VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
DJ0507.exe
Windows Exe (x86-32)
Created at 2019-06-03T12:43:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\DJ0507.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2018-07-13 22:27 (UTC+2) |
Last Seen | 2019-05-04 12:11 (UTC+2) |
Names | Win32.Trojan.Filecoder |
Families | Filecoder |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x409f20 |
Size Of Initialized Data | 0xc200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-04-02 16:47:20+00:00 |
Sections (1)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.rdata | 0x401000 | 0xd008 | 0xd200 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.02 |
Imports (5)
»
KERNEL32.dll (45)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetFilePointerEx | 0x0 | 0x401024 | 0xcb54 | 0xbf54 | 0x467 |
CloseHandle | 0x0 | 0x401028 | 0xcb58 | 0xbf58 | 0x52 |
lstrlenW | 0x0 | 0x40102c | 0xcb5c | 0xbf5c | 0x54e |
CreateFileW | 0x0 | 0x401030 | 0xcb60 | 0xbf60 | 0x8f |
HeapCreate | 0x0 | 0x401034 | 0xcb64 | 0xbf64 | 0x2cd |
GetCurrentProcess | 0x0 | 0x401038 | 0xcb68 | 0xbf68 | 0x1c0 |
ExitProcess | 0x0 | 0x40103c | 0xcb6c | 0xbf6c | 0x119 |
CreateThread | 0x0 | 0x401040 | 0xcb70 | 0xbf70 | 0xb5 |
GetCurrentThread | 0x0 | 0x401044 | 0xcb74 | 0xbf74 | 0x1c4 |
SetThreadPriority | 0x0 | 0x401048 | 0xcb78 | 0xbf78 | 0x499 |
WaitForMultipleObjects | 0x0 | 0x40104c | 0xcb7c | 0xbf7c | 0x4f7 |
Sleep | 0x0 | 0x401050 | 0xcb80 | 0xbf80 | 0x4b2 |
GetLogicalDrives | 0x0 | 0x401054 | 0xcb84 | 0xbf84 | 0x209 |
SetFilePointer | 0x0 | 0x401058 | 0xcb88 | 0xbf88 | 0x466 |
FindClose | 0x0 | 0x40105c | 0xcb8c | 0xbf8c | 0x12e |
lstrcmpiA | 0x0 | 0x401060 | 0xcb90 | 0xbf90 | 0x544 |
lstrcmpiW | 0x0 | 0x401064 | 0xcb94 | 0xbf94 | 0x545 |
lstrcpyA | 0x0 | 0x401068 | 0xcb98 | 0xbf98 | 0x547 |
ReadFile | 0x0 | 0x40106c | 0xcb9c | 0xbf9c | 0x3c0 |
lstrcatW | 0x0 | 0x401070 | 0xcba0 | 0xbfa0 | 0x53f |
GetModuleFileNameW | 0x0 | 0x401074 | 0xcba4 | 0xbfa4 | 0x214 |
CreateProcessW | 0x0 | 0x401078 | 0xcba8 | 0xbfa8 | 0xa8 |
GetEnvironmentVariableW | 0x0 | 0x40107c | 0xcbac | 0xbfac | 0x1dc |
GetDriveTypeA | 0x0 | 0x401080 | 0xcbb0 | 0xbfb0 | 0x1d2 |
GetTempPathW | 0x0 | 0x401084 | 0xcbb4 | 0xbfb4 | 0x285 |
GetTempFileNameW | 0x0 | 0x401088 | 0xcbb8 | 0xbfb8 | 0x283 |
SetFileAttributesW | 0x0 | 0x40108c | 0xcbbc | 0xbfbc | 0x461 |
GetFileAttributesW | 0x0 | 0x401090 | 0xcbc0 | 0xbfc0 | 0x1ea |
FindFirstFileW | 0x0 | 0x401094 | 0xcbc4 | 0xbfc4 | 0x139 |
FindNextFileW | 0x0 | 0x401098 | 0xcbc8 | 0xbfc8 | 0x145 |
CopyFileW | 0x0 | 0x40109c | 0xcbcc | 0xbfcc | 0x75 |
MoveFileExW | 0x0 | 0x4010a0 | 0xcbd0 | 0xbfd0 | 0x360 |
SetPriorityClass | 0x0 | 0x4010a4 | 0xcbd4 | 0xbfd4 | 0x47d |
MultiByteToWideChar | 0x0 | 0x4010a8 | 0xcbd8 | 0xbfd8 | 0x367 |
WideCharToMultiByte | 0x0 | 0x4010ac | 0xcbdc | 0xbfdc | 0x511 |
CompareStringA | 0x0 | 0x4010b0 | 0xcbe0 | 0xbfe0 | 0x61 |
WriteFile | 0x0 | 0x4010b4 | 0xcbe4 | 0xbfe4 | 0x525 |
GetFileSizeEx | 0x0 | 0x4010b8 | 0xcbe8 | 0xbfe8 | 0x1f1 |
GetLastError | 0x0 | 0x4010bc | 0xcbec | 0xbfec | 0x202 |
lstrlenA | 0x0 | 0x4010c0 | 0xcbf0 | 0xbff0 | 0x54d |
GetProcessHeap | 0x0 | 0x4010c4 | 0xcbf4 | 0xbff4 | 0x24a |
HeapFree | 0x0 | 0x4010c8 | 0xcbf8 | 0xbff8 | 0x2cf |
HeapReAlloc | 0x0 | 0x4010cc | 0xcbfc | 0xbffc | 0x2d2 |
lstrcpyW | 0x0 | 0x4010d0 | 0xcc00 | 0xc000 | 0x548 |
HeapAlloc | 0x0 | 0x4010d4 | 0xcc04 | 0xc004 | 0x2cb |
ADVAPI32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExW | 0x0 | 0x401000 | 0xcb30 | 0xbf30 | 0x26e |
RegOpenKeyExW | 0x0 | 0x401004 | 0xcb34 | 0xbf34 | 0x261 |
RegCreateKeyExW | 0x0 | 0x401008 | 0xcb38 | 0xbf38 | 0x239 |
RegCloseKey | 0x0 | 0x40100c | 0xcb3c | 0xbf3c | 0x230 |
CryptGenRandom | 0x0 | 0x401010 | 0xcb40 | 0xbf40 | 0xc1 |
CryptReleaseContext | 0x0 | 0x401014 | 0xcb44 | 0xbf44 | 0xcb |
CryptAcquireContextW | 0x0 | 0x401018 | 0xcb48 | 0xbf48 | 0xb1 |
RegSetValueExW | 0x0 | 0x40101c | 0xcb4c | 0xbf4c | 0x27e |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHChangeNotify | 0x0 | 0x4010dc | 0xcc0c | 0xc00c | 0x7f |
ShellExecuteExW | 0x0 | 0x4010e0 | 0xcc10 | 0xc010 | 0x121 |
SHLWAPI.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindFileNameW | 0x0 | 0x4010e8 | 0xcc18 | 0xc018 | 0x49 |
PathRemoveFileSpecW | 0x0 | 0x4010ec | 0xcc1c | 0xc01c | 0x8b |
PathAddBackslashW | 0x0 | 0x4010f0 | 0xcc20 | 0xc020 | 0x30 |
ntdll.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_aulldiv | 0x0 | 0x4010f8 | 0xcc28 | 0xc028 | 0x4fe |
_alldiv | 0x0 | 0x4010fc | 0xcc2c | 0xc02c | 0x4f6 |
_allrem | 0x0 | 0x401100 | 0xcc30 | 0xc030 | 0x4fa |
_chkstk | 0x0 | 0x401104 | 0xcc34 | 0xc034 | 0x502 |
RtlUnwind | 0x0 | 0x401108 | 0xcc38 | 0xc038 | 0x396 |
NtQueryVirtualMemory | 0x0 | 0x40110c | 0xcc3c | 0xc03c | 0x135 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
dj0507.exe | 1 | 0x00400000 | 0x0040EFFF | Content Changed | - | 32-bit | 0x004070A6, 0x00406C91, ... |
![]() |
![]() |
...
|
dj0507.exe | 1 | 0x00400000 | 0x0040EFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.GlobeImposter.5906BF65 |
Malicious
|
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\Searches\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{f325f05b-f963-4640-a43b-c8a494cdda0f}\VC_redist.x86.exe.luboversova148 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\FeUF71vWxC-R_T0Mi7-7\Fg_0Wqv.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\7wwxc13fiAkyUN-6.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\lD1OmWx6 wB.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\pfo9l0XM-P.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\qdqKy6ZIloP1.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\XlTJHwmxjwUMC 3R.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_mnJpKAivBVA.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\TOw_H99qjPPLgXP7iZ2.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\s1HiXGpBYRKoGp\aiV14sXCwanauc_0Jp\Fa3PtmkW3ymwNZNw4SUb\wAFO4vF5Cr5e.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\KE9gMB601K4OO05_r.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Links\Downloads.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\Public\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Videos\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Videos\Sample Videos\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Recorded TV\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Recorded TV\Sample Media\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Pictures\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Music\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Music\Sample Music\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Music\Sample Music\Kalimba.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Music\Sample Music\Sleep Away.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Libraries\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Libraries\RecordedTV.library-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Downloads\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Documents\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Desktop\Adobe Reader X.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Desktop\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Desktop\Google Chrome.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Desktop\Mozilla Firefox.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG1 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\ntuser.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Videos\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Searches\Everywhere.search-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Searches\Indexed Locations.search-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Saved Games\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Pictures\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Music\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Links\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Links\Desktop.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Links\Downloads.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Links\RecentPlaces.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\Windows Live\Get Windows Live.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\Windows Live\Windows Live Gallery.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\Windows Live\Windows Live Mail.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\Windows Live\Windows Live Spaces.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\MSN Websites\MSN Autos.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\MSN Websites\MSN.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\Links\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Favorites\Links\Web Slice Gallery.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Default\Downloads\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Documents\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Desktop\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Contacts\Administrator.contact | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\Contacts\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\AppData\Local\IconCache.db | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Sun\Java\Java Update\jaureglist.xml.luboversova148 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\cab1.cab.luboversova148 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\vc_runtimeAdditional_x86.msi.luboversova148 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{f325f05b-f963-4640-a43b-c8a494cdda0f}\state.rsm.luboversova148 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{e6e75766-da0f-4ba2-9788-6ea593ce702d}\state.rsm.luboversova148 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{e6e75766-da0f-4ba2-9788-6ea593ce702d}\vcredist_x86.exe.luboversova148 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Adobe\ARM\Reader_10.0.0\AdbeRdrSecUpd10111.msp.luboversova148 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Adobe\ARM\Reader_10.0.0\AdbeRdrUpd10110_MUI.msp.luboversova148 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Adobe\ARM\Reader_10.0.0\AdbeRdrUpd10116_MUI.msp.luboversova148 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\ntuser.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\0HOB0.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\I88KCnzu34A.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\y4AlXAUP\cOAktq9wSdswv-NZxD.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\y4AlXAUP\dtFxIR0O8g-_4kxZ.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\y4AlXAUP\owQkwXYCL9 2BqMzJl.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\y4AlXAUP\qNc6CPYLId4I.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\y4AlXAUP\Y04jiS_ZS9NNx.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\y4AlXAUP\zPr-sLw.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\y4AlXAUP\VFdf84Pcuzqu-5Bnc\ewMZZ.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\y4AlXAUP\VFdf84Pcuzqu-5Bnc\xbawAnIdaT.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\y4AlXAUP\AcozpIXeVDq5gk5q\5 Z_u.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\y4AlXAUP\AcozpIXeVDq5gk5q\AAOb1NLtDy61Lpve.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\y4AlXAUP\AcozpIXeVDq5gk5q\NT7U.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\y4AlXAUP\AcozpIXeVDq5gk5q\TnU1xeo8nVk3wILla7V.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\JZceueVrm\GE_svmz.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\JZceueVrm\IlW2ME5IaW-G0iOE8r.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\JZceueVrm\SK9hXfhPZjeURvdk\4VE6.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\JZceueVrm\SK9hXfhPZjeURvdk\EtUTp5lXdblWrZY.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\JZceueVrm\SK9hXfhPZjeURvdk\IT2tXj7aBB61USw.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\JZceueVrm\SK9hXfhPZjeURvdk\Ofq31KQQe AIpZpvIA.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\JZceueVrm\SK9hXfhPZjeURvdk\WGmUVebys.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\FeUF71vWxC-R_T0Mi7-7\FkVojblw_THpWOw9G.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\FeUF71vWxC-R_T0Mi7-7\SI3i-9iw3YOt-N3Y7gVH.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\FeUF71vWxC-R_T0Mi7-7\u1aH6_TpTgql5gjSa.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\FeUF71vWxC-R_T0Mi7-7\v Uf1zPXLrjtT2Y.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\FeUF71vWxC-R_T0Mi7-7\ZWc_lQ7.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Searches\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Searches\Everywhere.search-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Searches\Indexed Locations.search-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Saved Games\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\3cQGxU2J.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\3uMF3M.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\5MEAA_d-KkzvlL0W.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\6F6-y ghi.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8B5H1PyBXY.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8pRh_UY0A.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AQtCr7oJ9HJB.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\CmCmd0VgS6gNq2pc2nC.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\DljeptCh-thzJygXIn.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EF1wUUaZL.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Eo6Akl9Okoy.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EY d-WIM.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\f26gPQbwYG.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\fBtEYgoyC.png | Modified File | Audio |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\H7TK5.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\i4FAGRLi6WxJW6pav.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ib23UmgUAw2bj.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\iEg1u5NDh4.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\iH_VhYMkHO78Kv1VNP.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\l76uY.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\mmjganv2qFg G8.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\moSuT1EQh15G9ERw.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\otsSFwKc09mG.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\sb4B9JCoTqMXmvOM.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VGfzC6Ai6Ue.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\WmEISnC qtcxr.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\WxM1e9Ho.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_sNaR-bNceAGJg9At.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_X5ue7QgQ.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\CCDfkJCbcUM67_ dTzte.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZHPR9I_CokTPDHHq.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\x8YM0GdT--\aa3UjR6r8x.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\x8YM0GdT--\dGfrJ.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\x8YM0GdT--\DhOa.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\x8YM0GdT--\GlJhw4cdqMqktIg.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\x8YM0GdT--\Jguwe0YD9cquJaXN.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\x8YM0GdT--\roMmT9bTP7uwqlq6RV.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\I0pL.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\Kwf2b9uJZFoNmD-.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\nofZEZ2ch9C6w3.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\VVSq6cNNJ2-oK8KN.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\YyyHZAK-RfbkGt.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\s1HiXGpBYRKoGp\00VS3kJJ6MNiiE.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\s1HiXGpBYRKoGp\2koGnzhXvlu6y.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\s1HiXGpBYRKoGp\WMW-H.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\s1HiXGpBYRKoGp\aiV14sXCwanauc_0Jp\Fm 4i194M2.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\s1HiXGpBYRKoGp\aiV14sXCwanauc_0Jp\Fa3PtmkW3ymwNZNw4SUb\m4xgCRpN8aOD.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\s1HiXGpBYRKoGp\aiV14sXCwanauc_0Jp\Fa3PtmkW3ymwNZNw4SUb\mBDb1CGhui.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\s1HiXGpBYRKoGp\aiV14sXCwanauc_0Jp\Fa3PtmkW3ymwNZNw4SUb\oqTPpEL_gge8Q.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\s1HiXGpBYRKoGp\aiV14sXCwanauc_0Jp\Fa3PtmkW3ymwNZNw4SUb\we7A41R.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\sNl_-UFQ.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\OEfaKVM_w\4L8q.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\OEfaKVM_w\nmNoD1VwZqXI9w9o-.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\OEfaKVM_w\o0wrpWmKB7YecEnye.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\OEfaKVM_w\QV_Oa.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\OEfaKVM_w\RUJFRwpqdcG.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\OEfaKVM_w\LdVCG8zU\6xQggsforu5AFkuJh1.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\OEfaKVM_w\LdVCG8zU\G9YMUm1RPcJ.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\OEfaKVM_w\LdVCG8zU\HxuODNreV7t5.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\OEfaKVM_w\LdVCG8zU\IWtK4Cm-OX8r7QT9Y.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\OEfaKVM_w\LdVCG8zU\k4nB-wWqxpU90.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\OEfaKVM_w\LdVCG8zU\qSJd6mYPrkgRnG.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\OEfaKVM_w\LdVCG8zU\GQF6ziPJ -gMDGHFtj\bv2O2SANKrHifB8.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\OEfaKVM_w\LdVCG8zU\GQF6ziPJ -gMDGHFtj\qR4RuVMJgnfmu3HeG0o.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qeIzZOjIaq\dkE4YLiQ9mlXfY\197n9jzI7Xoe14nTxyBU\OEfaKVM_w\LdVCG8zU\GQF6ziPJ -gMDGHFtj\x6G_mHOgSpXK.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Links\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Links\Desktop.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Links\RecentPlaces.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\Public\FA28CEBC2E33EFC43108410E5485331570DE0D6409C427058B6568CB4612E2D3 | Dropped File | Text |
Not Queried
|
...
|
»