VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Wiper, Exploit |
1.exe
Windows Exe (x86-32)
Created at 2019-07-12T15:03:00
Remarks
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-07-12 15:44 (UTC+2) |
Last Seen | 2019-07-12 16:34 (UTC+2) |
Names | Win32.Exploit.Graftor |
Families | Graftor |
Classification | Exploit |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x407032 |
Size Of Code | 0x16000 |
Size Of Initialized Data | 0x13000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-07-12 10:27:39+00:00 |
Packer | Armadillo v1.71 |
Version Information (7)
»
Comments | Command |
CompanyName | Skystars Corporation |
FileDescription | Command |
FileVersion | 1.0.0.0 |
LegalCopyright | Skystars Corporation 版权所有 |
ProductName | Command |
ProductVersion | 1.0.0.0 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x15afa | 0x16000 | 0x1000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x417000 | 0x4afa | 0x5000 | 0x17000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.76 |
.data | 0x41c000 | 0xf7bc | 0x6000 | 0x1c000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.7 |
.rsrc | 0x42c000 | 0x8000 | 0x8000 | 0x22000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.22 |
Imports (8)
»
KERNEL32.dll (103)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleFileNameA | 0x0 | 0x417080 | 0x1a8bc | 0x1a8bc | 0x17d |
GetCommandLineA | 0x0 | 0x417084 | 0x1a8c0 | 0x1a8c0 | 0x110 |
RemoveDirectoryA | 0x0 | 0x417088 | 0x1a8c4 | 0x1a8c4 | 0x2c4 |
GetTickCount | 0x0 | 0x41708c | 0x1a8c8 | 0x1a8c8 | 0x1df |
DeleteFileA | 0x0 | 0x417090 | 0x1a8cc | 0x1a8cc | 0x83 |
GetFileSize | 0x0 | 0x417094 | 0x1a8d0 | 0x1a8d0 | 0x163 |
ReadFile | 0x0 | 0x417098 | 0x1a8d4 | 0x1a8d4 | 0x2b5 |
FindClose | 0x0 | 0x41709c | 0x1a8d8 | 0x1a8d8 | 0xce |
FindFirstFileA | 0x0 | 0x4170a0 | 0x1a8dc | 0x1a8dc | 0xd2 |
FindNextFileA | 0x0 | 0x4170a4 | 0x1a8e0 | 0x1a8e0 | 0xdc |
GetStartupInfoA | 0x0 | 0x4170a8 | 0x1a8e4 | 0x1a8e4 | 0x1b7 |
CreateProcessA | 0x0 | 0x4170ac | 0x1a8e8 | 0x1a8e8 | 0x66 |
WaitForSingleObject | 0x0 | 0x4170b0 | 0x1a8ec | 0x1a8ec | 0x390 |
CreateFileA | 0x0 | 0x4170b4 | 0x1a8f0 | 0x1a8f0 | 0x53 |
WriteFile | 0x0 | 0x4170b8 | 0x1a8f4 | 0x1a8f4 | 0x3a4 |
CloseHandle | 0x0 | 0x4170bc | 0x1a8f8 | 0x1a8f8 | 0x34 |
IsBadReadPtr | 0x0 | 0x4170c0 | 0x1a8fc | 0x1a8fc | 0x233 |
HeapFree | 0x0 | 0x4170c4 | 0x1a900 | 0x1a900 | 0x216 |
HeapReAlloc | 0x0 | 0x4170c8 | 0x1a904 | 0x1a904 | 0x21a |
HeapAlloc | 0x0 | 0x4170cc | 0x1a908 | 0x1a908 | 0x210 |
ExitProcess | 0x0 | 0x4170d0 | 0x1a90c | 0x1a90c | 0xb9 |
GetModuleHandleA | 0x0 | 0x4170d4 | 0x1a910 | 0x1a910 | 0x17f |
GetProcessHeap | 0x0 | 0x4170d8 | 0x1a914 | 0x1a914 | 0x1a3 |
MoveFileA | 0x0 | 0x4170dc | 0x1a918 | 0x1a918 | 0x26e |
CreateDirectoryA | 0x0 | 0x4170e0 | 0x1a91c | 0x1a91c | 0x4b |
lstrlenA | 0x0 | 0x4170e4 | 0x1a920 | 0x1a920 | 0x3cc |
GetTempPathA | 0x0 | 0x4170e8 | 0x1a924 | 0x1a924 | 0x1d5 |
GetSystemDirectoryA | 0x0 | 0x4170ec | 0x1a928 | 0x1a928 | 0x1c1 |
GetWindowsDirectoryA | 0x0 | 0x4170f0 | 0x1a92c | 0x1a92c | 0x1f3 |
GetVersionExA | 0x0 | 0x4170f4 | 0x1a930 | 0x1a930 | 0x1e9 |
GetLastError | 0x0 | 0x4170f8 | 0x1a934 | 0x1a934 | 0x171 |
GetCurrentProcess | 0x0 | 0x4170fc | 0x1a938 | 0x1a938 | 0x142 |
MultiByteToWideChar | 0x0 | 0x417100 | 0x1a93c | 0x1a93c | 0x275 |
WideCharToMultiByte | 0x0 | 0x417104 | 0x1a940 | 0x1a940 | 0x394 |
GetCurrentThreadId | 0x0 | 0x417108 | 0x1a944 | 0x1a944 | 0x146 |
GetCurrentThread | 0x0 | 0x41710c | 0x1a948 | 0x1a948 | 0x145 |
lstrcmpiA | 0x0 | 0x417110 | 0x1a94c | 0x1a94c | 0x3c3 |
lstrcmpA | 0x0 | 0x417114 | 0x1a950 | 0x1a950 | 0x3c0 |
GlobalDeleteAtom | 0x0 | 0x417118 | 0x1a954 | 0x1a954 | 0x1fa |
GlobalAlloc | 0x0 | 0x41711c | 0x1a958 | 0x1a958 | 0x1f8 |
GlobalLock | 0x0 | 0x417120 | 0x1a95c | 0x1a95c | 0x203 |
LocalAlloc | 0x0 | 0x417124 | 0x1a960 | 0x1a960 | 0x258 |
LocalFree | 0x0 | 0x417128 | 0x1a964 | 0x1a964 | 0x25c |
InitializeCriticalSection | 0x0 | 0x41712c | 0x1a968 | 0x1a968 | 0x223 |
TlsAlloc | 0x0 | 0x417130 | 0x1a96c | 0x1a96c | 0x363 |
DeleteCriticalSection | 0x0 | 0x417134 | 0x1a970 | 0x1a970 | 0x81 |
GlobalFree | 0x0 | 0x417138 | 0x1a974 | 0x1a974 | 0x1ff |
GlobalUnlock | 0x0 | 0x41713c | 0x1a978 | 0x1a978 | 0x20a |
GlobalHandle | 0x0 | 0x417140 | 0x1a97c | 0x1a97c | 0x202 |
TlsFree | 0x0 | 0x417144 | 0x1a980 | 0x1a980 | 0x364 |
LeaveCriticalSection | 0x0 | 0x417148 | 0x1a984 | 0x1a984 | 0x251 |
GlobalReAlloc | 0x0 | 0x41714c | 0x1a988 | 0x1a988 | 0x206 |
EnterCriticalSection | 0x0 | 0x417150 | 0x1a98c | 0x1a98c | 0x98 |
TlsSetValue | 0x0 | 0x417154 | 0x1a990 | 0x1a990 | 0x366 |
LocalReAlloc | 0x0 | 0x417158 | 0x1a994 | 0x1a994 | 0x25f |
TlsGetValue | 0x0 | 0x41715c | 0x1a998 | 0x1a998 | 0x365 |
lstrcpynA | 0x0 | 0x417160 | 0x1a99c | 0x1a99c | 0x3c9 |
GlobalFlags | 0x0 | 0x417164 | 0x1a9a0 | 0x1a9a0 | 0x1fe |
InterlockedDecrement | 0x0 | 0x417168 | 0x1a9a4 | 0x1a9a4 | 0x228 |
WritePrivateProfileStringA | 0x0 | 0x41716c | 0x1a9a8 | 0x1a9a8 | 0x3a9 |
lstrcatA | 0x0 | 0x417170 | 0x1a9ac | 0x1a9ac | 0x3bd |
lstrcpyA | 0x0 | 0x417174 | 0x1a9b0 | 0x1a9b0 | 0x3c6 |
InterlockedIncrement | 0x0 | 0x417178 | 0x1a9b4 | 0x1a9b4 | 0x22c |
SetLastError | 0x0 | 0x41717c | 0x1a9b8 | 0x1a9b8 | 0x328 |
GetProcAddress | 0x0 | 0x417180 | 0x1a9bc | 0x1a9bc | 0x1a0 |
GlobalFindAtomA | 0x0 | 0x417184 | 0x1a9c0 | 0x1a9c0 | 0x1fb |
GlobalAddAtomA | 0x0 | 0x417188 | 0x1a9c4 | 0x1a9c4 | 0x1f6 |
GlobalGetAtomNameA | 0x0 | 0x41718c | 0x1a9c8 | 0x1a9c8 | 0x200 |
GetVersion | 0x0 | 0x417190 | 0x1a9cc | 0x1a9cc | 0x1e8 |
FreeLibrary | 0x0 | 0x417194 | 0x1a9d0 | 0x1a9d0 | 0xf8 |
LoadLibraryA | 0x0 | 0x417198 | 0x1a9d4 | 0x1a9d4 | 0x252 |
GetProcessVersion | 0x0 | 0x41719c | 0x1a9d8 | 0x1a9d8 | 0x1ab |
SetErrorMode | 0x0 | 0x4171a0 | 0x1a9dc | 0x1a9dc | 0x315 |
SetFilePointer | 0x0 | 0x4171a4 | 0x1a9e0 | 0x1a9e0 | 0x31b |
FlushFileBuffers | 0x0 | 0x4171a8 | 0x1a9e4 | 0x1a9e4 | 0xee |
GetCPInfo | 0x0 | 0x4171ac | 0x1a9e8 | 0x1a9e8 | 0x104 |
GetOEMCP | 0x0 | 0x4171b0 | 0x1a9ec | 0x1a9ec | 0x193 |
RtlUnwind | 0x0 | 0x4171b4 | 0x1a9f0 | 0x1a9f0 | 0x2d7 |
TerminateProcess | 0x0 | 0x4171b8 | 0x1a9f4 | 0x1a9f4 | 0x35e |
RaiseException | 0x0 | 0x4171bc | 0x1a9f8 | 0x1a9f8 | 0x2a7 |
HeapSize | 0x0 | 0x4171c0 | 0x1a9fc | 0x1a9fc | 0x21c |
GetACP | 0x0 | 0x4171c4 | 0x1aa00 | 0x1aa00 | 0xfd |
UnhandledExceptionFilter | 0x0 | 0x4171c8 | 0x1aa04 | 0x1aa04 | 0x36e |
FreeEnvironmentStringsA | 0x0 | 0x4171cc | 0x1aa08 | 0x1aa08 | 0xf6 |
FreeEnvironmentStringsW | 0x0 | 0x4171d0 | 0x1aa0c | 0x1aa0c | 0xf7 |
GetEnvironmentStrings | 0x0 | 0x4171d4 | 0x1aa10 | 0x1aa10 | 0x155 |
GetEnvironmentStringsW | 0x0 | 0x4171d8 | 0x1aa14 | 0x1aa14 | 0x157 |
SetHandleCount | 0x0 | 0x4171dc | 0x1aa18 | 0x1aa18 | 0x324 |
GetStdHandle | 0x0 | 0x4171e0 | 0x1aa1c | 0x1aa1c | 0x1b9 |
GetFileType | 0x0 | 0x4171e4 | 0x1aa20 | 0x1aa20 | 0x166 |
GetEnvironmentVariableA | 0x0 | 0x4171e8 | 0x1aa24 | 0x1aa24 | 0x158 |
HeapDestroy | 0x0 | 0x4171ec | 0x1aa28 | 0x1aa28 | 0x214 |
HeapCreate | 0x0 | 0x4171f0 | 0x1aa2c | 0x1aa2c | 0x212 |
VirtualFree | 0x0 | 0x4171f4 | 0x1aa30 | 0x1aa30 | 0x383 |
VirtualAlloc | 0x0 | 0x4171f8 | 0x1aa34 | 0x1aa34 | 0x381 |
IsBadWritePtr | 0x0 | 0x4171fc | 0x1aa38 | 0x1aa38 | 0x236 |
SetUnhandledExceptionFilter | 0x0 | 0x417200 | 0x1aa3c | 0x1aa3c | 0x34a |
LCMapStringA | 0x0 | 0x417204 | 0x1aa40 | 0x1aa40 | 0x244 |
LCMapStringW | 0x0 | 0x417208 | 0x1aa44 | 0x1aa44 | 0x245 |
GetStringTypeA | 0x0 | 0x41720c | 0x1aa48 | 0x1aa48 | 0x1ba |
GetStringTypeW | 0x0 | 0x417210 | 0x1aa4c | 0x1aa4c | 0x1bd |
IsBadCodePtr | 0x0 | 0x417214 | 0x1aa50 | 0x1aa50 | 0x230 |
SetStdHandle | 0x0 | 0x417218 | 0x1aa54 | 0x1aa54 | 0x337 |
USER32.dll (87)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PostQuitMessage | 0x0 | 0x417230 | 0x1aa6c | 0x1aa6c | 0x204 |
PostMessageA | 0x0 | 0x417234 | 0x1aa70 | 0x1aa70 | 0x202 |
SendMessageA | 0x0 | 0x417238 | 0x1aa74 | 0x1aa74 | 0x23b |
SetCursor | 0x0 | 0x41723c | 0x1aa78 | 0x1aa78 | 0x24d |
GetWindowLongA | 0x0 | 0x417240 | 0x1aa7c | 0x1aa7c | 0x16e |
GetLastActivePopup | 0x0 | 0x417244 | 0x1aa80 | 0x1aa80 | 0x128 |
SetWindowsHookExA | 0x0 | 0x417248 | 0x1aa84 | 0x1aa84 | 0x28a |
GetCursorPos | 0x0 | 0x41724c | 0x1aa88 | 0x1aa88 | 0x10b |
IsWindowVisible | 0x0 | 0x417250 | 0x1aa8c | 0x1aa8c | 0x1b1 |
ValidateRect | 0x0 | 0x417254 | 0x1aa90 | 0x1aa90 | 0x2c4 |
CallNextHookEx | 0x0 | 0x417258 | 0x1aa94 | 0x1aa94 | 0x1a |
GetKeyState | 0x0 | 0x41725c | 0x1aa98 | 0x1aa98 | 0x121 |
GetNextDlgTabItem | 0x0 | 0x417260 | 0x1aa9c | 0x1aa9c | 0x143 |
GetFocus | 0x0 | 0x417264 | 0x1aaa0 | 0x1aaa0 | 0x116 |
EnableMenuItem | 0x0 | 0x417268 | 0x1aaa4 | 0x1aaa4 | 0xc2 |
CheckMenuItem | 0x0 | 0x41726c | 0x1aaa8 | 0x1aaa8 | 0x39 |
SetMenuItemBitmaps | 0x0 | 0x417270 | 0x1aaac | 0x1aaac | 0x261 |
ModifyMenuA | 0x0 | 0x417274 | 0x1aab0 | 0x1aab0 | 0x1e7 |
GetMenuState | 0x0 | 0x417278 | 0x1aab4 | 0x1aab4 | 0x137 |
LoadBitmapA | 0x0 | 0x41727c | 0x1aab8 | 0x1aab8 | 0x1b8 |
GetMenuCheckMarkDimensions | 0x0 | 0x417280 | 0x1aabc | 0x1aabc | 0x12e |
GetClassNameA | 0x0 | 0x417284 | 0x1aac0 | 0x1aac0 | 0xfc |
PtInRect | 0x0 | 0x417288 | 0x1aac4 | 0x1aac4 | 0x20c |
GetWindowRect | 0x0 | 0x41728c | 0x1aac8 | 0x1aac8 | 0x174 |
GetDlgCtrlID | 0x0 | 0x417290 | 0x1aacc | 0x1aacc | 0x110 |
GetWindow | 0x0 | 0x417294 | 0x1aad0 | 0x1aad0 | 0x16a |
ClientToScreen | 0x0 | 0x417298 | 0x1aad4 | 0x1aad4 | 0x40 |
SetWindowTextA | 0x0 | 0x41729c | 0x1aad8 | 0x1aad8 | 0x286 |
GetWindowTextA | 0x0 | 0x4172a0 | 0x1aadc | 0x1aadc | 0x177 |
UnhookWindowsHookEx | 0x0 | 0x4172a4 | 0x1aae0 | 0x1aae0 | 0x2ae |
GetMenuItemCount | 0x0 | 0x4172a8 | 0x1aae4 | 0x1aae4 | 0x132 |
GetDC | 0x0 | 0x4172ac | 0x1aae8 | 0x1aae8 | 0x10c |
ReleaseDC | 0x0 | 0x4172b0 | 0x1aaec | 0x1aaec | 0x22a |
TabbedTextOutA | 0x0 | 0x4172b4 | 0x1aaf0 | 0x1aaf0 | 0x29b |
DrawTextA | 0x0 | 0x4172b8 | 0x1aaf4 | 0x1aaf4 | 0xbc |
GrayStringA | 0x0 | 0x4172bc | 0x1aaf8 | 0x1aaf8 | 0x17d |
GetDlgItem | 0x0 | 0x4172c0 | 0x1aafc | 0x1aafc | 0x111 |
SetForegroundWindow | 0x0 | 0x4172c4 | 0x1ab00 | 0x1ab00 | 0x257 |
SetWindowPos | 0x0 | 0x4172c8 | 0x1ab04 | 0x1ab04 | 0x283 |
ShowWindow | 0x0 | 0x4172cc | 0x1ab08 | 0x1ab08 | 0x292 |
SetFocus | 0x0 | 0x4172d0 | 0x1ab0c | 0x1ab0c | 0x256 |
GetSystemMetrics | 0x0 | 0x4172d4 | 0x1ab10 | 0x1ab10 | 0x15d |
GetWindowPlacement | 0x0 | 0x4172d8 | 0x1ab14 | 0x1ab14 | 0x173 |
IsIconic | 0x0 | 0x4172dc | 0x1ab18 | 0x1ab18 | 0x1a6 |
SystemParametersInfoA | 0x0 | 0x4172e0 | 0x1ab1c | 0x1ab1c | 0x299 |
RegisterWindowMessageA | 0x0 | 0x4172e4 | 0x1ab20 | 0x1ab20 | 0x227 |
GetMessagePos | 0x0 | 0x4172e8 | 0x1ab24 | 0x1ab24 | 0x13c |
GetMessageTime | 0x0 | 0x4172ec | 0x1ab28 | 0x1ab28 | 0x13d |
DefWindowProcA | 0x0 | 0x4172f0 | 0x1ab2c | 0x1ab2c | 0x8e |
RemovePropA | 0x0 | 0x4172f4 | 0x1ab30 | 0x1ab30 | 0x22c |
CallWindowProcA | 0x0 | 0x4172f8 | 0x1ab34 | 0x1ab34 | 0x1b |
GetPropA | 0x0 | 0x4172fc | 0x1ab38 | 0x1ab38 | 0x14a |
SetPropA | 0x0 | 0x417300 | 0x1ab3c | 0x1ab3c | 0x26a |
GetClassLongA | 0x0 | 0x417304 | 0x1ab40 | 0x1ab40 | 0xfa |
CreateWindowExA | 0x0 | 0x417308 | 0x1ab44 | 0x1ab44 | 0x60 |
DestroyWindow | 0x0 | 0x41730c | 0x1ab48 | 0x1ab48 | 0x99 |
GetMenuItemID | 0x0 | 0x417310 | 0x1ab4c | 0x1ab4c | 0x133 |
GetSubMenu | 0x0 | 0x417314 | 0x1ab50 | 0x1ab50 | 0x159 |
GetMenu | 0x0 | 0x417318 | 0x1ab54 | 0x1ab54 | 0x12c |
RegisterClassA | 0x0 | 0x41731c | 0x1ab58 | 0x1ab58 | 0x216 |
GetClassInfoA | 0x0 | 0x417320 | 0x1ab5c | 0x1ab5c | 0xf6 |
WinHelpA | 0x0 | 0x417324 | 0x1ab60 | 0x1ab60 | 0x2d1 |
GetCapture | 0x0 | 0x417328 | 0x1ab64 | 0x1ab64 | 0xf3 |
GetTopWindow | 0x0 | 0x41732c | 0x1ab68 | 0x1ab68 | 0x163 |
CopyRect | 0x0 | 0x417330 | 0x1ab6c | 0x1ab6c | 0x4a |
GetClientRect | 0x0 | 0x417334 | 0x1ab70 | 0x1ab70 | 0xff |
AdjustWindowRectEx | 0x0 | 0x417338 | 0x1ab74 | 0x1ab74 | 0x2 |
GetSysColor | 0x0 | 0x41733c | 0x1ab78 | 0x1ab78 | 0x15a |
MapWindowPoints | 0x0 | 0x417340 | 0x1ab7c | 0x1ab7c | 0x1da |
LoadIconA | 0x0 | 0x417344 | 0x1ab80 | 0x1ab80 | 0x1be |
LoadCursorA | 0x0 | 0x417348 | 0x1ab84 | 0x1ab84 | 0x1ba |
GetSysColorBrush | 0x0 | 0x41734c | 0x1ab88 | 0x1ab88 | 0x15b |
LoadStringA | 0x0 | 0x417350 | 0x1ab8c | 0x1ab8c | 0x1cb |
DestroyMenu | 0x0 | 0x417354 | 0x1ab90 | 0x1ab90 | 0x97 |
GetActiveWindow | 0x0 | 0x417358 | 0x1ab94 | 0x1ab94 | 0xeb |
GetForegroundWindow | 0x0 | 0x41735c | 0x1ab98 | 0x1ab98 | 0x117 |
IsWindowEnabled | 0x0 | 0x417360 | 0x1ab9c | 0x1ab9c | 0x1ae |
PeekMessageA | 0x0 | 0x417364 | 0x1aba0 | 0x1aba0 | 0x200 |
GetMessageA | 0x0 | 0x417368 | 0x1aba4 | 0x1aba4 | 0x13a |
TranslateMessage | 0x0 | 0x41736c | 0x1aba8 | 0x1aba8 | 0x2aa |
DispatchMessageA | 0x0 | 0x417370 | 0x1abac | 0x1abac | 0xa1 |
wsprintfA | 0x0 | 0x417374 | 0x1abb0 | 0x1abb0 | 0x2d7 |
MessageBoxA | 0x0 | 0x417378 | 0x1abb4 | 0x1abb4 | 0x1df |
GetParent | 0x0 | 0x41737c | 0x1abb8 | 0x1abb8 | 0x145 |
EnableWindow | 0x0 | 0x417380 | 0x1abbc | 0x1abbc | 0xc4 |
SetWindowLongA | 0x0 | 0x417384 | 0x1abc0 | 0x1abc0 | 0x280 |
UnregisterClassA | 0x0 | 0x417388 | 0x1abc4 | 0x1abc4 | 0x2b3 |
GDI32.dll (24)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PtVisible | 0x0 | 0x41701c | 0x1a858 | 0x1a858 | 0x1f1 |
GetDeviceCaps | 0x0 | 0x417020 | 0x1a85c | 0x1a85c | 0x16b |
RectVisible | 0x0 | 0x417024 | 0x1a860 | 0x1a860 | 0x1f5 |
TextOutA | 0x0 | 0x417028 | 0x1a864 | 0x1a864 | 0x24e |
ExtTextOutA | 0x0 | 0x41702c | 0x1a868 | 0x1a868 | 0xdd |
Escape | 0x0 | 0x417030 | 0x1a86c | 0x1a86c | 0xd4 |
GetObjectA | 0x0 | 0x417034 | 0x1a870 | 0x1a870 | 0x195 |
GetStockObject | 0x0 | 0x417038 | 0x1a874 | 0x1a874 | 0x1a5 |
CreateBitmap | 0x0 | 0x41703c | 0x1a878 | 0x1a878 | 0x27 |
DeleteObject | 0x0 | 0x417040 | 0x1a87c | 0x1a87c | 0x8f |
DeleteDC | 0x0 | 0x417044 | 0x1a880 | 0x1a880 | 0x8c |
SaveDC | 0x0 | 0x417048 | 0x1a884 | 0x1a884 | 0x207 |
RestoreDC | 0x0 | 0x41704c | 0x1a888 | 0x1a888 | 0x200 |
SelectObject | 0x0 | 0x417050 | 0x1a88c | 0x1a88c | 0x20e |
SetBkColor | 0x0 | 0x417054 | 0x1a890 | 0x1a890 | 0x215 |
SetTextColor | 0x0 | 0x417058 | 0x1a894 | 0x1a894 | 0x23c |
SetMapMode | 0x0 | 0x41705c | 0x1a898 | 0x1a898 | 0x22b |
SetViewportOrgEx | 0x0 | 0x417060 | 0x1a89c | 0x1a89c | 0x23f |
OffsetViewportOrgEx | 0x0 | 0x417064 | 0x1a8a0 | 0x1a8a0 | 0x1d5 |
SetViewportExtEx | 0x0 | 0x417068 | 0x1a8a4 | 0x1a8a4 | 0x23e |
ScaleViewportExtEx | 0x0 | 0x41706c | 0x1a8a8 | 0x1a8a8 | 0x208 |
SetWindowExtEx | 0x0 | 0x417070 | 0x1a8ac | 0x1a8ac | 0x242 |
ScaleWindowExtEx | 0x0 | 0x417074 | 0x1a8b0 | 0x1a8b0 | 0x209 |
GetClipBox | 0x0 | 0x417078 | 0x1a8b4 | 0x1a8b4 | 0x160 |
WINSPOOL.DRV (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ClosePrinter | 0x0 | 0x417390 | 0x1abcc | 0x1abcc | 0x1b |
DocumentPropertiesA | 0x0 | 0x417394 | 0x1abd0 | 0x1abd0 | 0x46 |
OpenPrinterA | 0x0 | 0x417398 | 0x1abd4 | 0x1abd4 | 0x7d |
COMCTL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x11 | 0x417014 | 0x1a850 | 0x1a850 | - |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFileExistsA | 0x0 | 0x417228 | 0x1aa64 | 0x1aa64 | 0x2d |
ADVAPI32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyExA | 0x0 | 0x417000 | 0x1a83c | 0x1a83c | 0x1ec |
RegCloseKey | 0x0 | 0x417004 | 0x1a840 | 0x1a840 | 0x1cb |
RegCreateKeyExA | 0x0 | 0x417008 | 0x1a844 | 0x1a844 | 0x1d1 |
RegSetValueExA | 0x0 | 0x41700c | 0x1a848 | 0x1a848 | 0x204 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathA | 0x0 | 0x417220 | 0x1aa5c | 0x1aa5c | 0xc4 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
1.exe | 1 | 0x00400000 | 0x00433FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Graftor.602767 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\5uCl6.pptx.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\akWullZV3EwuyRnw.pptx.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\CPySWMll AnWU6bLZ9.docx.SKYSTARS | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\iJAd4NLQA5m2_U7sFDwi.docx.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\LdyKq sH.pptx.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6b 5xTdqcrCQ2\8qE80HJgAQ4T-05.ots.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6CaRSI1gd4xA\6fah5Apwpl8.odp.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6CaRSI1gd4xA\Ck73aG03huDrzd07UJ.pps.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6CaRSI1gd4xA\sHSDSkZ0g_NoboxW.odp.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6CaRSI1gd4xA\T_P_-SNfCBkG8Aq2jj.xls.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\My Shapes\desktop.ini.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\VBGVmC8I55cDkr\4S7aUwFCgm0F2.docx.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\VBGVmC8I55cDkr\jCl699k6cnu.doc.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\VBGVmC8I55cDkr\ojzwNs9.pps.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\VBGVmC8I55cDkr\p1IDCpnxsoIZs5eLNz.doc.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\4eaJAvH8dt snU9W.flv.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\7IfjlEOaKqm-B.wav.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\desktop.ini.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\EDxoaq8Iw18ul.gif.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\imF1N2GKr.bmp.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\IpQ3E_cZPa8PdDey.ots.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\umeQAnzpGAKM.wav.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\w_MGGU cdFd.flv.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\i4dQ\okSd1.pptx.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\i4dQ\WKgBkja.ods.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\OPn7B_oStEDZG-Z\Q1gx-EumCFr8hNVa8.mp4.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\OPn7B_oStEDZG-Z\H938whtrhk\jq8VxXCnWlEayHpw6D.avi.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\pXbnvbUkulG\kFSjmyF-KmWxxu h.swf.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\197VZVbvdT s2CUJs.mp3.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\7_2Pm_o.bmp.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\8RPUZRrEb-g13uY1.flv.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\aK8F9M7.jpg.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\DlRKCMr1kuUs99ccD.wav.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Hp9uEm2qgDx9.mp4.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\hYLZvHOHq.bmp.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\r4h7GGfytZNn.mp4.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\WtGBDq uSQoCPzY.avi.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\XUo1Tt.jpg.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Crypto\RSA\S-1-5-21-3388679973-3930757225-3770151564-1000\83aa4cc77f591dfc2374580bbd95f6ba_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Crypto\RSA\S-1-5-21-3388679973-3930757225-3770151564-1000\932a2db58c237abd381d22df4c63a04a_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player (2).lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Internet Explorer\UserData\Low\index.dat.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Office\Recent\Global.LNK.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Office\Recent\Templates.LNK.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Outlook\Outlook.srs.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Protect\S-1-5-21-3111613574-2524581245-2586426736-500\be5b4fbd-cb99-45f5-9462-5f896dd3a6b9.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Protect\S-1-5-21-3111613574-2524581245-2586426736-500\Preferred.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Protect\S-1-5-21-3388679973-3930757225-3770151564-1000\02540a10-7eb7-4b20-a8c7-470f8986389c.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Publisher Building Blocks\ContentStore.xml.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@adobe[1].txt.SKYSTARS | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@everesttech[1].txt.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@ad13.adfarm1.adition[1].txt.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adfarm1.adition[2].txt.SKYSTARS | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adform[1].txt.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adnxs[1].txt.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@bing[1].txt.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@google[1].txt.SKYSTARS | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@linkedin[1].txt.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@msn[1].txt.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@skadtec[1].txt.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\index.dat.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\IETldCache\Low\index.dat.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Libraries\Documents.library-ms.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\PrivacIE\Low\index.dat.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\0R8VZmxctZ1GX1QI5rL.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\1SVv3QXnp1AD4QB.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\2LoErBDNL.flv.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\4RX058L3qJC413r4.flv.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\6b 5xTdqcrCQ2.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\6GPQLrb9z.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\76hRSKD790-L.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\7fgzkGfed5cplNOCn.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\8qE80HJgAQ4T-05.ots.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\9H9uiT4RQS.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\9rfr3g.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\axiblyMnDJq6wybsV.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\b1Al6ru.mkv.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\BEthdv.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\C 8INbgLqg8.mkv.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\DB4Pt MG-kRMN5PaImf6.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\desktop.ini.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\eiXRArevP-KNSUGJ1km.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\ESHHI8tKuSTh9Xs1d.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\eYe5rxlt-hbeM.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\H938whtrhk.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\HDB0GdLUiySD7s83WAzQ.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\hYLZvHOHq.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\i4dQ.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\IpQ3E_cZPa8PdDey.ots.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\k8AKeCkuzc4HIIi.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\MArt8B5Nnvr6CocV2.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\mn5_uAB.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\oFYgBk4QtpG412-y.mkv.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\ojzwNs9.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\OXwvMzo7VU4DQ.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\p2v55AVj.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\PQjPiQ-k5UaAunXcyp.lnk.SKYSTARS | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\R7_g8IwpOeJE _.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\Rj1_r3.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\sLz-Qn.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\SS_0.lnk.SKYSTARS | Dropped File | Compressed |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\tefEtu9q3KkgFxvT.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\VJDc9FNq06.mkv.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\VVWQOJivCiw.ots.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\wcytZbmWqSORl.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\xzSJ7.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\yF7UTSD8x5Tqa.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\YitNJanVQcH2FO.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\yNNti.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\YqrvAc.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\Y_JdOEwgYzgJjoB_mnj.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\ZwQr6.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\AutomaticDestinations\7e4dca80246863e3.automaticDestinations-ms.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\CustomDestinations\5afe4de1b92fc382.customDestinations-ms.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\SendTo\Compressed (zipped) Folder.ZFSendToTarget.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\SendTo\Fax Recipient.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (2).lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\addons.json.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\compatibility.ini.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\extensions.sqlite.SKYSTARS | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\key3.db.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\marionette.log.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\places.sqlite.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\prefs.js.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\search.json.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\secmod.db.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\signons.sqlite.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\bookmarkbackups\bookmarks-2017-06-05_5.json.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\fi-FI\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\it-IT\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\nl-NL\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\ru-RU\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\zh-CN\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\zh-TW\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.SKYSTARS | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\-MKqyxYjc5JRno0_.xlsx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\4su2oko3I.odp.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\76hRSKD790-L.pptx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\9Vfajx59Z9Z5.docx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\aajrkz KC.doc.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\axiblyMnDJq6wybsV.docx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\BEthdv.xlsx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\desktop.ini.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\E5dSTIR0F62ceIRi.xlsx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\eDeJvIUF8LXYojXe.xls.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\k8AKeCkuzc4HIIi.xlsx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\KczBX1JhveWm.xlsx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\OXwvMzo7VU4DQ.ods.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\PyIsTigOF966Nu_K.csv.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\rF_ok6UvUojb.xlsx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\RIHbvM5AACGsvn9b3.docx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\ThsCTAWGPdf6ip5.pptx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\wt3HXsmzIUggPP_.docx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6b 5xTdqcrCQ2\1SVv3QXnp1AD4QB.doc.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6b 5xTdqcrCQ2\7GRcqO09RMPUte99-j.docx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6b 5xTdqcrCQ2\hap-mdvd.xls.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6b 5xTdqcrCQ2\p2v55AVj.ppt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6b 5xTdqcrCQ2\Rj1_r3.docx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6b 5xTdqcrCQ2\sLz-Qn.pps.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6b 5xTdqcrCQ2\ZwQr6.pdf.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6CaRSI1gd4xA\ah1cMF2z.rtf.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6CaRSI1gd4xA\YBis7kkv5pT8UqO.odt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\6CaRSI1gd4xA\YitNJanVQcH2FO.odt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\My Shapes\_private\folder.ico.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\Outlook Files\voeimd@djhreuu.uhd.pst.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\VBGVmC8I55cDkr\ky0CNsBAgguhn.pptx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\\VBGVmC8I55cDkr\w7j NA8Fc2Fqu.odt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\-uMN xl8k6N90pMRQ.mp3.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\1.exe.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\2LoErBDNL.flv.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\6GPQLrb9z.png.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\9H9uiT4RQS.bmp.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\9IYI59Ta.jpg.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\Auw4sdsTepKYeu356.ppt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\cV435fL13v.jpg.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\cyqPND.wav.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\GwN9jYVw.bmp.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\IL_OG8.avi.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\L4u6PoFiCYyO.png.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\LbU4hyLoWMMWQlqFMMj.m4a.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\NJ0nkkjXO-jifKg04a.wav.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\PQjPiQ-k5UaAunXcyp.jpg.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\QpTBIG9 owV873iL.wav.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\VVWQOJivCiw.ots.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\w RjCfDLyWOGuuuBV9.wav.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\YMN7La I9lBJZO.m4a.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\YqrvAc.rtf.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\i4dQ\DB4Pt MG-kRMN5PaImf6.png.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\i4dQ\SS_0.doc.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\i4dQ\xzSJ7.doc.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\i4dQ\YuGi.wav.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\OPn7B_oStEDZG-Z\0R8VZmxctZ1GX1QI5rL.jpg.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\OPn7B_oStEDZG-Z\SBBTIRRJYRwtk_6hA.swf.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\OPn7B_oStEDZG-Z\T4nvE0-PZS_fB.jpg.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\OPn7B_oStEDZG-Z\ESHHI8tKuSTh9Xs1d\siXuQ8hvAO01ox4.csv.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\OPn7B_oStEDZG-Z\ESHHI8tKuSTh9Xs1d\TDPtbCn5uV9.png.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\OPn7B_oStEDZG-Z\H938whtrhk\C 8INbgLqg8.mkv.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\pXbnvbUkulG\KcjGX0 W5p_j5 Xn.m4a.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\pXbnvbUkulG\oP55.swf.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\\pXbnvbUkulG\POP8pfc9QmIhWOQhe.avi.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\-IJUXNcRg2PG0aCimvIX.m4a.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\5-OIo.csv.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\7fgzkGfed5cplNOCn.gif.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\9rfr3g.ods.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\b1Al6ru.mkv.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\ETUq1TsefE.wav.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\eYRSDHH9d.mp3.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\fpkLEmTA.rtf.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\HDB0GdLUiySD7s83WAzQ.pptx.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\koSBvQEvpYLBX86IlR C.mp4.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\K_ahl0R.swf.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\lE3JQhfZrFvsQUDm.pps.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\nBYfGQWP20W1fBYymA.wav.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\OItGubAn-.bmp.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\oOeIcMMwhOI.ppt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\oX7qYv9qTw54L.mp3.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\r9fxrCjn_fvX0.flv.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\RgphzL-7QJRwXkj.avi.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\tefEtu9q3KkgFxvT.ods.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\UbpxQyPEL.avi.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\UTcXL9zykuS.mp4.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\w0Ctkj.gif.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Adobe\Acrobat\10.0\JavaScripts\glob.settings.js.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Adobe\Acrobat\10.0\Security\addressbook.acrodata.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Adobe\Acrobat\10.0\Security\CRLCache\48B76449F3D5FEFA1133AA805E420F0FCA643651.crl.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Adobe\Acrobat\10.0\Security\CRLCache\A9B8213768ADC68AF64FCC6409E8BE414726687F.crl.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Crypto\RSA\S-1-5-21-3388679973-3930757225-3770151564-1000\fda992c8d564f97e48410a19a2e459f6_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Internet Explorer\Quick Launch\desktop.ini.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\desktop.ini.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\MS Project\14\1033\Global.MPT.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Office\MSO1033.acl.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Office\Recent\index.dat.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Outlook\Outlook.xml.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Protect\CREDHIST.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Protect\SYNCHIST.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Protect\S-1-5-21-3388679973-3930757225-3770151564-1000\0e15476d-d8fe-46ca-8099-ebdcf80f637c.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Protect\S-1-5-21-3388679973-3930757225-3770151564-1000\102a7bc8-3f85-4bb4-840a-38257d2965d2.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Protect\S-1-5-21-3388679973-3930757225-3770151564-1000\2be989a0-16a1-424b-9211-51aa3bb43e5d.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Protect\S-1-5-21-3388679973-3930757225-3770151564-1000\fbbe72db-afd8-443b-88dd-64b20388700d.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Protect\S-1-5-21-3388679973-3930757225-3770151564-1000\Preferred.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Templates\Normal.dotm.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\UProof\CUSTOM.DIC.SKYSTARS | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@adobe[3].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@demdex[1].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@dpm.demdex[2].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@google[2].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@ml314[1].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@rlcdn[2].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\index.dat.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adformdsp[1].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adtech[2].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adtr02[1].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@advertising[1].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@api.bing[2].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@at.atwola[1].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@c.bing[1].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@c.msn[1].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@doubleclick[2].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@google[3].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@google[4].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@m.exactag[1].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@scorecardresearch[2].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@server.adformdsp[1].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@track.adform[2].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@www.bing[2].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@www.linkedin[1].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@www.msn[2].txt.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\IETldCache\index.dat.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Libraries\desktop.ini.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Libraries\Music.library-ms.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Libraries\Pictures.library-ms.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Libraries\Videos.library-ms.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\PrivacIE\index.dat.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\-MKqyxYjc5JRno0_.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\-XGB.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\0PhF0I.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\3qeSyu.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\4eaJAvH8dt snU9W.flv.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\4S7aUwFCgm0F2.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\4su2oko3I.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\5-OIo.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\5IpCSj0.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\5uCl6.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\6CaRSI1gd4xA.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\6fah5Apwpl8.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\6zAa2BvVTWYN4.flv.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\7GRcqO09RMPUte99-j.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\7_2Pm_o.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\8kcn2BrTvdA4FudkvK.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\8RPUZRrEb-g13uY1.flv.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\9Vfajx59Z9Z5.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\aajrkz KC.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\ah1cMF2z.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\akWullZV3EwuyRnw.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\Auw4sdsTepKYeu356.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\Azl-UDflFCdqTtxVRZ5.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\Ck73aG03huDrzd07UJ.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\CPySWMll AnWU6bLZ9.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\cV435fL13v.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\dFSJ.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\E5dSTIR0F62ceIRi.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\eDeJvIUF8LXYojXe.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\EDgV-s2v0.mkv.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\EDxoaq8Iw18ul.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\fDaXSi7d38rWdnWNf.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\fpkLEmTA.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\GwN9jYVw.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\hap-mdvd.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\iJAd4NLQA5m2_U7sFDwi.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\imF1N2GKr.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\iqVhjJhZSIBuxl.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\IvQM2Pg89mN43.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\jCl699k6cnu.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\JYJ IrXH7S7J4lrI7c.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\KczBX1JhveWm.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\KlwMfLBW.mkv.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\ky0CNsBAgguhn.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\L8JGos.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\LdyKq sH.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\lE3JQhfZrFvsQUDm.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\mJO8uMF6Tat.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\mwGRgJsn.flv.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\My Music.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\My Pictures.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\My Videos.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\niS1LNMjpLd63RldlE.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\oaNX t.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\okSd1.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\oOeIcMMwhOI.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\OPn7B_oStEDZG-Z.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\p1IDCpnxsoIZs5eLNz.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\p7HLkCBt6lrk.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\pXbnvbUkulG.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\PyIsTigOF966Nu_K.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\qli3XF0tWwDGKFecggK7.mkv.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\R19lpaVKOfq7YVANQ.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\r9fxrCjn_fvX0.flv.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\rF_ok6UvUojb.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\RgozBY-.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\RIHbvM5AACGsvn9b3.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\Roaming.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\sHSDSkZ0g_NoboxW.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\siXuQ8hvAO01ox4.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\tf9tO-.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\ThsCTAWGPdf6ip5.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\tNxjHi4dfeQcdL.mkv.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\T_P_-SNfCBkG8Aq2jj.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\u8CGw8 qXyI_TQhqAida.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\u8FNPSsnCaar3G.mkv.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\VBGVmC8I55cDkr.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\vuD7hrqb3Qw4jb.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\w0Ctkj.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\w7j NA8Fc2Fqu.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\WKgBkja.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\wt3HXsmzIUggPP_.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\WU-9paSh0TSA.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\wvisDVGwhMu ffvUh.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\w_MGGU cdFd.flv.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\X4gIJecgSY-_.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\xF rEYVMCXzUTbMksZVb.mkv.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\YBis7kkv5pT8UqO.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\AutomaticDestinations\eb282ead62b4db87.automaticDestinations-ms.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\CustomDestinations\1b4dd67f29cb1962.customDestinations-ms.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\CustomDestinations\7e4dca80246863e3.customDestinations-ms.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\CustomDestinations\be71009ff8bb02a2.customDestinations-ms.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\SendTo\Desktop (create shortcut).DeskLink.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\SendTo\Desktop.ini.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\SendTo\Mail Recipient.MAPIMail.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\desktop.ini.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\desktop.ini.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer (2).lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Microsoft\Windows\Themes\TranscodedWallpaper.jpg.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\profiles.ini.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Crash Reports\InstallTime20131025151332.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\cert8.db.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\content-prefs.sqlite.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\cookies.sqlite.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\downloads.sqlite.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\extensions.ini.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\localstore.rdf.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\mimeTypes.rdf.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\permissions.sqlite.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\pluginreg.dat.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\sessionstore.bak.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\sessionstore.js.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\times.json.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\webappsstore.sqlite.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\\Mozilla\Firefox\Profiles\silmbjec.default\webapps\webapps.json.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\memtest.exe.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\cs-CZ\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\da-DK\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\de-DE\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\el-GR\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\en-US\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\en-US\memtest.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\es-ES\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Fonts\chs_boot.ttf.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Fonts\cht_boot.ttf.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Fonts\jpn_boot.ttf.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Fonts\kor_boot.ttf.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Fonts\wgl4_boot.ttf.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\fr-FR\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\hu-HU\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\ja-JP\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\ko-KR\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\nb-NO\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\pl-PL\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\pt-BR\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\pt-PT\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\sv-SE\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\tr-TR\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\zh-HK\bootmgr.exe.mui.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.SKYSTARS | Dropped File | Stream |
Not Queried
|
...
|
»