0x45b |
FoldStringA | 0x0 | 0x5e2b14 | 0x1e231c | 0x1df91c | 0x145 |
EnumCalendarInfoExW | 0x0 | 0x5e2b18 | 0x1e2320 | 0x1df920 | 0xdd |
VerifyVersionInfoA | 0x0 | 0x5e2b1c | 0x1e2324 | 0x1df924 | 0x452 |
CreateMailslotW | 0x0 | 0x5e2b20 | 0x1e2328 | 0x1df928 | 0x89 |
GetTimeZoneInformation | 0x0 | 0x5e2b24 | 0x1e232c | 0x1df92c | 0x26b |
GetACP | 0x0 | 0x5e2b28 | 0x1e2330 | 0x1df930 | 0x152 |
VirtualFree | 0x0 | 0x5e2b2c | 0x1e2334 | 0x1df934 | 0x457 |
VirtualAlloc | 0x0 | 0x5e2b30 | 0x1e2338 | 0x1df938 | 0x454 |
GetSystemInfo | 0x0 | 0x5e2b34 | 0x1e233c | 0x1df93c | 0x249 |
GetVersion | 0x0 | 0x5e2b38 | 0x1e2340 | 0x1df940 | 0x274 |
VirtualQuery | 0x0 | 0x5e2b3c | 0x1e2344 | 0x1df944 | 0x45c |
WideCharToMultiByte | 0x0 | 0x5e2b40 | 0x1e2348 | 0x1df948 | 0x47a |
MultiByteToWideChar | 0x0 | 0x5e2b44 | 0x1e234c | 0x1df94c | 0x31a |
lstrlenW | 0x0 | 0x5e2b48 | 0x1e2350 | 0x1df950 | 0x4b6 |
lstrcpynW | 0x0 | 0x5e2b4c | 0x1e2354 | 0x1df954 | 0x4b3 |
LoadLibraryExW | 0x0 | 0x5e2b50 | 0x1e2358 | 0x1df958 | 0x2f3 |
GetThreadLocale | 0x0 | 0x5e2b54 | 0x1e235c | 0x1df95c | 0x25f |
GetStartupInfoA | 0x0 | 0x5e2b58 | 0x1e2360 | 0x1df960 | 0x239 |
GetProcAddress | 0x0 | 0x5e2b5c | 0x1e2364 | 0x1df964 | 0x220 |
GetModuleHandleW | 0x0 | 0x5e2b60 | 0x1e2368 | 0x1df968 | 0x1f9 |
GetModuleFileNameW | 0x0 | 0x5e2b64 | 0x1e236c | 0x1df96c | 0x1f5 |
GetLocaleInfoW | 0x0 | 0x5e2b68 | 0x1e2370 | 0x1df970 | 0x1ea |
GetCommandLineW | 0x0 | 0x5e2b6c | 0x1e2374 | 0x1df974 | 0x170 |
FreeLibrary | 0x0 | 0x5e2b70 | 0x1e2378 | 0x1df978 | 0x14c |
FindFirstFileW | 0x0 | 0x5e2b74 | 0x1e237c | 0x1df97c | 0x124 |
FindClose | 0x0 | 0x5e2b78 | 0x1e2380 | 0x1df980 | 0x119 |
ExitProcess | 0x0 | 0x5e2b7c | 0x1e2384 | 0x1df984 | 0x104 |
ExitThread | 0x0 | 0x5e2b80 | 0x1e2388 | 0x1df988 | 0x105 |
CreateThread | 0x0 | 0x5e2b84 | 0x1e238c | 0x1df98c | 0xa3 |
CompareStringW | 0x0 | 0x5e2b88 | 0x1e2390 | 0x1df990 | 0x55 |
WriteFile | 0x0 | 0x5e2b8c | 0x1e2394 | 0x1df994 | 0x48d |
RtlUnwind | 0x0 | 0x5e2b90 | 0x1e2398 | 0x1df998 | 0x392 |
RaiseException | 0x0 | 0x5e2b94 | 0x1e239c | 0x1df99c | 0x35a |
GetStdHandle | 0x0 | 0x5e2b98 | 0x1e23a0 | 0x1df9a0 | 0x23b |
CloseHandle | 0x0 | 0x5e2b9c | 0x1e23a4 | 0x1df9a4 | 0x43 |
TlsSetValue | 0x0 | 0x5e2ba0 | 0x1e23a8 | 0x1df9a8 | 0x435 |
TlsGetValue | 0x0 | 0x5e2ba4 | 0x1e23ac | 0x1df9ac | 0x434 |
LocalAlloc | 0x0 | 0x5e2ba8 | 0x1e23b0 | 0x1df9b0 | 0x2f9 |
lstrcpyW | 0x0 | 0x5e2bac | 0x1e23b4 | 0x1df9b4 | 0x4b0 |
WriteProcessMemory | 0x0 | 0x5e2bb0 | 0x1e23b8 | 0x1df9b8 | 0x496 |
WritePrivateProfileStringW | 0x0 | 0x5e2bb4 | 0x1e23bc | 0x1df9bc | 0x493 |
WinExec | 0x0 | 0x5e2bb8 | 0x1e23c0 | 0x1df9c0 | 0x47b |
WaitForSingleObject | 0x0 | 0x5e2bbc | 0x1e23c4 | 0x1df9c4 | 0x464 |
WaitForMultipleObjectsEx | 0x0 | 0x5e2bc0 | 0x1e23c8 | 0x1df9c8 | 0x463 |
VirtualQueryEx | 0x0 | 0x5e2bc4 | 0x1e23cc | 0x1df9cc | 0x45d |
VirtualProtect | 0x0 | 0x5e2bc8 | 0x1e23d0 | 0x1df9d0 | 0x45a |
SwitchToThread | 0x0 | 0x5e2bcc | 0x1e23d4 | 0x1df9d4 | 0x429 |
SizeofResource | 0x0 | 0x5e2bd0 | 0x1e23d8 | 0x1df9d8 | 0x420 |
SignalObjectAndWait | 0x0 | 0x5e2bd4 | 0x1e23dc | 0x1df9dc | 0x41f |
SetThreadLocale | 0x0 | 0x5e2bd8 | 0x1e23e0 | 0x1df9e0 | 0x409 |
SetLastError | 0x0 | 0x5e2bdc | 0x1e23e4 | 0x1df9e4 | 0x3ec |
SetFilePointer | 0x0 | 0x5e2be0 | 0x1e23e8 | 0x1df9e8 | 0x3df |
SetFileAttributesW | 0x0 | 0x5e2be4 | 0x1e23ec | 0x1df9ec | 0x3da |
SetEvent | 0x0 | 0x5e2be8 | 0x1e23f0 | 0x1df9f0 | 0x3d3 |
SetErrorMode | 0x0 | 0x5e2bec | 0x1e23f4 | 0x1df9f4 | 0x3d2 |
SetEndOfFile | 0x0 | 0x5e2bf0 | 0x1e23f8 | 0x1df9f8 | 0x3cd |
SearchPathW | 0x0 | 0x5e2bf4 | 0x1e23fc | 0x1df9fc | 0x397 |
ResumeThread | 0x0 | 0x5e2bf8 | 0x1e2400 | 0x1dfa00 | 0x38d |
ResetEvent | 0x0 | 0x5e2bfc | 0x1e2404 | 0x1dfa04 | 0x38a |
ReadFile | 0x0 | 0x5e2c00 | 0x1e2408 | 0x1dfa08 | 0x368 |
MulDiv | 0x0 | 0x5e2c04 | 0x1e240c | 0x1dfa0c | 0x319 |
LockResource | 0x0 | 0x5e2c08 | 0x1e2410 | 0x1dfa10 | 0x307 |
LocalFree | 0x0 | 0x5e2c0c | 0x1e2414 | 0x1dfa14 | 0x2fd |
LoadResource | 0x0 | 0x5e2c10 | 0x1e2418 | 0x1dfa18 | 0x2f6 |
LoadLibraryW | 0x0 | 0x5e2c14 | 0x1e241c | 0x1dfa1c | 0x2f4 |
LeaveCriticalSection | 0x0 | 0x5e2c18 | 0x1e2420 | 0x1dfa20 | 0x2ef |
IsValidLocale | 0x0 | 0x5e2c1c | 0x1e2424 | 0x1dfa24 | 0x2dd |
IsBadReadPtr | 0x0 | 0x5e2c20 | 0x1e2428 | 0x1dfa28 | 0x2c8 |
InitializeCriticalSection | 0x0 | 0x5e2c24 | 0x1e242c | 0x1dfa2c | 0x2b4 |
HeapDestroy | 0x0 | 0x5e2c28 | 0x1e2430 | 0x1dfa30 | 0x2a0 |
HeapCreate | 0x0 | 0x5e2c2c | 0x1e2434 | 0x1dfa34 | 0x29f |
GlobalFindAtomW | 0x0 | 0x5e2c30 | 0x1e2438 | 0x1dfa38 | 0x289 |
GlobalDeleteAtom | 0x0 | 0x5e2c34 | 0x1e243c | 0x1dfa3c | 0x287 |
GlobalAddAtomW | 0x0 | 0x5e2c38 | 0x1e2440 | 0x1dfa40 | 0x284 |
GetWindowsDirectoryW | 0x0 | 0x5e2c3c | 0x1e2444 | 0x1dfa44 | 0x281 |
GetVersionExW | 0x0 | 0x5e2c40 | 0x1e2448 | 0x1dfa48 | 0x276 |
GetTempPathW | 0x0 | 0x5e2c44 | 0x1e244c | 0x1dfa4c | 0x25b |
GetTempFileNameW | 0x0 | 0x5e2c48 | 0x1e2450 | 0x1dfa50 | 0x259 |
GetPrivateProfileStringW | 0x0 | 0x5e2c4c | 0x1e2454 | 0x1dfa54 | 0x21d |
GetLocalTime | 0x0 | 0x5e2c50 | 0x1e2458 | 0x1dfa58 | 0x1e7 |
GetFullPathNameW | 0x0 | 0x5e2c54 | 0x1e245c | 0x1dfa5c | 0x1df |
GetFileAttributesW | 0x0 | 0x5e2c58 | 0x1e2460 | 0x1dfa60 | 0x1ce |
GetEnvironmentVariableW | 0x0 | 0x5e2c5c | 0x1e2464 | 0x1dfa64 | 0x1c3 |
GetDateFormatW | 0x0 | 0x5e2c60 | 0x1e2468 | 0x1dfa68 | 0x1b0 |
GetCurrentThread | 0x0 | 0x5e2c64 | 0x1e246c | 0x1dfa6c | 0x1ac |
GetCPInfo | 0x0 | 0x5e2c68 | 0x1e2470 | 0x1dfa70 | 0x15b |
FreeResource | 0x0 | 0x5e2c6c | 0x1e2474 | 0x1dfa74 | 0x14f |
InterlockedIncrement | 0x0 | 0x5e2c70 | 0x1e2478 | 0x1dfa78 | 0x2c0 |
InterlockedExchangeAdd | 0x0 | 0x5e2c74 | 0x1e247c | 0x1dfa7c | 0x2be |
InterlockedDecrement | 0x0 | 0x5e2c78 | 0x1e2480 | 0x1dfa80 | 0x2bc |
FormatMessageW | 0x0 | 0x5e2c7c | 0x1e2484 | 0x1dfa84 | 0x148 |
FlushInstructionCache | 0x0 | 0x5e2c80 | 0x1e2488 | 0x1dfa88 | 0x142 |
FindResourceW | 0x0 | 0x5e2c84 | 0x1e248c | 0x1dfa8c | 0x139 |
FindNextFileW | 0x0 | 0x5e2c88 | 0x1e2490 | 0x1dfa90 | 0x130 |
FileTimeToLocalFileTime | 0x0 | 0x5e2c8c | 0x1e2494 | 0x1dfa94 | 0x10f |
FileTimeToDosDateTime | 0x0 | 0x5e2c90 | 0x1e2498 | 0x1dfa98 | 0x10e |
EnumCalendarInfoA | 0x0 | 0x5e2c94 | 0x1e249c | 0x1dfa9c | 0xda |
EnterCriticalSection | 0x0 | 0x5e2c98 | 0x1e24a0 | 0x1dfaa0 | 0xd9 |
DeleteFileW | 0x0 | 0x5e2c9c | 0x1e24a4 | 0x1dfaa4 | 0xc3 |
DeleteCriticalSection | 0x0 | 0x5e2ca0 | 0x1e24a8 | 0x1dfaa8 | 0xbe |
CreateProcessW | 0x0 | 0x5e2ca4 | 0x1e24ac | 0x1dfaac | 0x97 |
CreateFileW | 0x0 | 0x5e2ca8 | 0x1e24b0 | 0x1dfab0 | 0x7f |
CreateEventW | 0x0 | 0x5e2cac | 0x1e24b4 | 0x1dfab4 | 0x75 |
CreateDirectoryW | 0x0 | 0x5e2cb0 | 0x1e24b8 | 0x1dfab8 | 0x71 |
CompareStringA | 0x0 | 0x5e2cb4 | 0x1e24bc | 0x1dfabc | 0x52 |
GetModuleHandleA | 0x0 | 0x5e2cb8 | 0x1e24c0 | 0x1dfac0 | 0x1f6 |
LoadLibraryA | 0x0 | 0x5e2cbc | 0x1e24c4 | 0x1dfac4 | 0x2f1 |
VirtualAllocEx | 0x0 | 0x5e2cc0 | 0x1e24c8 | 0x1dfac8 | 0x455 |
USER32.dll (191)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ScreenToClient | 0x0 | 0x5e2cc8 | 0x1e24d0 | 0x1dfad0 | 0x254 |
ChangeDisplaySettingsExA | 0x0 | 0x5e2ccc | 0x1e24d4 | 0x1dfad4 | 0x23 |
GetTabbedTextExtentW | 0x0 | 0x5e2cd0 | 0x1e24d8 | 0x1dfad8 | 0x171 |
DdeImpersonateClient | 0x0 | 0x5e2cd4 | 0x1e24dc | 0x1dfadc | 0x7f |
VkKeyScanW | 0x0 | 0x5e2cd8 | 0x1e24e0 | 0x1dfae0 | 0x2f7 |
ScrollWindowEx | 0x0 | 0x5e2cdc | 0x1e24e4 | 0x1dfae4 | 0x258 |
EnumDisplaySettingsW | 0x0 | 0x5e2ce0 | 0x1e24e8 | 0x1dfae8 | 0xe3 |
MonitorFromRect | 0x0 | 0x5e2ce4 | 0x1e24ec | 0x1dfaec | 0x203 |
SetCaretBlinkTime | 0x0 | 0x5e2ce8 | 0x1e24f0 | 0x1dfaf0 | 0x268 |
MessageBeep | 0x0 | 0x5e2cec | 0x1e24f4 | 0x1dfaf4 | 0x1f7 |
ShowCursor | 0x0 | 0x5e2cf0 | 0x1e24f8 | 0x1dfaf8 | 0x2b3 |
OemToCharBuffW | 0x0 | 0x5e2cf4 | 0x1e24fc | 0x1dfafc | 0x20c |
CallWindowProcA | 0x0 | 0x5e2cf8 | 0x1e2500 | 0x1dfb00 | 0x1c |
WINNLSGetEnableStatus | 0x0 | 0x5e2cfc | 0x1e2504 | 0x1dfb04 | 0x2fa |
CloseClipboard | 0x0 | 0x5e2d00 | 0x1e2508 | 0x1dfb08 | 0x47 |
CreateAcceleratorTableW | 0x0 | 0x5e2d04 | 0x1e250c | 0x1dfb0c | 0x52 |
SetMenuInfo | 0x0 | 0x5e2d08 | 0x1e2510 | 0x1dfb10 | 0x282 |
DefFrameProcA | 0x0 | 0x5e2d0c | 0x1e2514 | 0x1dfb14 | 0x90 |
GetKeyboardType | 0x0 | 0x5e2d10 | 0x1e2518 | 0x1dfb18 | 0x137 |
LoadStringW | 0x0 | 0x5e2d14 | 0x1e251c | 0x1dfb1c | 0x1e4 |
MessageBoxA | 0x0 | 0x5e2d18 | 0x1e2520 | 0x1dfb20 | 0x1f8 |
CharNextW | 0x0 | 0x5e2d1c | 0x1e2524 | 0x1dfb24 | 0x2f |
CreateWindowExW | 0x0 | 0x5e2d20 | 0x1e2528 | 0x1dfb28 | 0x68 |
WindowFromPoint | 0x0 | 0x5e2d24 | 0x1e252c | 0x1dfb2c | 0x303 |
WaitMessage | 0x0 | 0x5e2d28 | 0x1e2530 | 0x1dfb30 | 0x2fd |
UpdateWindow | 0x0 | 0x5e2d2c | 0x1e2534 | 0x1dfb34 | 0x2e9 |
UnregisterClassW | 0x0 | 0x5e2d30 | 0x1e2538 | 0x1dfb38 | 0x2df |
UnhookWindowsHookEx | 0x0 | 0x5e2d34 | 0x1e253c | 0x1dfb3c | 0x2d9 |
TranslateMessage | 0x0 | 0x5e2d38 | 0x1e2540 | 0x1dfb40 | 0x2d5 |
TranslateMDISysAccel | 0x0 | 0x5e2d3c | 0x1e2544 | 0x1dfb44 | 0x2d4 |
TrackPopupMenu | 0x0 | 0x5e2d40 | 0x1e2548 | 0x1dfb48 | 0x2cf |
SystemParametersInfoW | 0x0 | 0x5e2d44 | 0x1e254c | 0x1dfb4c | 0x2c5 |
ShowWindow | 0x0 | 0x5e2d48 | 0x1e2550 | 0x1dfb50 | 0x2b8 |
ShowScrollBar | 0x0 | 0x5e2d4c | 0x1e2554 | 0x1dfb54 | 0x2b5 |
ShowOwnedPopups | 0x0 | 0x5e2d50 | 0x1e2558 | 0x1dfb58 | 0x2b4 |
SetWindowRgn | 0x0 | 0x5e2d54 | 0x1e255c | 0x1dfb5c | 0x2a8 |
SetWindowsHookExW | 0x0 | 0x5e2d58 | 0x1e2560 | 0x1dfb60 | 0x2b0 |
SetWindowTextW | 0x0 | 0x5e2d5c | 0x1e2564 | 0x1dfb64 | 0x2ac |
SetWindowPos | 0x0 | 0x5e2d60 | 0x1e2568 | 0x1dfb68 | 0x2a7 |
SetWindowPlacement | 0x0 | 0x5e2d64 | 0x1e256c | 0x1dfb6c | 0x2a6 |
SetWindowLongW | 0x0 | 0x5e2d68 | 0x1e2570 | 0x1dfb70 | 0x2a5 |
SetTimer | 0x0 | 0x5e2d6c | 0x1e2574 | 0x1dfb74 | 0x29e |
SetScrollRange | 0x0 | 0x5e2d70 | 0x1e2578 | 0x1dfb78 | 0x295 |
SetScrollPos | 0x0 | 0x5e2d74 | 0x1e257c | 0x1dfb7c | 0x294 |
SetScrollInfo | 0x0 | 0x5e2d78 | 0x1e2580 | 0x1dfb80 | 0x293 |
SetRect | 0x0 | 0x5e2d7c | 0x1e2584 | 0x1dfb84 | 0x291 |
SetPropW | 0x0 | 0x5e2d80 | 0x1e2588 | 0x1dfb88 | 0x290 |
SetParent | 0x0 | 0x5e2d84 | 0x1e258c | 0x1dfb8c | 0x289 |
SetMenuItemInfoW | 0x0 | 0x5e2d88 | 0x1e2590 | 0x1dfb90 | 0x285 |
SetMenu | 0x0 | 0x5e2d8c | 0x1e2594 | 0x1dfb94 | 0x27f |
SetForegroundWindow | 0x0 | 0x5e2d90 | 0x1e2598 | 0x1dfb98 | 0x27a |
SetFocus | 0x0 | 0x5e2d94 | 0x1e259c | 0x1dfb9c | 0x279 |
SetCursor | 0x0 | 0x5e2d98 | 0x1e25a0 | 0x1dfba0 | 0x270 |
SetClassLongW | 0x0 | 0x5e2d9c | 0x1e25a4 | 0x1dfba4 | 0x26b |
SetCapture | 0x0 | 0x5e2da0 | 0x1e25a8 | 0x1dfba8 | 0x267 |
SetActiveWindow | 0x0 | 0x5e2da4 | 0x1e25ac | 0x1dfbac | 0x266 |
SendMessageA | 0x0 | 0x5e2da8 | 0x1e25b0 | 0x1dfbb0 | 0x25e |
SendMessageW | 0x0 | 0x5e2dac | 0x1e25b4 | 0x1dfbb4 | 0x263 |
ScrollWindow | 0x0 | 0x5e2db0 | 0x1e25b8 | 0x1dfbb8 | 0x257 |
RemovePropW | 0x0 | 0x5e2db4 | 0x1e25bc | 0x1dfbbc | 0x250 |
RemoveMenu | 0x0 | 0x5e2db8 | 0x1e25c0 | 0x1dfbc0 | 0x24e |
ReleaseDC | 0x0 | 0x5e2dbc | 0x1e25c4 | 0x1dfbc4 | 0x24c |
ReleaseCapture | 0x0 | 0x5e2dc0 | 0x1e25c8 | 0x1dfbc8 | 0x24b |
RegisterWindowMessageW | 0x0 | 0x5e2dc4 | 0x1e25cc | 0x1dfbcc | 0x24a |
RegisterClipboardFormatW | 0x0 | 0x5e2dc8 | 0x1e25d0 | 0x1dfbd0 | 0x238 |
RegisterClassW | 0x0 | 0x5e2dcc | 0x1e25d4 | 0x1dfbd4 | 0x236 |
RedrawWindow | 0x0 | 0x5e2dd0 | 0x1e25d8 | 0x1dfbd8 | 0x232 |
PostQuitMessage | 0x0 | 0x5e2dd4 | 0x1e25dc | 0x1dfbdc | 0x220 |
PostMessageW | 0x0 | 0x5e2dd8 | 0x1e25e0 | 0x1dfbe0 | 0x21f |
PeekMessageA | 0x0 | 0x5e2ddc | 0x1e25e4 | 0x1dfbe4 | 0x21b |
PeekMessageW | 0x0 | 0x5e2de0 | 0x1e25e8 | 0x1dfbe8 | 0x21c |
OffsetRect | 0x0 | 0x5e2de4 | 0x1e25ec | 0x1dfbec | 0x20e |
MsgWaitForMultipleObjectsEx | 0x0 | 0x5e2de8 | 0x1e25f0 | 0x1dfbf0 | 0x207 |
MsgWaitForMultipleObjects | 0x0 | 0x5e2dec | 0x1e25f4 | 0x1dfbf4 | 0x206 |
MessageBoxW | 0x0 | 0x5e2df0 | 0x1e25f8 | 0x1dfbf8 | 0x1ff |
MapWindowPoints | 0x0 | 0x5e2df4 | 0x1e25fc | 0x1dfbfc | 0x1f3 |
MapVirtualKeyW | 0x0 | 0x5e2df8 | 0x1e2600 | 0x1dfc00 | 0x1f2 |
LoadKeyboardLayoutW | 0x0 | 0x5e2dfc | 0x1e2604 | 0x1dfc04 | 0x1dc |
LoadIconW | 0x0 | 0x5e2e00 | 0x1e2608 | 0x1dfc08 | 0x1d7 |
LoadCursorW | 0x0 | 0x5e2e04 | 0x1e260c | 0x1dfc0c | 0x1d5 |
LoadBitmapW | 0x0 | 0x5e2e08 | 0x1e2610 | 0x1dfc10 | 0x1d1 |
KillTimer | 0x0 | 0x5e2e0c | 0x1e2614 | 0x1dfc14 | 0x1cd |
IsZoomed | 0x0 | 0x5e2e10 | 0x1e2618 | 0x1dfc18 | 0x1cc |
IsWindowVisible | 0x0 | 0x5e2e14 | 0x1e261c | 0x1dfc1c | 0x1ca |
IsWindowUnicode | 0x0 | 0x5e2e18 | 0x1e2620 | 0x1dfc20 | 0x1c9 |
IsWindowEnabled | 0x0 | 0x5e2e1c | 0x1e2624 | 0x1dfc24 | 0x1c6 |
IsWindow | 0x0 | 0x5e2e20 | 0x1e2628 | 0x1dfc28 | 0x1c5 |
IsIconic | 0x0 | 0x5e2e24 | 0x1e262c | 0x1dfc2c | 0x1bd |
IsDialogMessageA | 0x0 | 0x5e2e28 | 0x1e2630 | 0x1dfc30 | 0x1b8 |
IsDialogMessageW | 0x0 | 0x5e2e2c | 0x1e2634 | 0x1dfc34 | 0x1b9 |
IsChild | 0x0 | 0x5e2e30 | 0x1e2638 | 0x1dfc38 | 0x1b5 |
InvalidateRect | 0x0 | 0x5e2e34 | 0x1e263c | 0x1dfc3c | 0x1aa |
IntersectRect | 0x0 | 0x5e2e38 | 0x1e2640 | 0x1dfc40 | 0x1a9 |
InsertMenuItemW | 0x0 | 0x5e2e3c | 0x1e2644 | 0x1dfc44 | 0x1a5 |
InsertMenuW | 0x0 | 0x5e2e40 | 0x1e2648 | 0x1dfc48 | 0x1a6 |
InflateRect | 0x0 | 0x5e2e44 | 0x1e264c | 0x1dfc4c | 0x1a1 |
GetWindowThreadProcessId | 0x0 | 0x5e2e48 | 0x1e2650 | 0x1dfc50 | 0x190 |
GetWindowTextW | 0x0 | 0x5e2e4c | 0x1e2654 | 0x1dfc54 | 0x18f |
GetWindowRect | 0x0 | 0x5e2e50 | 0x1e2658 | 0x1dfc58 | 0x188 |
GetWindowPlacement | 0x0 | 0x5e2e54 | 0x1e265c | 0x1dfc5c | 0x187 |
GetWindowLongW | 0x0 | 0x5e2e58 | 0x1e2660 | 0x1dfc60 | 0x182 |
GetWindowDC | 0x0 | 0x5e2e5c | 0x1e2664 | 0x1dfc64 | 0x17f |
GetTopWindow | 0x0 | 0x5e2e60 | 0x1e2668 | 0x1dfc68 | 0x175 |
GetSystemMetrics | 0x0 | 0x5e2e64 | 0x1e266c | 0x1dfc6c | 0x16f |
GetSystemMenu | 0x0 | 0x5e2e68 | 0x1e2670 | 0x1dfc70 | 0x16e |
GetSysColorBrush | 0x0 | 0x5e2e6c | 0x1e2674 | 0x1dfc74 | 0x16d |
GetSysColor | 0x0 | 0x5e2e70 | 0x1e2678 | 0x1dfc78 | 0x16c |
GetSubMenu | 0x0 | 0x5e2e74 | 0x1e267c | 0x1dfc7c | 0x16b |
GetScrollRange | 0x0 | 0x5e2e78 | 0x1e2680 | 0x1dfc80 | 0x168 |
GetScrollPos | 0x0 | 0x5e2e7c | 0x1e2684 | 0x1dfc84 | 0x167 |
GetScrollInfo | 0x0 | 0x5e2e80 | 0x1e2688 | 0x1dfc88 | 0x166 |
GetPropW | 0x0 | 0x5e2e84 | 0x1e268c | 0x1dfc8c | 0x15c |
GetParent | 0x0 | 0x5e2e88 | 0x1e2690 | 0x1dfc90 | 0x155 |
GetWindow | 0x0 | 0x5e2e8c | 0x1e2694 | 0x1dfc94 | 0x17d |
GetMessagePos | 0x0 | 0x5e2e90 | 0x1e2698 | 0x1dfc98 | 0x14c |
GetMenuStringW | 0x0 | 0x5e2e94 | 0x1e269c | 0x1dfc9c | 0x149 |
GetMenuState | 0x0 | 0x5e2e98 | 0x1e26a0 | 0x1dfca0 | 0x147 |
GetMenuItemInfoW | 0x0 | 0x5e2e9c | 0x1e26a4 | 0x1dfca4 | 0x145 |
GetMenuItemID | 0x0 | 0x5e2ea0 | 0x1e26a8 | 0x1dfca8 | 0x143 |
GetMenuItemCount | 0x0 | 0x5e2ea4 | 0x1e26ac | 0x1dfcac | 0x142 |
GetMenu | 0x0 | 0x5e2ea8 | 0x1e26b0 | 0x1dfcb0 | 0x13c |
GetLastActivePopup | 0x0 | 0x5e2eac | 0x1e26b4 | 0x1dfcb4 | 0x138 |
GetKeyboardState | 0x0 | 0x5e2eb0 | 0x1e26b8 | 0x1dfcb8 | 0x136 |
GetKeyboardLayoutNameW | 0x0 | 0x5e2eb4 | 0x1e26bc | 0x1dfcbc | 0x135 |
GetKeyboardLayoutList | 0x0 | 0x5e2eb8 | 0x1e26c0 | 0x1dfcc0 | 0x133 |
GetKeyboardLayout | 0x0 | 0x5e2ebc | 0x1e26c4 | 0x1dfcc4 | 0x132 |
GetKeyState | 0x0 | 0x5e2ec0 | 0x1e26c8 | 0x1dfcc8 | 0x131 |
GetKeyNameTextW | 0x0 | 0x5e2ec4 | 0x1e26cc | 0x1dfccc | 0x130 |
GetIconInfo | 0x0 | 0x5e2ec8 | 0x1e26d0 | 0x1dfcd0 | 0x128 |
GetForegroundWindow | 0x0 | 0x5e2ecc | 0x1e26d4 | 0x1dfcd4 | 0x125 |
GetFocus | 0x0 | 0x5e2ed0 | 0x1e26d8 | 0x1dfcd8 | 0x124 |
GetDesktopWindow | 0x0 | 0x5e2ed4 | 0x1e26dc | 0x1dfcdc | 0x11c |
GetDCEx | 0x0 | 0x5e2ed8 | 0x1e26e0 | 0x1dfce0 | 0x11b |
GetDC | 0x0 | 0x5e2edc | 0x1e26e4 | 0x1dfce4 | 0x11a |
GetCursorPos | 0x0 | 0x5e2ee0 | 0x1e26e8 | 0x1dfce8 | 0x119 |
GetCursor | 0x0 | 0x5e2ee4 | 0x1e26ec | 0x1dfcec | 0x116 |
GetClipboardData | 0x0 | 0x5e2ee8 | 0x1e26f0 | 0x1dfcf0 | 0x10f |
GetClientRect | 0x0 | 0x5e2eec | 0x1e26f4 | 0x1dfcf4 | 0x10d |
GetClassLongW | 0x0 | 0x5e2ef0 | 0x1e26f8 | 0x1dfcf8 | 0x109 |
GetClassInfoW | 0x0 | 0x5e2ef4 | 0x1e26fc | 0x1dfcfc | 0x107 |
GetCapture | 0x0 | 0x5e2ef8 | 0x1e2700 | 0x1dfd00 | 0x101 |
GetActiveWindow | 0x0 | 0x5e2efc | 0x1e2704 | 0x1dfd04 | 0xf9 |
FrameRect | 0x0 | 0x5e2f00 | 0x1e2708 | 0x1dfd08 | 0xf6 |
FindWindowExW | 0x0 | 0x5e2f04 | 0x1e270c | 0x1dfd0c | 0xf2 |
FindWindowW | 0x0 | 0x5e2f08 | 0x1e2710 | 0x1dfd10 | 0xf3 |
FillRect | 0x0 | 0x5e2f0c | 0x1e2714 | 0x1dfd14 | 0xef |
EnumWindows | 0x0 | 0x5e2f10 | 0x1e2718 | 0x1dfd18 | 0xeb |
EnumThreadWindows | 0x0 | 0x5e2f14 | 0x1e271c | 0x1dfd1c | 0xe8 |
EnumChildWindows | 0x0 | 0x5e2f18 | 0x1e2720 | 0x1dfd20 | 0xd8 |
EndPaint | 0x0 | 0x5e2f1c | 0x1e2724 | 0x1dfd24 | 0xd5 |
EnableWindow | 0x0 | 0x5e2f20 | 0x1e2728 | 0x1dfd28 | 0xd1 |
EnableScrollBar | 0x0 | 0x5e2f24 | 0x1e272c | 0x1dfd2c | 0xd0 |
EnableMenuItem | 0x0 | 0x5e2f28 | 0x1e2730 | 0x1dfd30 | 0xcf |
DrawTextExW | 0x0 | 0x5e2f2c | 0x1e2734 | 0x1dfd34 | 0xc7 |
DrawTextW | 0x0 | 0x5e2f30 | 0x1e2738 | 0x1dfd38 | 0xc8 |
DrawMenuBar | 0x0 | 0x5e2f34 | 0x1e273c | 0x1dfd3c | 0xc1 |
DrawIconEx | 0x0 | 0x5e2f38 | 0x1e2740 | 0x1dfd40 | 0xc0 |
DrawIcon | 0x0 | 0x5e2f3c | 0x1e2744 | 0x1dfd44 | 0xbf |
DrawFrameControl | 0x0 | 0x5e2f40 | 0x1e2748 | 0x1dfd48 | 0xbe |
DrawEdge | 0x0 | 0x5e2f44 | 0x1e274c | 0x1dfd4c | 0xbb |
DispatchMessageA | 0x0 | 0x5e2f48 | 0x1e2750 | 0x1dfd50 | 0xa8 |
DispatchMessageW | 0x0 | 0x5e2f4c | 0x1e2754 | 0x1dfd54 | 0xa9 |
DestroyWindow | 0x0 | 0x5e2f50 | 0x1e2758 | 0x1dfd58 | 0xa0 |
DestroyMenu | 0x0 | 0x5e2f54 | 0x1e275c | 0x1dfd5c | 0x9e |
DestroyIcon | 0x0 | 0x5e2f58 | 0x1e2760 | 0x1dfd60 | 0x9d |
DestroyCursor | 0x0 | 0x5e2f5c | 0x1e2764 | 0x1dfd64 | 0x9c |
DeleteMenu | 0x0 | 0x5e2f60 | 0x1e2768 | 0x1dfd68 | 0x98 |
DefWindowProcW | 0x0 | 0x5e2f64 | 0x1e276c | 0x1dfd6c | 0x96 |
DefMDIChildProcW | 0x0 | 0x5e2f68 | 0x1e2770 | 0x1dfd70 | 0x93 |
DefFrameProcW | 0x0 | 0x5e2f6c | 0x1e2774 | 0x1dfd74 | 0x91 |
CreatePopupMenu | 0x0 | 0x5e2f70 | 0x1e2778 | 0x1dfd78 | 0x65 |
CreateMenu | 0x0 | 0x5e2f74 | 0x1e277c | 0x1dfd7c | 0x64 |
CreateIcon | 0x0 | 0x5e2f78 | 0x1e2780 | 0x1dfd80 | 0x5e |
ClientToScreen | 0x0 | 0x5e2f7c | 0x1e2784 | 0x1dfd84 | 0x45 |
CheckMenuItem | 0x0 | 0x5e2f80 | 0x1e2788 | 0x1dfd88 | 0x3d |
CharUpperBuffW | 0x0 | 0x5e2f84 | 0x1e278c | 0x1dfd8c | 0x39 |
CharToOemW | 0x0 | 0x5e2f88 | 0x1e2790 | 0x1dfd90 | 0x36 |
CharLowerBuffW | 0x0 | 0x5e2f8c | 0x1e2794 | 0x1dfd94 | 0x2b |
CharLowerW | 0x0 | 0x5e2f90 | 0x1e2798 | 0x1dfd98 | 0x2c |
CallWindowProcW | 0x0 | 0x5e2f94 | 0x1e279c | 0x1dfd9c | 0x1d |
CallNextHookEx | 0x0 | 0x5e2f98 | 0x1e27a0 | 0x1dfda0 | 0x1b |
BeginPaint | 0x0 | 0x5e2f9c | 0x1e27a4 | 0x1dfda4 | 0xe |
AdjustWindowRectEx | 0x0 | 0x5e2fa0 | 0x1e27a8 | 0x1dfda8 | 0x3 |
ActivateKeyboardLayout | 0x0 | 0x5e2fa4 | 0x1e27ac | 0x1dfdac | 0x0 |
DrawTextA | 0x0 | 0x5e2fa8 | 0x1e27b0 | 0x1dfdb0 | 0xc5 |
DefWindowProcA | 0x0 | 0x5e2fac | 0x1e27b4 | 0x1dfdb4 | 0x95 |
LoadIconA | 0x0 | 0x5e2fb0 | 0x1e27b8 | 0x1dfdb8 | 0x1d6 |
LoadCursorA | 0x0 | 0x5e2fb4 | 0x1e27bc | 0x1dfdbc | 0x1d2 |
GetDialogBaseUnits | 0x0 | 0x5e2fb8 | 0x1e27c0 | 0x1dfdc0 | 0x11d |
OemKeyScan | 0x0 | 0x5e2fbc | 0x1e27c4 | 0x1dfdc4 | 0x209 |
WindowFromDC | 0x0 | 0x5e2fc0 | 0x1e27c8 | 0x1dfdc8 | 0x301 |
GDI32.dll (87)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GdiSetBatchLimit | 0x0 | 0x5e2fc8 | 0x1e27d0 | 0x1dfdd0 | 0x185 |
ScaleViewportExtEx | 0x0 | 0x5e2fcc | 0x1e27d4 | 0x1dfdd4 | 0x258 |
GetEUDCTimeStampExW | 0x0 | 0x5e2fd0 | 0x1e27d8 | 0x1dfdd8 | 0x1b9 |
EngDeleteClip | 0x0 | 0x5e2fd4 | 0x1e27dc | 0x1dfddc | 0xec |
GetNearestPaletteIndex | 0x0 | 0x5e2fd8 | 0x1e27e0 | 0x1dfde0 | 0x1de |
GetCharacterPlacementW | 0x0 | 0x5e2fdc | 0x1e27e4 | 0x1dfde4 | 0x1a9 |
CreateBrushIndirect | 0x0 | 0x5e2fe0 | 0x1e27e8 | 0x1dfde8 | 0x2a |
PlayEnhMetaFile | 0x0 | 0x5e2fe4 | 0x1e27ec | 0x1dfdec | 0x230 |
CreateColorSpaceW | 0x0 | 0x5e2fe8 | 0x1e27f0 | 0x1dfdf0 | 0x2c |
GdiPlayDCScript | 0x0 | 0x5e2fec | 0x1e27f4 | 0x1dfdf4 | 0x176 |
GetCharABCWidthsI | 0x0 | 0x5e2ff0 | 0x1e27f8 | 0x1dfdf8 | 0x19e |
Arc | 0x0 | 0x5e2ff4 | 0x1e27fc | 0x1dfdfc | 0xb |
EngCreatePalette | 0x0 | 0x5e2ff8 | 0x1e2800 | 0x1dfe00 | 0xea |
GetPolyFillMode | 0x0 | 0x5e2ffc | 0x1e2804 | 0x1dfe04 | 0x1ed |
GetGlyphOutlineA | 0x0 | 0x5e3000 | 0x1e2808 | 0x1dfe08 | 0x1ca |
UnrealizeObject | 0x0 | 0x5e3004 | 0x1e280c | 0x1dfe0c | 0x2a3 |
StretchDIBits | 0x0 | 0x5e3008 | 0x1e2810 | 0x1dfe10 | 0x29b |
StretchBlt | 0x0 | 0x5e300c | 0x1e2814 | 0x1dfe14 | 0x29a |
SetWindowOrgEx | 0x0 | 0x5e3010 | 0x1e2818 | 0x1dfe18 | 0x294 |
SetWinMetaFileBits | 0x0 | 0x5e3014 | 0x1e281c | 0x1dfe1c | 0x292 |
SetViewportOrgEx | 0x0 | 0x5e3018 | 0x1e2820 | 0x1dfe20 | 0x290 |
SetTextColor | 0x0 | 0x5e301c | 0x1e2824 | 0x1dfe24 | 0x28d |
SetStretchBltMode | 0x0 | 0x5e3020 | 0x1e2828 | 0x1dfe28 | 0x289 |
SetROP2 | 0x0 | 0x5e3024 | 0x1e282c | 0x1dfe2c | 0x286 |
SetPixel | 0x0 | 0x5e3028 | 0x1e2830 | 0x1dfe30 | 0x282 |
SetEnhMetaFileBits | 0x0 | 0x5e302c | 0x1e2834 | 0x1dfe34 | 0x272 |
SetDIBColorTable | 0x0 | 0x5e3030 | 0x1e2838 | 0x1dfe38 | 0x26e |
SetBrushOrgEx | 0x0 | 0x5e3034 | 0x1e283c | 0x1dfe3c | 0x269 |
SetBkMode | 0x0 | 0x5e3038 | 0x1e2840 | 0x1dfe40 | 0x266 |
SetBkColor | 0x0 | 0x5e303c | 0x1e2844 | 0x1dfe44 | 0x265 |
SelectPalette | 0x0 | 0x5e3040 | 0x1e2848 | 0x1dfe48 | 0x25f |
SelectObject | 0x0 | 0x5e3044 | 0x1e284c | 0x1dfe4c | 0x25e |
SaveDC | 0x0 | 0x5e3048 | 0x1e2850 | 0x1dfe50 | 0x257 |
RestoreDC | 0x0 | 0x5e304c | 0x1e2854 | 0x1dfe54 | 0x250 |
ResizePalette | 0x0 | 0x5e3050 | 0x1e2858 | 0x1dfe58 | 0x24f |
Rectangle | 0x0 | 0x5e3054 | 0x1e285c | 0x1dfe5c | 0x246 |
RectVisible | 0x0 | 0x5e3058 | 0x1e2860 | 0x1dfe60 | 0x245 |
RealizePalette | 0x0 | 0x5e305c | 0x1e2864 | 0x1dfe64 | 0x243 |
Polyline | 0x0 | 0x5e3060 | 0x1e2868 | 0x1dfe68 | 0x23e |
PatBlt | 0x0 | 0x5e3064 | 0x1e286c | 0x1dfe6c | 0x22d |
MoveToEx | 0x0 | 0x5e3068 | 0x1e2870 | 0x1dfe70 | 0x221 |
MaskBlt | 0x0 | 0x5e306c | 0x1e2874 | 0x1dfe74 | 0x21e |
LineTo | 0x0 | 0x5e3070 | 0x1e2878 | 0x1dfe78 | 0x21d |
IntersectClipRect | 0x0 | 0x5e3074 | 0x1e287c | 0x1dfe7c | 0x217 |
GetWindowOrgEx | 0x0 | 0x5e3078 | 0x1e2880 | 0x1dfe80 | 0x213 |
GetWinMetaFileBits | 0x0 | 0x5e307c | 0x1e2884 | 0x1dfe84 | 0x211 |
GetTextMetricsW | 0x0 | 0x5e3080 | 0x1e2888 | 0x1dfe88 | 0x20d |
GetTextExtentPoint32W | 0x0 | 0x5e3084 | 0x1e288c | 0x1dfe8c | 0x205 |
GetSystemPaletteEntries | 0x0 | 0x5e3088 | 0x1e2890 | 0x1dfe90 | 0x1f9 |
GetStockObject | 0x0 | 0x5e308c | 0x1e2894 | 0x1dfe94 | 0x1f4 |
GetRgnBox | 0x0 | 0x5e3090 | 0x1e2898 | 0x1dfe98 | 0x1f3 |
GetPixel | 0x0 | 0x5e3094 | 0x1e289c | 0x1dfe9c | 0x1eb |
GetPaletteEntries | 0x0 | 0x5e3098 | 0x1e28a0 | 0x1dfea0 | 0x1e7 |
GetObjectType | 0x0 | 0x5e309c | 0x1e28a4 | 0x1dfea4 | 0x1e3 |
GetObjectW | 0x0 | 0x5e30a0 | 0x1e28a8 | 0x1dfea8 | 0x1e4 |
GetEnhMetaFilePaletteEntries | 0x0 | 0x5e30a4 | 0x1e28ac | 0x1dfeac | 0x1bf |
GetEnhMetaFileHeader | 0x0 | 0x5e30a8 | 0x1e28b0 | 0x1dfeb0 | 0x1be |
GetEnhMetaFileBits | 0x0 | 0x5e30ac | 0x1e28b4 | 0x1dfeb4 | 0x1bb |
GetDeviceCaps | 0x0 | 0x5e30b0 | 0x1e28b8 | 0x1dfeb8 | 0x1b5 |
GetDIBits | 0x0 | 0x5e30b4 | 0x1e28bc | 0x1dfebc | 0x1b4 |
GetDIBColorTable | 0x0 | 0x5e30b8 | 0x1e28c0 | 0x1dfec0 | 0x1b3 |
GetDCOrgEx | 0x0 | 0x5e30bc | 0x1e28c4 | 0x1dfec4 | 0x1b1 |
GetCurrentPositionEx | 0x0 | 0x5e30c0 | 0x1e28c8 | 0x1dfec8 | 0x1af |
GetCurrentObject | 0x0 | 0x5e30c4 | 0x1e28cc | 0x1dfecc | 0x1ae |
GetClipBox | 0x0 | 0x5e30c8 | 0x1e28d0 | 0x1dfed0 | 0x1aa |
GetBrushOrgEx | 0x0 | 0x5e30cc | 0x1e28d4 | 0x1dfed4 | 0x197 |
GetBitmapBits | 0x0 | 0x5e30d0 | 0x1e28d8 | 0x1dfed8 | 0x191 |
FrameRgn | 0x0 | 0x5e30d4 | 0x1e28dc | 0x1dfedc | 0x132 |
ExcludeClipRect | 0x0 | 0x5e30d8 | 0x1e28e0 | 0x1dfee0 | 0x11c |
DeleteObject | 0x0 | 0x5e30dc | 0x1e28e4 | 0x1dfee4 | 0xd0 |
DeleteEnhMetaFile | 0x0 | 0x5e30e0 | 0x1e28e8 | 0x1dfee8 | 0xce |
DeleteDC | 0x0 | 0x5e30e4 | 0x1e28ec | 0x1dfeec | 0xcd |
CreateSolidBrush | 0x0 | 0x5e30e8 | 0x1e28f0 | 0x1dfef0 | 0x52 |
CreateRoundRectRgn | 0x0 | 0x5e30ec | 0x1e28f4 | 0x1dfef4 | 0x4f |
CreateRectRgn | 0x0 | 0x5e30f0 | 0x1e28f8 | 0x1dfef8 | 0x4d |
CreatePenIndirect | 0x0 | 0x5e30f4 | 0x1e28fc | 0x1dfefc | 0x4a |
CreatePalette | 0x0 | 0x5e30f8 | 0x1e2900 | 0x1dff00 | 0x47 |
CreateHalftonePalette | 0x0 | 0x5e30fc | 0x1e2904 | 0x1dff04 | 0x40 |
CreateFontIndirectW | 0x0 | 0x5e3100 | 0x1e2908 | 0x1dff08 | 0x3e |
CreateDIBitmap | 0x0 | 0x5e3104 | 0x1e290c | 0x1dff0c | 0x34 |
CreateDIBSection | 0x0 | 0x5e3108 | 0x1e2910 | 0x1dff10 | 0x33 |
CreateCompatibleDC | 0x0 | 0x5e310c | 0x1e2914 | 0x1dff14 | 0x2e |
CreateCompatibleBitmap | 0x0 | 0x5e3110 | 0x1e2918 | 0x1dff18 | 0x2d |
CreateBitmap | 0x0 | 0x5e3114 | 0x1e291c | 0x1dff1c | 0x28 |
CopyEnhMetaFileW | 0x0 | 0x5e3118 | 0x1e2920 | 0x1dff20 | 0x25 |
BitBlt | 0x0 | 0x5e311c | 0x1e2924 | 0x1dff24 | 0x12 |
GetEnhMetaFileW | 0x0 | 0x5e3120 | 0x1e2928 | 0x1dff28 | 0x1c1 |
ADVAPI32.dll (17)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExW | 0x0 | 0x5e3128 | 0x1e2930 | 0x1dff30 | 0x268 |
RegOpenKeyExW | 0x0 | 0x5e312c | 0x1e2934 | 0x1dff34 | 0x25b |
RegCloseKey | 0x0 | 0x5e3130 | 0x1e2938 | 0x1dff38 | 0x22a |
RegFlushKey | 0x0 | 0x5e3134 | 0x1e293c | 0x1dff3c | 0x24d |
RegCreateKeyExW | 0x0 | 0x5e3138 | 0x1e2940 | 0x1dff40 | 0x233 |
OpenProcessToken | 0x0 | 0x5e313c | 0x1e2944 | 0x1dff44 | 0x1f1 |
GetUserNameW | 0x0 | 0x5e3140 | 0x1e2948 | 0x1dff48 | 0x15f |
CreateProcessAsUserW | 0x0 | 0x5e3144 | 0x1e294c | 0x1dff4c | 0x78 |
UnlockServiceDatabase | 0x0 | 0x5e3148 | 0x1e2950 | 0x1dff50 | 0x2f9 |
StartServiceW | 0x0 | 0x5e314c | 0x1e2954 | 0x1dff54 | 0x2c3 |
QueryServiceStatus | 0x0 | 0x5e3150 | 0x1e2958 | 0x1dff58 | 0x222 |
QueryServiceLockStatusW | 0x0 | 0x5e3154 | 0x1e295c | 0x1dff5c | 0x220 |
OpenServiceW | 0x0 | 0x5e3158 | 0x1e2960 | 0x1dff60 | 0x1f5 |
OpenSCManagerW | 0x0 | 0x5e315c | 0x1e2964 | 0x1dff64 | 0x1f3 |
LockServiceDatabase | 0x0 | 0x5e3160 | 0x1e2968 | 0x1dff68 | 0x182 |
CloseServiceHandle | 0x0 | 0x5e3164 | 0x1e296c | 0x1dff6c | 0x53 |
ChangeServiceConfigW | 0x0 | 0x5e3168 | 0x1e2970 | 0x1dff70 | 0x4b |
SHELL32.dll (21)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHChangeNotify | 0x0 | 0x5e3170 | 0x1e2978 | 0x1dff78 | 0x7c |
ExtractIconExA | 0x0 | 0x5e3174 | 0x1e297c | 0x1dff7c | 0x2a |
SHGetSpecialFolderPathA | 0x0 | 0x5e3178 | 0x1e2980 | 0x1dff80 | 0xd9 |
ShellExecuteEx | 0x0 | 0x5e317c | 0x1e2984 | 0x1dff84 | 0x115 |
ShellHookProc | 0x0 | 0x5e3180 | 0x1e2988 | 0x1dff88 | 0x119 |
SHGetIconOverlayIndexW | 0x0 | 0x5e3184 | 0x1e298c | 0x1dff8c | 0xc3 |
SHGetSettings | 0x0 | 0x5e3188 | 0x1e2990 | 0x1dff90 | 0xd7 |
SHAppBarMessage | 0x0 | 0x5e318c | 0x1e2994 | 0x1dff94 | 0x70 |
SHAddToRecentDocs | 0x0 | 0x5e3190 | 0x1e2998 | 0x1dff98 | 0x6e |
SHLoadInProc | 0x0 | 0x5e3194 | 0x1e299c | 0x1dff9c | 0xe7 |
Shell_NotifyIcon | 0x0 | 0x5e3198 | 0x1e29a0 | 0x1dffa0 | 0x121 |
DoEnvironmentSubstW | 0x0 | 0x5e319c | 0x1e29a4 | 0x1dffa4 | 0x1a |
ExtractAssociatedIconExW | 0x0 | 0x5e31a0 | 0x1e29a8 | 0x1dffa8 | 0x26 |
SHGetDesktopFolder | 0x0 | 0x5e31a4 | 0x1e29ac | 0x1dffac | 0xb3 |
SHCreateProcessAsUserW | 0x0 | 0x5e31a8 | 0x1e29b0 | 0x1dffb0 | 0x92 |
SHFileOperationW | 0x0 | 0x5e31ac | 0x1e29b4 | 0x1dffb4 | 0xa9 |
SHPathPrepareForWriteW | 0x0 | 0x5e31b0 | 0x1e29b8 | 0x1dffb8 | 0xf1 |
DoEnvironmentSubstA | 0x0 | 0x5e31b4 | 0x1e29bc | 0x1dffbc | 0x19 |
SHGetFileInfo | 0x0 | 0x5e31b8 | 0x1e29c0 | 0x1dffc0 | 0xb8 |
ShellExecuteW | 0x0 | 0x5e31bc | 0x1e29c4 | 0x1dffc4 | 0x118 |
SHGetSpecialFolderPathW | 0x0 | 0x5e31c0 | 0x1e29c8 | 0x1dffc8 | 0xda |
SHLWAPI.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StrRChrW | 0x0 | 0x5e31c8 | 0x1e29d0 | 0x1dffd0 | 0x136 |
StrChrA | 0x0 | 0x5e31cc | 0x1e29d4 | 0x1dffd4 | 0x10d |
StrCmpNIA | 0x0 | 0x5e31d0 | 0x1e29d8 | 0x1dffd8 | 0x11c |
StrRStrIW | 0x0 | 0x5e31d4 | 0x1e29dc | 0x1dffdc | 0x138 |
StrStrIA | 0x0 | 0x5e31d8 | 0x1e29e0 | 0x1dffe0 | 0x141 |
StrStrA | 0x0 | 0x5e31dc | 0x1e29e4 | 0x1dffe4 | 0x140 |
StrStrIW | 0x0 | 0x5e31e0 | 0x1e29e8 | 0x1dffe8 | 0x142 |
COMCTL32.dll (27)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InitializeFlatSB | 0x0 | 0x5e31e8 | 0x1e29f0 | 0x1dfff0 | 0x7c |
FlatSB_SetScrollProp | 0x0 | 0x5e31ec | 0x1e29f4 | 0x1dfff4 | 0x44 |
FlatSB_SetScrollPos | 0x0 | 0x5e31f0 | 0x1e29f8 | 0x1dfff8 | 0x43 |
FlatSB_SetScrollInfo | 0x0 | 0x5e31f4 | 0x1e29fc | 0x1dfffc | 0x42 |
FlatSB_GetScrollPos | 0x0 | 0x5e31f8 | 0x1e2a00 | 0x1e0000 | 0x3f |
FlatSB_GetScrollInfo | 0x0 | 0x5e31fc | 0x1e2a04 | 0x1e0004 | 0x3e |
_TrackMouseEvent | 0x0 | 0x5e3200 | 0x1e2a08 | 0x1e0008 | 0x91 |
ImageList_SetIconSize | 0x0 | 0x5e3204 | 0x1e2a0c | 0x1e000c | 0x74 |
ImageList_GetIconSize | 0x0 | 0x5e3208 | 0x1e2a10 | 0x1e0010 | 0x62 |
ImageList_Write | 0x0 | 0x5e320c | 0x1e2a14 | 0x1e0014 | 0x77 |
ImageList_Read | 0x0 | 0x5e3210 | 0x1e2a18 | 0x1e0018 | 0x6a |
ImageList_GetDragImage | 0x0 | 0x5e3214 | 0x1e2a1c | 0x1e001c | 0x5f |
ImageList_DragShowNolock | 0x0 | 0x5e3218 | 0x1e2a20 | 0x1e0020 | 0x58 |
ImageList_DragMove | 0x0 | 0x5e321c | 0x1e2a24 | 0x1e0024 | 0x57 |
ImageList_DragLeave | 0x0 | 0x5e3220 | 0x1e2a28 | 0x1e0028 | 0x56 |
ImageList_DragEnter | 0x0 | 0x5e3224 | 0x1e2a2c | 0x1e002c | 0x55 |
ImageList_EndDrag | 0x0 | 0x5e3228 | 0x1e2a30 | 0x1e0030 | 0x5d |
ImageList_BeginDrag | 0x0 | 0x5e322c | 0x1e2a34 | 0x1e0034 | 0x50 |
ImageList_Remove | 0x0 | 0x5e3230 | 0x1e2a38 | 0x1e0038 | 0x6c |
ImageList_DrawEx | 0x0 | 0x5e3234 | 0x1e2a3c | 0x1e003c | 0x5a |
ImageList_GetBkColor | 0x0 | 0x5e3238 | 0x1e2a40 | 0x1e0040 | 0x5e |
ImageList_SetBkColor | 0x0 | 0x5e323c | 0x1e2a44 | 0x1e0044 | 0x70 |
ImageList_Add | 0x0 | 0x5e3240 | 0x1e2a48 | 0x1e0048 | 0x4d |
ImageList_SetImageCount | 0x0 | 0x5e3244 | 0x1e2a4c | 0x1e004c | 0x75 |
ImageList_GetImageCount | 0x0 | 0x5e3248 | 0x1e2a50 | 0x1e0050 | 0x63 |
ImageList_Destroy | 0x0 | 0x5e324c | 0x1e2a54 | 0x1e0054 | 0x54 |
ImageList_Create | 0x0 | 0x5e3250 | 0x1e2a58 | 0x1e0058 | 0x53 |
WINMM.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PlaySoundA | 0x0 | 0x5e3258 | 0x1e2a60 | 0x1e0060 | 0x8 |
Digital Signatures (1)
»
Certificate: OHZOIPIFGKOQRMDDPN
»
Issued by | OHZOIPIFGKOQRMDDPN |
Country Name | - |
Valid From | 2020-06-23 09:20:34+00:00 |
Valid Until | 2039-12-31 23:59:59+00:00 |
Algorithm | sha1_rsa |
Serial Number | B7 FB D5 2D 89 51 68 8B 41 C6 54 47 53 C1 C5 26 |
Thumbprint | 57 E7 08 7E DF CF 2D F8 9A 95 B2 1C 39 27 9E BB FC E4 92 B4 |
Memory Dumps (24)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Relevant Image |
![]() |
32-bit | 0x005BE000 |
![]() |
![]() |
...
|
buffer | 1 | 0x01D90000 | 0x01E9DFFF | First Execution |
![]() |
32-bit | 0x01E9D3C0 |
![]() |
![]() |
...
|
buffer | 1 | 0x01D90000 | 0x01E9DFFF | Content Changed |
![]() |
32-bit | 0x01E9CD5D |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x0044BEE7 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x00484295 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x0047BE26 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x0047E81D |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x0041D3E0 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x00433F92 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x00401000 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x00402000 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x00404000 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x00405000 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x00437FED |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x0046B04E |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x0043AB1E |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x00439469 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x0040EE00 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x00418008 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x00409B10 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x00484880 |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x0047D0AC |
![]() |
![]() |
...
|
pnbkityyj8uba9a3.exe | 1 | 0x00400000 | 0x00604FFF | Content Changed |
![]() |
32-bit | 0x0041A60A |
![]() |
![]() |
...
|
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\5Ix4x Zrrz9.png.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\Ar1hxneqYeFE.png | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\Atg0ia0f-hvtA.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\Febsg R4M7-vEDd.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\fWfsEPEIPS5iQ.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\HCUglpPfaSUy_gxUzyc.wav.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\j6siW7.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\Pzx6fpsA9OXtuDBog.mkv.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\s_iuSMxQ_04.bmp.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\t3vvbT3ZQCdF3ub.ppt.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\uG00\BhEzfZlmrrK.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\uG00\FdgC GY6o3fHrP\CgXQHI.avi.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\uG00\FdgC GY6o3fHrP\mc1gKhG75xE.mp3.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\uG00\FdgC GY6o3fHrP\nXjzCF.bmp.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\uG00\FdgC GY6o3fHrP\Yz8WJ.docx.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\uG00\HY3y9IXb940.bmp.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\uG00\NosLIJ\a3JM2lKC0zUR5msr28U.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\uG00\NosLIJ\L_32iH2E.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\uG00\NosLIJ\qZaGEzFWiiE19.mkv.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\uG00\NosLIJ\RFaHkUAFPtP5wP.docx.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\uG00\NosLIJ\zMOh8tX1mVaoKiOQnxu.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\Uigc.mp3.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\V3iqiftW.bmp.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\wCOtT4JFLsfFLw.png.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\WDAESLQgZz xnDDuE.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\y-GJpZQRI3wx3NvVXSGv.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\yNS-T svTfTr\d6j1hSr02.gif.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\yNS-T svTfTr\kA05z9QMAzYA -g-3yr6.m4a.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\yNS-T svTfTr\RoCgO_mN.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\yqHNIwAE.wav.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\b8pwaJC0k-9-HuwLQ.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\bL_mXf2Ye-ldtQyCu6\07kXAuuAMixu86uY6.doc.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\bL_mXf2Ye-ldtQyCu6\8kPQy.doc.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\bL_mXf2Ye-ldtQyCu6\bGpbgVM\-T0KrQoR.ots | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\bL_mXf2Ye-ldtQyCu6\bGpbgVM\bN9-3J_jWBO HXCJ-KK.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\bL_mXf2Ye-ldtQyCu6\C2Wh3iSr_.pdf.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\bL_mXf2Ye-ldtQyCu6\GFcD7o7.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\bL_mXf2Ye-ldtQyCu6\KSlOZSLNqk QbkDDo.ots | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\bL_mXf2Ye-ldtQyCu6\QsLwtv1qo7XpxV.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\bL_mXf2Ye-ldtQyCu6\UNB0zZ8d9HiLdduoE.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\Dfo6us8cR1GLNk.pptx.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\eN852.pptx.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\JCexS3FbFGa12KkYoKn.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\JFJTNIsp.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\JPFExSoGUDHiFLf5Zy7.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\KTeLUNN0isUPmpZMn4.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\Lm2GtCMzmC AbL.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\OISOP4mu\4MBevd0TLoAyC9cJXL.pptx.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\OISOP4mu\gwl2r0_t8uB.ppt.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\OISOP4mu\I0Lw.csv.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\OISOP4mu\LiJ57y9OwxbPrYjN-.csv.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\OISOP4mu\LrfNXJIyxYL_Kg4.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\OISOP4mu\SGm0pYH.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\OISOP4mu\X-ril3U.xls.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\RDrtPUg2MduUfz-9Kh_.pptx.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\s3aLBgfepqUE.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\uXsb5Sxp.pptx.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\ZHCvSfI.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\2VyXqSCN.m4a.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\Jcmn7ldP.m4a.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\k6dgwz.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\NcOblAIBIjHqfx_In.m4a.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QDwF8pjoJkyS.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\XaIrtXt KPd.m4a.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\yq0Y9a.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\M7Cng.wav.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\pCY8LsS5WGiRguK.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\RTZJ0quFZh\hOVJDmAE_IKZ.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\RTZJ0quFZh\isbgMeOQ.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\RTZJ0quFZh\MZIIwgQ.wav.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\RTZJ0quFZh\o5sH1EH WslJcy kK6.wav.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\RTZJ0quFZh\wnlX-.wav.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\VuByEzYRn stgFhY22.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\Y_2V4.m4a.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\z tjdyv.m4a.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\_t3a_.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\16NSNmPd YHKAOc.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\-xfX9yd18Sqi.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\03UbPPcyl8pnQPTLaiM.png.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\48YeavRWSVG.bmp.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\4esMJ HDr1oVKAfJgJ.jpg.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\4uMBMGp6.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\bQLAhSvsk1xQ.png.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\EjF4v4tE9.png.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\gm_fpr.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\HTTVKr.gif.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\hvSxAZ0TpaYFt.gif.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\KGFKX4gJ.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\lnZNaNdd2scU0E5.gif.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\T8ElJEsSnY8.png.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\VPSpS-EdNJQKAtr.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\Y2v6l8M0FZe_PYDSvSd7.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\YBXGDZTiqfRSD5ydyxy.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\7 DGjT-oC.png.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\DB5bTjPW93bPO2GnuWew.png | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\eeqKXrNays-.gif.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\i2RelRpkwKphsC0Bvo6p.png.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\j_qua.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\mJPmBvnB_tB1IQ.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\Nf5C5C.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\Q1nXCy_WX.gif.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\qADOuF.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\qT1 jfyIjq_.gif.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\QVU_9QqqdGIFg.bmp.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\wyx5Ff.png | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\11sZTE9bc.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\dgT_.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\eTPyRR19_EY k7Js.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\MvIYz2iK.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\n1P1z hL3u3T.mp4.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\SOdqBTFA96sjMnYg.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\tGHhj01lNhf5vRVDjCu3.swf.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\VfjyAZ.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\VHoe8-6FdPflu6T.avi.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\ywHYvPs6W0-AFVh.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\8no_itL-.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\9PTt3.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\ARJInqhjI.mkv.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\cDkU5YVPTLW1.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\ePgg_4I.swf.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\hwYKWAk5G.avi.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\JGow.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\YSoil7qxqor59V.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\zhBuk7tYPjhh.mp4.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\zPwjRXFx4ak-wcF-4M.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\Default\Favorites\Microsoft Websites\IE Add-on site.url.JGHh4eBP8Fd1I | Dropped File | Text |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Unknown
|
...
|
»
C:\\Users\Default\Favorites\Microsoft Websites\Microsoft At Work.url.JGHh4eBP8Fd1I | Dropped File | Text |
Unknown
|
...
|
»
C:\\Users\Default\Favorites\Microsoft Websites\Microsoft Store.url.JGHh4eBP8Fd1I | Dropped File | Text |
Unknown
|
...
|
»
C:\\Users\Default\Favorites\MSN Websites\MSN Entertainment.url.JGHh4eBP8Fd1I | Dropped File | Text |
Unknown
|
...
|
»
C:\\Users\Default\Favorites\MSN Websites\MSN Money.url.JGHh4eBP8Fd1I | Dropped File | Text |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url.JGHh4eBP8Fd1I | Dropped File | Text |
Unknown
|
...
|
»
C:\\Users\Default\Favorites\MSN Websites\MSN.url.JGHh4eBP8Fd1I | Dropped File | Text |
Unknown
|
...
|
»
C:\\Users\Default\NTUSER.DAT.LOG | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\Default\NTUSER.DAT.LOG1.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Searches\Everywhere.search-ms.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\Default\Searches\Indexed Locations.search-ms.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\Public\Music\Sample Music\Kalimba.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\Public\Pictures\Sample Pictures\Desert.jpg.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\Public\Pictures\Sample Pictures\Tulips.jpg.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv.JGHh4eBP8Fd1I | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\EdGFu Be0O1gN5PVnO.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\iduO2IYXd-tHc.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\l4GFxa.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\OUUG.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\qI6kFyRkRoYIVG4dmz.mp4.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\uG00\FdgC GY6o3fHrP\apSnOqmi2FU2J4If.png.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\uG00\NosLIJ\a66u.mp3.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\uG00\NosLIJ\Mmk5zi_w8tSTA.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\yNS-T svTfTr\kVkMHSU621Zz3O9zX.pptx.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\yNS-T svTfTr\X4NlrGT u9Jw-t.avi.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\z6hR6LT.ots | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZN09Mu6_2Jh.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\5APKTu101u.xlsx.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\8ft07GD YM-V.docx.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\bL_mXf2Ye-ldtQyCu6\bGpbgVM\tlLNA9YsGD.ods | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\bL_mXf2Ye-ldtQyCu6\VXwMVSftTYpNt.ots.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\IFjdM87kR.odt.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\MuH1f.pptx.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\OISOP4mu\2Vmwa.ots | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\OISOP4mu\KyDQsrk5d86AH.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\OISOP4mu\piQJ5jiLae2bU80f.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\OISOP4mu\v00ii.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\rFulVR.xlsx.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\tFZbqhBddTNoIIoKv.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\zmTALao3p.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url | Modified File | Text |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\6ZIUSh7Ohe7nfy2FNxB.mp3.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\I ss8INmAtYGieum.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\OpiNrZgPecWAi8r Wl.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\VVgGsRmhcblB7F1BVRv.wav.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\1H4bBYQSFM1_.m4a.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\fw iEK6p.mp3.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\Rbo4EjHh.mp3.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\RTZJ0quFZh\cWcX2Uf6TiPMIgG.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\RTZJ0quFZh\e-LaUK.wav.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\RTZJ0quFZh\Mys1G.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\RTZJ0quFZh\qHyTX69yaacfS_Cxq.wav.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\RTZJ0quFZh\zp39y118mNhzEg.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\ysdsbDDIUX4Sr668g7\UMlP lT1wnoAyzoKSbb.m4a.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\72Di8SCcamc.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\9jy3.bmp.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\gqjiYviI.png.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\Hr0aHLLOWCDo2CKsY9du.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6hn746vGXDtVwDEI3xjG\TnTOEeWjs7USgnxZ.bmp.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\BR8CvW-.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\JkFcmXIHR.bmp.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\ki6g_pWzdFb.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\o42yb-k1XfE.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\so5Q9L53Hw.jpg.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\Ydp6NeRIYBx07.bmp.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\2uS77ihf6.flv.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\Andl.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\C9YzcLM8.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\Iz-BRvLG.flv.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\OopN_upnVuL.mp4.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\1gJliXStDVXSn3WE J5\x9Vu.flv.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\GCg CxCEfi_Cg.mkv.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\lrEr-Lj.mkv.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\ohzw3-nis.avi.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\PaDVDk9CUxv2f_K8Q.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\WZL3h3db2LCIoGXQCrBP.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\xUW_XdKL8c5SY7Q9nUFs.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\y1jW_yIztM5DBSm8D.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url.JGHh4eBP8Fd1I | Dropped File | Text |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Not Queried
|
...
|
»
C:\\Users\Default\Favorites\MSN Websites\MSN Autos.url | Modified File | Text |
Not Queried
|
...
|
»
C:\\Users\Default\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Not Queried
|
...
|
»
C:\\Users\Default\NTUSER.DAT.LOG2 | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\Public\Libraries\RecordedTV.library-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\Public\Music\Sample Music\Sleep Away.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\Public\Pictures\Sample Pictures\Koala.jpg.JGHh4eBP8Fd1I | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\Public\Pictures\Sample Pictures\Penguins.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\Public\Videos\Sample Videos\Wildlife.wmv | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\5p5nrgjn0js_halpmcxz@myip[1].txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\5p5nrgjn0js_halpmcxz@myip[2].txt | Dropped File | Text |
Not Queried
|
...
|
»