VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
OnyxLocker.exe
Windows Exe (x86-32)
Created at 2019-10-05T23:39:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OnyxLocker.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-10-01 23:47 (UTC+2) |
Last Seen | 2019-10-05 02:34 (UTC+2) |
Names | ByteCode-MSIL.Trojan.Encoder |
Families | Encoder |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x406406 |
Size Of Code | 0x4600 |
Size Of Initialized Data | 0x800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2094-01-04 21:34:38+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | - |
FileDescription | OnyxLocker |
FileVersion | 1.0.0.0 |
InternalName | OnyxLocker.exe |
LegalCopyright | Copyright © 2019 |
LegalTrademarks | - |
OriginalFilename | OnyxLocker.exe |
ProductName | OnyxLocker |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x440c | 0x4600 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.2 |
.rsrc | 0x408000 | 0x5bc | 0x600 | 0x4800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.1 |
.reloc | 0x40a000 | 0xc | 0x200 | 0x4e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.08 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x63dc | 0x45dc | 0x0 |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.32536925 |
Malicious
|
c:\users\5p5nrgjn0js halpmcxz\desktop\041p-mkjy.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\0i2o2gdqvsnq4.jpg | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\0ayntq6 hmmrk7r.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\1fx9d.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\4sl7hhq3j1-s_a.pptx | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\-gmwijx5.mp3 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\a4zu5utea_camxnbqmu.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\0agofzdjrcj.png | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\c3dqr-.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\cb0jhs.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\csl9t4.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\5ow2gacwg72jq8.gif | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\adisqdhf.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\e-9ikdbffraqrpgx1x.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\ak-me0zyuoyq.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\fhse_-j994cefqfp.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\b1vruukxcd.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\bjgcc865hqufjejo.mp3 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\n7wltufdyz.docx | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\grdc-.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nchym3jvtc2niedq8ou.xlsx | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\gie-.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\o1c4wo8fwewe4s.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\qwqgbk_.xlsx | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\kyhjfexvjp.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\tf-l7vanenlu.xlsx | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\tsrgn _7sdhapjt.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\u_9aejyvl3.pptx | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\v1knoyjfdjz-mnlncb.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\ymvrl71rfcouvu257u.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\jrycn4nc3nzvcyucq.jpg | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\o-r_gy.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\6ausdyoxbw67yazx.pdf | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\7cj-dofuxd5ylobyzbu.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\lcgi04v\yuoswxczh.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\lcgi04v\bkkqxlkcc7\capfuey7k f h0ng_2og.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\lcgi04v\bkkqxlkcc7\ivdtbrm069lbyx-k.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\lcgi04v\t5fa8nh\ixiauuz6k.gif | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\lcgi04v\t5fa8nh\ozxlxa gt1.gif | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\h6yxjyx\l2mem.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\h6yxjyx\sa2qvvzw.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\8sura_vkvu3qhjvwtvqy.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\ao7vq3pcjkg0p1r8q-.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\t0lt86ykdvn ztr7al9\vxtafjjvz90n6b.png | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\c5rmsd6d2zrxxgekh ww.rtf | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\t0lt86ykdvn ztr7al9\_lpqo66zv4ajw9sjgw.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\t0lt86ykdvn ztr7al9\ile-\iyvgw.png | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\nn8ymbrdlb9_5o2.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\z6mi.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\t0lt86ykdvn ztr7al9\ile-\q2z3dxu.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\2hx-o1_ct2d-u_wz.flv | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\job0jiv_j9e.jpg | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\q ast.mp4 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\jteivarcttikhqvv3k.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\t0lt86ykdvn ztr7al9\ile-\zp9g panzmladxrly.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\kg9pm5p0m9uh4z6p.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\knopib20dlu.wav | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\s9eplzwe.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\sco8vgcocaam8zxjlk.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\txs32r9qw0.mp3 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\shwlyjyqlxrto4khkkif.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\hg6y\e1rvdpxj8.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\wmbuqq5hjh.mp3 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\4s-nm.doc | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\hg6y\oenql4d71yivkco.flv | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\5pcsqjmx bsvfa8\1epiapcj.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\5pcsqjmx bsvfa8\6_j7tc0hobl_vcfxe.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\klxubww_mfi.doc | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\pgob3jc5d.docx | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\qp m xnef4\6oakol1bo.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\qp m xnef4\bx26dxogbddu91it.odt | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\5pcsqjmx bsvfa8\wixid9t.png | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\qp m xnef4\cpaiw dtkx3k7qfeb53.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\qp m xnef4\jtpsdt.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\2hgp7jn\aww0fonxqpe6sjxux_k9.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\qp m xnef4\l-fnnafsjg7eq.csv | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\2hgp7jn\npuv2.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\qp m xnef4\9br0qi-aac\amxd.odt | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\x2azany7xrvk\pjlpj3m.avi | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\x2azany7xrvk\1fod_i\bzxaz3lc8 0gnwdg.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\5pcsqjmx bsvfa8\wyvh70r5 hwd.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\2hgp7jn\iuy i6plh2plgbwaq\5zp0ok sml.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\x2azany7xrvk\1fod_i\qa42p0bzv.flv | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\qp m xnef4\9br0qi-aac\hiongzm8ro0r.pptx | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\2hgp7jn\iuy i6plh2plgbwaq\dsj9srivhwkg.mp3 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\x2azany7xrvk\b2apjyvo cep\ixfjqy4skk 8ihirsjj.avi | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\qp m xnef4\9br0qi-aac\uqhk5q_qa.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\x2azany7xrvk\b2apjyvo cep\mhr725yntfmhml_-ok.flv | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\2hgp7jn\iuy i6plh2plgbwaq\gb4_a6etosqdvxdg.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\qp m xnef4\9br0qi-aac\z9dztjpsszvuwoxmt.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\x2azany7xrvk\b2apjyvo cep\lblgye9pbpjfaw\c_ojnilokbi6fmnshkb.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\2hgp7jn\iuy i6plh2plgbwaq\uplo.mp3 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\x2azany7xrvk\b2apjyvo cep\lblgye9pbpjfaw\raxniu tep3ws.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\qp m xnef4\uyrceatuz6h\vtaog.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\x2azany7xrvk\b2apjyvo cep\lblgye9pbpjfaw\k1wo-3\aoace6bpt-fpf 9.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\qp m xnef4\uyrceatuz6h\ywizjs.odp | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\x2azany7xrvk\b2apjyvo cep\lblgye9pbpjfaw\k1wo-3\so6b7g_jn2sug.avi | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\excelmui.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\document building blocks\1033\14\built-in building blocks.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\powerpointmui.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\publishermui.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\internet explorer\quick launch\launch internet explorer browser.lnk | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\internet explorer\quick launch\shows desktop.lnk | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\mozilla firefox.lnk | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\windows explorer (2).lnk | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\wordmui.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\windows media player.lnk | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\proof.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.es\proof.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.fr\proof.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\office32mui.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\setup.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\office\recent\global.lnk | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\infopathmui.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\outlook\outlook.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-00b4-0409-1000-0000000ff1ce}-c\projectmui.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-00b4-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dw20.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dwtrig20.exe | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\5p5nrgjn0js_halpmcxz@adobe[3].onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\5p5nrgjn0js_halpmcxz@demdex[1].onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\5p5nrgjn0js_halpmcxz@dpm.demdex[2].txt | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\5p5nrgjn0js_halpmcxz@everesttech[1].onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\5p5nrgjn0js_halpmcxz@google[2].txt | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\setup.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@ad13.adfarm1.adition[1].onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@adform[1].txt | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@adnxs[1].onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@adtech[2].onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\accessmui.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@advertising[1].onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@api.bing[2].onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@at.atwola[1].txt | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@google[1].onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@google[4].txt | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@m.exactag[1].txt | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@scorecardresearch[2].onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@server.adformdsp[1].txt | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@track.adform[2].txt | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@www.linkedin[1].onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@www.msn[2].txt | Modified File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{91140000-003b-0000-1000-0000000ff1ce}-c\office32ww.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{91140000-003b-0000-1000-0000000ff1ce}-c\ose.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{91140000-003b-0000-1000-0000000ff1ce}-c\prjprorww.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\msocache\all users\{91140000-0011-0000-1000-0000000ff1ce}-c\setup.onx | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\-q oedf3qfaisdais.doc | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\4kpv.jpg | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\2mht.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\huqp4v.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\mcfxnvur8.docx | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\lcgi04v\b4xfoqhmmw6par-1q bn.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\h6hi.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\t4rg _as6dc5_lil.flv | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\5wsi.wav | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\lcgi04v\wvizli-el8.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\hsacyb0rtc089xtyg8s.ppt | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\hssybc.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\ktkz.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\h6yxjyx\eeoaimly2m617-e.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\lcgi04v\bkkqxlkcc7\2 phssyqb9oneusaf7el.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\lcgi04v\cuhdhurvog6lsbivkuk\vlovhd.png | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\lcgi04v\cuhdhurvog6lsbivkuk\cyqjki12yd-zl3i4tbus\enoalwpxmsrki.gif | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\m4_czbjz46tuk3so7e.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\t0lt86ykdvn ztr7al9\-uwmv wnhtk.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\aso6jqoi0cqyyi2.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\baxpzux9n 4ntg.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\t0lt86ykdvn ztr7al9\i5_4cpyvacgz 0zn.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\bbnwh4.png | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\weszw6l6x8egu88.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\g3cdzt8s6a2sk1jvi.jpg | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\py3r9l3.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\hgitmhz.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\q wdmzwyyn0pship2.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\nr6w6zqzel.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\rr212zchee9a 4dterg.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\usou.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\rzar.wav | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\wntpp5pzmex6.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\f9suulloy99.pdf | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\wwbyz.wav | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\fm5m.doc | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\y2 btjuu1ieyknhlo_r_.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\_ay6.ppt | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\l4fmglk.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\vklzlyrr2622e.doc | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\2hgp7jn\6clu5j4 vddqy5.wav | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\qp m xnef4\yn-v1k3r3hpfqkmtr2ti.odp | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\adobe\acrobat\10.0\javascripts\glob.settings.onx | Dropped File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\2hgp7jn\oampi1gliu.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\pictures\t0lt86ykdvn ztr7al9\tzydys\2udb.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\2hgp7jn\sb87336otcj6b.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\2hgp7jn\iuy i6plh2plgbwaq\fan8potwvh8n1_jbusiq.wav | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\qp m xnef4\9br0qi-aac\vxntn5at5rll4m.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\x2azany7xrvk\b2apjyvo cep\ym-xvfad.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\nrzhup9ri rtgx\qp m xnef4\9br0qi-aac\vycqu2.rtf | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\2hgp7jn\iuy i6plh2plgbwaq\qg1_zbvj6bide.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\2hgp7jn\iuy i6plh2plgbwaq\tlqyvhsgmfyyavlc.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\music\2hgp7jn\iuy i6plh2plgbwaq\xptye7bv5upgjln.wav | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\videos\ugttrwkgd\xbr9xm0\tmbexhdxcmufktsjj\x2azany7xrvk\b2apjyvo cep\lblgye9pbpjfaw\k1wo-3\ohmlz9yjbvzc.avi | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\outlook files\voeimd@djhreuu.uhd.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\documents\xcfeu\0gs6ntg0zcx.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\internet explorer\quick launch\google chrome.lnk | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\internet explorer\quick launch\window switcher.lnk | Modified File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\outlookmui.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\google chrome.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\internet explorer (2).lnk | Modified File | Unknown |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\internet explorer.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\windows media player (2).onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proofing.xml | Modified File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\office\recent\templates.lnk | Modified File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-0054-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-0054-0409-1000-0000000ff1ce}-c\visiomui.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\onenotemui.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\setup.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\groovemui.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\publisher building blocks\contentstore.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\5p5nrgjn0js_halpmcxz@adobe[1].txt | Modified File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\officemui.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\officemuiset.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\5p5nrgjn0js_halpmcxz@ml314[1].txt | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\5p5nrgjn0js_halpmcxz@rlcdn[2].txt | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@adfarm1.adition[2].txt | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@adformdsp[1].onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\accessmuiset.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@adtr02[1].txt | Modified File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\branding.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@bing[1].txt | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@c.bing[1].txt | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@c.msn[1].onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@doubleclick[2].onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@google[3].txt | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@linkedin[1].onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@msn[1].onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{91140000-0011-0000-1000-0000000ff1ce}-c\proplusrww.onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@skadtec[1].onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\low\5p5nrgjn0js_halpmcxz@www.bing[2].onx | Dropped File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{91140000-0011-0000-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
c:\msocache\all users\{91140000-003b-0000-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\Прочти меня! 6 .txt | Dropped File | Text |
Not Queried
|
...
|
»