VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Variant.Fugrafa.39551
Mal/Generic-S
|
lok.exe
Windows Exe (x86-32)
Created at 2020-05-11T09:11:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\lok.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4014ed |
Size Of Code | 0xf600 |
Size Of Initialized Data | 0x48ea00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-08-15 02:29:15+00:00 |
Version Information (4)
»
FileVersionBeer | 1.3.3.4 |
InternalName | hjalishu.uzi |
LegalCopyrighd | Copyrighd (C) 2020, jlfvjz |
ProductVersion | 1.7.54 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xf5f0 | 0xf600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.57 |
.rdata | 0x411000 | 0x1dea | 0x1e00 | 0xfa00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.59 |
.data | 0x413000 | 0x482d20 | 0x12600 | 0x11800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.17 |
.rsrc | 0x896000 | 0x6ee0 | 0x7000 | 0x23e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.68 |
Imports (2)
»
KERNEL32.dll (78)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GlobalAlloc | 0x0 | 0x411008 | 0x126d8 | 0x110d8 | 0x285 |
GetLocaleInfoW | 0x0 | 0x41100c | 0x126dc | 0x110dc | 0x1ea |
FormatMessageW | 0x0 | 0x411010 | 0x126e0 | 0x110e0 | 0x148 |
GetExitCodeProcess | 0x0 | 0x411014 | 0x126e4 | 0x110e4 | 0x1c5 |
GetFileAttributesW | 0x0 | 0x411018 | 0x126e8 | 0x110e8 | 0x1ce |
ReadFile | 0x0 | 0x41101c | 0x126ec | 0x110ec | 0x368 |
lstrlenW | 0x0 | 0x411020 | 0x126f0 | 0x110f0 | 0x4b6 |
IsBadStringPtrA | 0x0 | 0x411024 | 0x126f4 | 0x110f4 | 0x2c9 |
WritePrivateProfileStringW | 0x0 | 0x411028 | 0x126f8 | 0x110f8 | 0x493 |
GetCurrencyFormatW | 0x0 | 0x41102c | 0x126fc | 0x110fc | 0x1a3 |
LCMapStringA | 0x0 | 0x411030 | 0x12700 | 0x11100 | 0x2e1 |
FindFirstFileExA | 0x0 | 0x411034 | 0x12704 | 0x11104 | 0x11e |
GetLastError | 0x0 | 0x411038 | 0x12708 | 0x11108 | 0x1e6 |
GetProcAddress | 0x0 | 0x41103c | 0x1270c | 0x1110c | 0x220 |
RemoveDirectoryA | 0x0 | 0x411040 | 0x12710 | 0x11110 | 0x37d |
OpenWaitableTimerA | 0x0 | 0x411044 | 0x12714 | 0x11114 | 0x338 |
GetPrivateProfileSectionA | 0x0 | 0x411048 | 0x12718 | 0x11118 | 0x218 |
GetCurrentProcessId | 0x0 | 0x41104c | 0x1271c | 0x1111c | 0x1aa |
SetCommTimeouts | 0x0 | 0x411050 | 0x12720 | 0x11120 | 0x3a0 |
GetModuleHandleW | 0x0 | 0x411054 | 0x12724 | 0x11124 | 0x1f9 |
SleepEx | 0x0 | 0x411058 | 0x12728 | 0x11128 | 0x424 |
CreateHardLinkA | 0x0 | 0x41105c | 0x1272c | 0x1112c | 0x80 |
HeapAlloc | 0x0 | 0x411060 | 0x12730 | 0x11130 | 0x29d |
GetDriveTypeW | 0x0 | 0x411064 | 0x12734 | 0x11134 | 0x1bb |
FindResourceA | 0x0 | 0x411068 | 0x12738 | 0x11138 | 0x136 |
GetNamedPipeHandleStateW | 0x0 | 0x41106c | 0x1273c | 0x1113c | 0x202 |
CreateFileA | 0x0 | 0x411070 | 0x12740 | 0x11140 | 0x78 |
Sleep | 0x0 | 0x411074 | 0x12744 | 0x11144 | 0x421 |
ExitProcess | 0x0 | 0x411078 | 0x12748 | 0x11148 | 0x104 |
GetStartupInfoW | 0x0 | 0x41107c | 0x1274c | 0x1114c | 0x23a |
TerminateProcess | 0x0 | 0x411080 | 0x12750 | 0x11150 | 0x42d |
GetCurrentProcess | 0x0 | 0x411084 | 0x12754 | 0x11154 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x411088 | 0x12758 | 0x11158 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41108c | 0x1275c | 0x1115c | 0x415 |
IsDebuggerPresent | 0x0 | 0x411090 | 0x12760 | 0x11160 | 0x2d1 |
TlsGetValue | 0x0 | 0x411094 | 0x12764 | 0x11164 | 0x434 |
TlsAlloc | 0x0 | 0x411098 | 0x12768 | 0x11168 | 0x432 |
TlsSetValue | 0x0 | 0x41109c | 0x1276c | 0x1116c | 0x435 |
TlsFree | 0x0 | 0x4110a0 | 0x12770 | 0x11170 | 0x433 |
InterlockedIncrement | 0x0 | 0x4110a4 | 0x12774 | 0x11174 | 0x2c0 |
SetLastError | 0x0 | 0x4110a8 | 0x12778 | 0x11178 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x4110ac | 0x1277c | 0x1117c | 0x1ad |
InterlockedDecrement | 0x0 | 0x4110b0 | 0x12780 | 0x11180 | 0x2bc |
WriteFile | 0x0 | 0x4110b4 | 0x12784 | 0x11184 | 0x48d |
GetStdHandle | 0x0 | 0x4110b8 | 0x12788 | 0x11188 | 0x23b |
GetModuleFileNameA | 0x0 | 0x4110bc | 0x1278c | 0x1118c | 0x1f4 |
DeleteCriticalSection | 0x0 | 0x4110c0 | 0x12790 | 0x11190 | 0xbe |
LeaveCriticalSection | 0x0 | 0x4110c4 | 0x12794 | 0x11194 | 0x2ef |
EnterCriticalSection | 0x0 | 0x4110c8 | 0x12798 | 0x11198 | 0xd9 |
LoadLibraryA | 0x0 | 0x4110cc | 0x1279c | 0x1119c | 0x2f1 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4110d0 | 0x127a0 | 0x111a0 | 0x2b5 |
GetModuleFileNameW | 0x0 | 0x4110d4 | 0x127a4 | 0x111a4 | 0x1f5 |
FreeEnvironmentStringsW | 0x0 | 0x4110d8 | 0x127a8 | 0x111a8 | 0x14b |
GetEnvironmentStringsW | 0x0 | 0x4110dc | 0x127ac | 0x111ac | 0x1c1 |
GetCommandLineW | 0x0 | 0x4110e0 | 0x127b0 | 0x111b0 | 0x170 |
SetHandleCount | 0x0 | 0x4110e4 | 0x127b4 | 0x111b4 | 0x3e8 |
GetFileType | 0x0 | 0x4110e8 | 0x127b8 | 0x111b8 | 0x1d7 |
GetStartupInfoA | 0x0 | 0x4110ec | 0x127bc | 0x111bc | 0x239 |
HeapCreate | 0x0 | 0x4110f0 | 0x127c0 | 0x111c0 | 0x29f |
VirtualFree | 0x0 | 0x4110f4 | 0x127c4 | 0x111c4 | 0x457 |
HeapFree | 0x0 | 0x4110f8 | 0x127c8 | 0x111c8 | 0x2a1 |
QueryPerformanceCounter | 0x0 | 0x4110fc | 0x127cc | 0x111cc | 0x354 |
GetTickCount | 0x0 | 0x411100 | 0x127d0 | 0x111d0 | 0x266 |
GetSystemTimeAsFileTime | 0x0 | 0x411104 | 0x127d4 | 0x111d4 | 0x24f |
GetCPInfo | 0x0 | 0x411108 | 0x127d8 | 0x111d8 | 0x15b |
GetACP | 0x0 | 0x41110c | 0x127dc | 0x111dc | 0x152 |
GetOEMCP | 0x0 | 0x411110 | 0x127e0 | 0x111e0 | 0x213 |
IsValidCodePage | 0x0 | 0x411114 | 0x127e4 | 0x111e4 | 0x2db |
HeapSize | 0x0 | 0x411118 | 0x127e8 | 0x111e8 | 0x2a6 |
RtlUnwind | 0x0 | 0x41111c | 0x127ec | 0x111ec | 0x392 |
GetLocaleInfoA | 0x0 | 0x411120 | 0x127f0 | 0x111f0 | 0x1e8 |
WideCharToMultiByte | 0x0 | 0x411124 | 0x127f4 | 0x111f4 | 0x47a |
VirtualAlloc | 0x0 | 0x411128 | 0x127f8 | 0x111f8 | 0x454 |
HeapReAlloc | 0x0 | 0x41112c | 0x127fc | 0x111fc | 0x2a4 |
GetStringTypeA | 0x0 | 0x411130 | 0x12800 | 0x11200 | 0x23d |
MultiByteToWideChar | 0x0 | 0x411134 | 0x12804 | 0x11204 | 0x31a |
GetStringTypeW | 0x0 | 0x411138 | 0x12808 | 0x11208 | 0x240 |
LCMapStringW | 0x0 | 0x41113c | 0x1280c | 0x1120c | 0x2e3 |
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LookupAccountNameA | 0x0 | 0x411000 | 0x126d0 | 0x110d0 | 0x188 |
Memory Dumps (20)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
lok.exe | 1 | 0x00400000 | 0x0089CFFF | Relevant Image |
![]() |
32-bit | 0x004023E0 |
![]() |
![]() |
...
|
buffer | 1 | 0x002B05E0 | 0x002B7AD2 | First Execution |
![]() |
32-bit | 0x002B05E0 |
![]() |
![]() |
...
|
buffer | 1 | 0x00020000 | 0x0002AFFF | First Execution |
![]() |
32-bit | 0x00020000 |
![]() |
![]() |
...
|
lok.exe | 1 | 0x00400000 | 0x0089CFFF | Content Changed |
![]() |
32-bit | 0x00404FB0 |
![]() |
![]() |
...
|
lok.exe | 1 | 0x00400000 | 0x0089CFFF | Content Changed |
![]() |
32-bit | 0x00402550 |
![]() |
![]() |
...
|
lok.exe | 1 | 0x00400000 | 0x0089CFFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
lok.exe | 1 | 0x00400000 | 0x0089CFFF | Content Changed |
![]() |
32-bit | 0x00406500 |
![]() |
![]() |
...
|
lok.exe | 1 | 0x00400000 | 0x0089CFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
lok.exe | 2 | 0x00400000 | 0x0089CFFF | Relevant Image |
![]() |
32-bit | 0x004023E0 |
![]() |
![]() |
...
|
lok.exe | 1 | 0x00400000 | 0x0089CFFF | Content Changed |
![]() |
32-bit | 0x0040621D |
![]() |
![]() |
...
|
buffer | 2 | 0x002D05F0 | 0x002D7AE2 | First Execution |
![]() |
32-bit | 0x002D05F0 |
![]() |
![]() |
...
|
buffer | 2 | 0x00020000 | 0x0002AFFF | First Execution |
![]() |
32-bit | 0x00020000 |
![]() |
![]() |
...
|
lok.exe | 2 | 0x00400000 | 0x0089CFFF | Content Changed |
![]() |
32-bit | 0x00404FB0 |
![]() |
![]() |
...
|
lok.exe | 2 | 0x00400000 | 0x0089CFFF | Content Changed |
![]() |
32-bit | 0x00402550 |
![]() |
![]() |
...
|
lok.exe | 2 | 0x00400000 | 0x0089CFFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
lok.exe | 2 | 0x00400000 | 0x0089CFFF | Content Changed |
![]() |
32-bit | 0x00404DFC |
![]() |
![]() |
...
|
lok.exe | 2 | 0x00400000 | 0x0089CFFF | Content Changed |
![]() |
32-bit | 0x00402C40 |
![]() |
![]() |
...
|
buffer | 2 | 0x00020000 | 0x0002AFFF | Content Changed |
![]() |
32-bit | 0x00020920 |
![]() |
![]() |
...
|
lok.exe | 2 | 0x00400000 | 0x0089CFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
lok.exe | 1 | 0x00400000 | 0x0089CFFF | Content Changed |
![]() |
32-bit | 0x00405DC0 |
![]() |
![]() |
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2HqmpKv6lFgzjz6.wav.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3GD_ ZxL28r4c.mp4.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3YWouV\afvg.docx.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3YWouV\KRlIGanfuQwVeE.mp4.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3YWouV\lFN3zf5aXfg7HN _j.wav.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3YWouV\Q-l-sU3Aq.mp3.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3YWouV\RQ6cNQuUEDfxzqZ.gif.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3YWouV\WxQNUEXdD_.flv.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\b5p-6s.mp3.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fbNvFXNW.jpg.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\GF7kkv3HtKk1MRjKdNL.m4a.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\m SJd_T.wav.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\q5JPesstQKuaf49xCYaB.bmp.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RCCe1.mp3.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\UfgPP1QkBKWljqd.mp3.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\WGtJLhsOqIYtE.xlsx.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\YHSl3HwuPRJ.avi.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\yPy1SQ.mkv.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_vHHR1G.odp.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveLR.cab.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.msi.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\ShellUI.MST.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.msi.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPrWW2.cab.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.msi.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.FLT.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.FNT.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\EPSIMP32.FLT.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\GIFIMP32.FLT.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\JPEGIM32.FLT.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.CGM.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.WPG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\WPGIMP32.FLT.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MUAUTH.CAB.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\ExcelMUI.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\SETUP.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OCT.CHM.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUI.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.WW\Office32WW.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\OneNoteMUI.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\SETUP.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\SETUP.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\PowerPointMUI.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\SETUP.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\SETUP.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.es\Proof.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\SETUP.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\SETUP.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\WordMUI.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_ES.LEX.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\PHONE.XML.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\BASMLA.XSL.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TextConv\RECOVR32.CNV.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TextConv\WPFT532.CNV.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\ARCTIC.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\BLENDS.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\BLUECALM.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\BLUEPRNT.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\BOLDSTRI.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\BREEZE.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\CAPSULES.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\CASCADE.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\COMPASS.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\CONCRETE.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\DEEPBLUE.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\ECHO.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\ECLIPSE.ELM.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\ECLIPSE.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\EDGE.ELM.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\EDGE.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\EVRGREEN.ELM.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\EVRGREEN.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\ICE.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\INDUST.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\IRIS.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\JOURNAL.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\LAYERS.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\LEVEL.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\NETWORK.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\PAPYRUS.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PIXEL\PIXEL.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PIXEL\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PIXEL\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\PROFILE.ELM.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\QUAD\QUAD.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RADIAL\RADIAL.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RADIAL\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\REFINED.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RICEPAPR\RICEPAPR.ELM.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RICEPAPR\RICEPAPR.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RIPPLE\RIPPLE.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RIPPLE\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RMNSQUE\RMNSQUE.ELM.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SLATE\SLATE.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SPRING\SPRING.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\STRTEDGE\STRTEDGE.ELM.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\STRTEDGE\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\STUDIO\STUDIO.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SUMIPNTG\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATER\WATER.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATERMAR\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATERMAR\WATERMAR.INF.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\readme-warning.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FRAR\MSB1FRAR.ITS.KJHslgjkjdfg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\-KW2K2JqC.mp4.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0Pe3NN--.avi.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2tp1cpJo 8v.bmp.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3YWouV\2Z E V5apz_.mkv.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3YWouV\qFv2xxBTGjIdUTK.swf.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3YWouV\wKgFcGsJGp.mp3.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3YWouV\ZMaqfD_.bmp.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fVEYgEIUkEwNIz.ods.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gbZx5hj.png.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IastE7wzz1LJALDjR.jpg.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\iW5Mi0MX.jpg.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\j30qcibGVZ7TC cBYc.avi.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MtV3KshDPRFOAwx.pdf.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OGQs0CD.mp3.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.msi.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.msi.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.msi.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.msi.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.CNT.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\PICTIM32.FLT.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10O.CHM.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10R.CHM.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\SETUP.XML.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.fr\Proof.XML.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\SETUP.XML.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\VisiorWW.XML.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\SETUP.XML.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppobjs-spp-plugin-manifest-signed.xrm-ms.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_FR.LEX.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.XML.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TextConv\WPFT632.CNV.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\AFTRNOON.INF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\AXIS.ELM.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\AXIS.INF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\BLUECALM.ELM.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\CANYON.INF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\CONCRETE.ELM.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\EXPEDITN.ELM.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\EXPEDITN.INF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\INDUST.ELM.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\NETWORK.ELM.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\PROFILE.INF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\REFINED.ELM.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RICEPAPR\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RMNSQUE\PREVIEW.GIF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RMNSQUE\RMNSQUE.INF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RMNSQUE\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SATIN\SATIN.INF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SKY\SKY.INF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SONORA\SONORA.INF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SPRING\THMBNAIL.PNG.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\STRTEDGE\STRTEDGE.INF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SUMIPNTG\SUMIPNTG.INF.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATERMAR\WATERMAR.ELM.KJHslgjkjdfg | Dropped File | Stream |
Not Queried
|
...
|
»