VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
udxgjs.exe
Windows Exe (x86-32)
Created 6 years ago
Remarks (2/2)
(0x200000e): The overall sleep time of all monitored processes was truncated from "1 minute, 30 seconds" to "30 seconds" to reveal dormant functionality.
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\udxgjs.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-07-04 10:05 (UTC+2) |
Last Seen | 2019-07-22 23:57 (UTC+2) |
Names | Win32.Trojan.Filecoder |
Families | Filecoder |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x401000 |
Size Of Code | 0x1000 |
Size Of Initialized Data | 0x2000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-06-28 10:21:34+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xfe8 | 0x1000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.55 |
.rdata | 0x402000 | 0x72c | 0x800 | 0x1400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.data | 0x403000 | 0x1760 | 0x1200 | 0x1c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.84 |
Imports (4)
»
kernel32.dll (44)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleFileNameA | 0x0 | 0x402044 | 0x21c8 | 0x15c8 | 0x132 |
GetSystemTimeAsFileTime | 0x0 | 0x402048 | 0x21cc | 0x15cc | 0x179 |
GlobalAlloc | 0x0 | 0x40204c | 0x21d0 | 0x15d0 | 0x1a5 |
GlobalFree | 0x0 | 0x402050 | 0x21d4 | 0x15d4 | 0x1ac |
GlobalMemoryStatus | 0x0 | 0x402054 | 0x21d8 | 0x15d8 | 0x1b1 |
MapViewOfFile | 0x0 | 0x402058 | 0x21dc | 0x15dc | 0x200 |
MoveFileW | 0x0 | 0x40205c | 0x21e0 | 0x15e0 | 0x207 |
MultiByteToWideChar | 0x0 | 0x402060 | 0x21e4 | 0x15e4 | 0x20b |
OpenProcess | 0x0 | 0x402064 | 0x21e8 | 0x15e8 | 0x216 |
Process32FirstW | 0x0 | 0x402068 | 0x21ec | 0x15ec | 0x223 |
Process32NextW | 0x0 | 0x40206c | 0x21f0 | 0x15f0 | 0x224 |
RtlZeroMemory | 0x0 | 0x402070 | 0x21f4 | 0x15f4 | 0x258 |
SetErrorMode | 0x0 | 0x402074 | 0x21f8 | 0x15f8 | 0x27f |
GetLogicalDrives | 0x0 | 0x402078 | 0x21fc | 0x15fc | 0x12e |
SetFilePointerEx | 0x0 | 0x40207c | 0x2200 | 0x1600 | 0x286 |
Sleep | 0x0 | 0x402080 | 0x2204 | 0x1604 | 0x2b7 |
TerminateProcess | 0x0 | 0x402084 | 0x2208 | 0x1608 | 0x2bf |
UnmapViewOfFile | 0x0 | 0x402088 | 0x220c | 0x160c | 0x2cf |
WriteFile | 0x0 | 0x40208c | 0x2210 | 0x1610 | 0x2f7 |
lstrcatA | 0x0 | 0x402090 | 0x2214 | 0x1614 | 0x30f |
lstrcatW | 0x0 | 0x402094 | 0x2218 | 0x1618 | 0x310 |
lstrcmpW | 0x0 | 0x402098 | 0x221c | 0x161c | 0x312 |
lstrcmpiA | 0x0 | 0x40209c | 0x2220 | 0x1620 | 0x313 |
lstrcmpiW | 0x0 | 0x4020a0 | 0x2224 | 0x1624 | 0x314 |
lstrcpyW | 0x0 | 0x4020a4 | 0x2228 | 0x1628 | 0x316 |
lstrlenA | 0x0 | 0x4020a8 | 0x222c | 0x162c | 0x319 |
lstrlenW | 0x0 | 0x4020ac | 0x2230 | 0x1630 | 0x31a |
GetLastError | 0x0 | 0x4020b0 | 0x2234 | 0x1634 | 0x128 |
GetFileAttributesW | 0x0 | 0x4020b4 | 0x2238 | 0x1638 | 0x11a |
GetEnvironmentVariableA | 0x0 | 0x4020b8 | 0x223c | 0x163c | 0x113 |
GetDateFormatA | 0x0 | 0x4020bc | 0x2240 | 0x1640 | 0x104 |
GetCurrentProcessId | 0x0 | 0x4020c0 | 0x2244 | 0x1644 | 0x101 |
FindNextFileW | 0x0 | 0x4020c4 | 0x2248 | 0x1648 | 0xbb |
FindFirstFileW | 0x0 | 0x4020c8 | 0x224c | 0x164c | 0xb4 |
FindClose | 0x0 | 0x4020cc | 0x2250 | 0x1650 | 0xad |
FileTimeToSystemTime | 0x0 | 0x4020d0 | 0x2254 | 0x1654 | 0xa4 |
CreateToolhelp32Snapshot | 0x0 | 0x4020d4 | 0x2258 | 0x1658 | 0x59 |
CreateThread | 0x0 | 0x4020d8 | 0x225c | 0x165c | 0x56 |
CreateFileW | 0x0 | 0x4020dc | 0x2260 | 0x1660 | 0x40 |
CreateFileMappingA | 0x0 | 0x4020e0 | 0x2264 | 0x1664 | 0x3e |
CreateFileA | 0x0 | 0x4020e4 | 0x2268 | 0x1668 | 0x3d |
CopyFileA | 0x0 | 0x4020e8 | 0x226c | 0x166c | 0x2e |
SetFileAttributesW | 0x0 | 0x4020ec | 0x2270 | 0x1670 | 0x284 |
CloseHandle | 0x0 | 0x4020f0 | 0x2274 | 0x1674 | 0x23 |
shell32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHChangeNotify | 0x0 | 0x402108 | 0x228c | 0x168c | 0x60 |
ShellExecuteA | 0x0 | 0x40210c | 0x2290 | 0x1690 | 0xd9 |
advapi32.dll (16)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyExA | 0x0 | 0x402000 | 0x2184 | 0x1584 | 0x1d0 |
RegCloseKey | 0x0 | 0x402004 | 0x2188 | 0x1588 | 0x1b7 |
OpenProcessToken | 0x0 | 0x402008 | 0x218c | 0x158c | 0x198 |
LookupPrivilegeValueA | 0x0 | 0x40200c | 0x2190 | 0x1590 | 0x141 |
CryptReleaseContext | 0x0 | 0x402010 | 0x2194 | 0x1594 | 0x98 |
CryptImportKey | 0x0 | 0x402014 | 0x2198 | 0x1598 | 0x97 |
CryptGenKey | 0x0 | 0x402018 | 0x219c | 0x159c | 0x8d |
CryptExportKey | 0x0 | 0x40201c | 0x21a0 | 0x15a0 | 0x8c |
CryptEncrypt | 0x0 | 0x402020 | 0x21a4 | 0x15a4 | 0x87 |
CryptDestroyKey | 0x0 | 0x402024 | 0x21a8 | 0x15a8 | 0x84 |
CryptDecrypt | 0x0 | 0x402028 | 0x21ac | 0x15ac | 0x81 |
CryptAcquireContextA | 0x0 | 0x40202c | 0x21b0 | 0x15b0 | 0x7d |
AdjustTokenPrivileges | 0x0 | 0x402030 | 0x21b4 | 0x15b4 | 0x19 |
RegQueryValueExA | 0x0 | 0x402034 | 0x21b8 | 0x15b8 | 0x1da |
RegSetValueExA | 0x0 | 0x402038 | 0x21bc | 0x15bc | 0x1e7 |
RegCreateKeyA | 0x0 | 0x40203c | 0x21c0 | 0x15c0 | 0x1ba |
mpr.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetOpenEnumA | 0x0 | 0x4020f8 | 0x227c | 0x167c | 0x25 |
WNetEnumResourceA | 0x0 | 0x4020fc | 0x2280 | 0x1680 | 0x13 |
WNetCloseEnum | 0x0 | 0x402100 | 0x2284 | 0x1684 | 0xc |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
udxgjs.exe | 1 | 0x00400000 | 0x00404FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Win32.AV-Killer.amW@ae4J0Ed |
Malicious
|
\\?\C:\BOOTSECT.BAK.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\BOOTSTAT.DAT.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\centuries.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\detected-persistent-luther.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Sync Framework\reproducedmelissa.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Synchronization Services\outcomes-increasing.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Uninstall Information\israel.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Internet Explorer\SIGNUP\install.ins.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Document Themes 14\Adjacency.thmx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Internet Explorer\SIGNUP\install.ins.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Sync Framework\silicon_mu.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Java\jre7\COPYRIGHT.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Java\jre7\LICENSE.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Java\jre7\README.txt.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Java\jre7\release.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\Office14\AUTHZAX.DLL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Java\jre7\THIRDPARTYLICENSEREADME-JAVAFX.txt.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\IdentityCRL\ppcrlconfig.dll.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\MF\Pending.GRL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Java\jre7\THIRDPARTYLICENSEREADME.txt.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\OFFICE\AssetLibrary.ico.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft SQL Server Compact Edition\v3.5\sqlceca35.dll.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\-otFpnJAZYdGZgph-w2t.mp4.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\34Y20Hy8prQawh8W.odt.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\5NyfavX8M SwrLA.m4a.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\CbGRfnknZGA7NbXr.pptx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3gVd0.ppt.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\AIc9Isj7ADRjNzHWRWF_.pptx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3lrLEIdmVjd2 rgfcu.wav.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HS115HKsxh5.mp3.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\hXTeLs-.png.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IUA5z.png.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\JYhU_0gVh.swf.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\28F4t8tm71.mp3.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\4AhrnACXRo8vjDqPzc.mp3.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\Downloads.lnk.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\dso03pCxSlJZc_V5rD.xlsx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft.NET\RedistList\AssemblyList_4_client.xml.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\GXhem_I.pptx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\imbV OAx3F1cWZTn03J.docx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Public\Downloads\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft.NET\RedistList\AssemblyList_4_extended.xml.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Public\Music\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Public\Pictures\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Public\Libraries\RecordedTV.library-ms.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Default\Desktop\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Default\Documents\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\F7VVSodfwxzw.mp3.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\GYpujz6bZyZcO-T7R.mp3.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\KjsS.m4a.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\odMVujhZ6CV.mkv.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\RecentPlaces.lnk.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pXo9jRY.wav.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft.NET\Primary Interop Assemblies\adodb.dll.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\User Account Pictures\guest.bmp.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Fw8HolHjfbNy4TO.bmp.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Saved Games\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Searches\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Searches\Indexed Locations.search-ms.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Public\Videos\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Mozilla Firefox\AccessibleMarshal.dll.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Mozilla Firefox\application.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\Hx.hxn.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.EXCEL.14.1033.hxn.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.EXCEL.DEV.14.1033.hxn.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\L33cwZgAwdRp0L9II.xlsx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\HIFLZmmHRuFv.mp3.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Default\Contacts\Administrator.contact.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Document Themes 14\Apothecary.thmx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Mozilla Firefox\breakpadinjector.dll.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Default\Contacts\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft SQL Server Compact Edition\v3.5\sqlceer35EN.dll.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\8YZI9tbYOTKzo.ppt.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\bDIINWA2WJqh.mkv.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Compressed |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Visual Studio 8\VSTA\Bin\VSTAClientPkg.dll.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Stationery\Desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\FBIBLIO.DLL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\CAGCAT10.DLL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00004_.GIF.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00011_.GIF.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\FDATE.DLL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\dEs-EDIfkd iqMCvgGmm\LhqwkdHvHp.pps.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\dEs-EDIfkd iqMCvgGmm\O86Jsoq0pVAcuu.docx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00021_.GIF.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Default\Favorites\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Default\Music\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Uninstall Information\deviant-potential-mistakes.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Default\Links\Desktop.lnk.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Windows Defender\improving-birmingham.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Office14\1033\ACCESS12.ACC.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\dEs-EDIfkd iqMCvgGmm\uqnC-qDAk9uWzh2.doc.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Analysis Services\AS OLEDB\10\msmdlocal.dll.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.msi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Mozilla\logs\maintenanceservice-install.log.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\OFFICE\SharePointPortalSite.ico.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\OFFICE\SharePointTeamSite.ico.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p5E94XWFFk\9gTfF.mkv.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p5E94XWFFk\b1Sb6k4ypsm.mp3.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p5E94XWFFk\QbAGsrc4RZ.avi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\dEs-EDIfkd iqMCvgGmm\vRdpPed7cbcKAIsGT.ods.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\DW20.EXE.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\CAGCAT10.MMW.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Default\AppData\Local\IconCache.db.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft.NET\Primary Interop Assemblies\Microsoft.mshtml.dll.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Default\Links\RecentPlaces.lnk.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Windows Mail\ways_get_musicians.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\MSBuild\Microsoft.Office.InfoPath.targets.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\JNTkGdgD9rpv-.mp3.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RHlI3aC51oLl.avi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Office14\ACCDDSLM.DLL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\HhnogPUR3.avi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\RAC\Temp\sql3793.tmp.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\PcaDFoPfMRf61DpJA\1m1Vmuba.jpg.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\Wks9Pxy.cnv.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\CH4x6fQHSG1JHPS3ch5A.mp4.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Common Files\microsoft shared\VSTO\ActionsPane3.xsd.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00037_.GIF.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Document Themes 14\Aspect.thmx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\FPERSON.DLL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Public\Videos\Sample Videos\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\pjpe1PfeOP\A-ruelEk.bmp.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\pjpe1PfeOP\aKHBF.png.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\pjpe1PfeOP\g-knkuKhkJ2I8jMff9.gif.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.GROOVE.14.1033.hxn.[ID]hWWph9uJUOOy4hF1[ID] | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files (x86)\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\association ongoing artistic.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Microsoft Sync Framework\ceremony.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Microsoft Sync Framework\hometown_estate.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\MSBuild\pursuitbed.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\MSBuild\role.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Public\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\DESIGNER\MSADDNDR.DLL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files (x86)\Adobe\diary.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Document Themes 14\Angles.thmx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\Office14\BCSLaunch.dll.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\MF\Active.GRL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files (x86)\Java\jre7\Welcome.html.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\OFFICE\DocumentRepository.ico.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\IdentityCRL\ppcrlui.dll.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0QFeq.jpg.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\81Y6laQwMZt0iND.jpg.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\AB_vXOL0ok.avi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\1 2o4p5zHCb-fvAtztO.rtf.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\cn-HP5pWv wNnDGY4YF7.xlsx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Ffy2.mp4.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fW6GLbq3Ftca.bmp.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fxONycb0H.mp3.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gXq1w 2VVTzCJBe Hq.wav.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Downloads\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\1OrzHNREAkWyGRcOhFv.mp3.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\dilf19.docx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\dmhLA6w_YLOh5kl hnV.pptx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\Desktop.lnk.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\Office14\DGRMLNCH.DLL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Document Themes 14\Apex.thmx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KqudnBky5y.docx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\7rpWX8QM.m4a.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Documents\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Libraries\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Recorded TV\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\7szc_Fu5fkpO.wav.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\O8t8zV01Bvm4sS9lF.xlsx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OSIlz2Qe-sd.wav.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RB4vj.mp4.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Office14\ACCDDS.DLL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\User Account Pictures\user.bmp.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\9yivo5.gif.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Searches\Everywhere.search-ms.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9lMGhV91NDMpqht7Q.avi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RGRq4.wav.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\fP I YrA_L5y0L.swf.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Microsoft SQL Server Compact Edition\v3.5\sqlcecompact35.dll.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\OFFICE\MySharePoints.ico.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Office14\ACCDDSF.DLL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\OfficeSoftwareProtectionPlatform\tokens.dat.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\OFFICE\MySite.ico.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\BA-yZXQD61PJRw.flv.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\bmxWLLNd8TjkPhuK.m4a.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Office14\1033\ACCDDSUI.DLL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Visual Studio 8\VSTA\Bin\VSTAProject.dll.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\MSCONV97.DLL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\dEs-EDIfkd iqMCvgGmm\jN9TBQMyqFYmB5Rvq.ots.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Downloads\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\RECOVR32.CNV.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Audio |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\GDIPFONTCACHEV1.DAT.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Links\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Links\Downloads.lnk.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveLR.cab.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.msi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\msmdlocal.dll.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Music\Sample Music\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Recorded TV\Sample Media\desktop.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files (x86)\Adobe\Reader 10.0\Benioku.htm.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.msi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.msi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files (x86)\Mozilla Firefox\crashreporter.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Windows Media Player\brooklyn variations nothing.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Windows Photo Viewer\ensure.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Desktop\Adobe Reader X.lnk.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files (x86)\Windows Sidebar\settings.ini.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Windows Sidebar\frederick_manufacturing.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Windows Portable Devices\large.exe.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\lrVIyqwWp.xlsx.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\wOarRpMQhZLo-EiPn.jpg.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.GRAPH.14.1033.hxn.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.msi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioLR.cab.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Stationery\1033\CURRENCY.GIF.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdf.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-07132009-221054.log.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\4H-Oizv5lIrvjR1O9\8y51R.png.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Music\Sample Music\Kalimba.mp3.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.msi.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\MSB1AR.LEX.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\pjpe1PfeOP\58 _CW2YhTWDYT.bmp.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\pjpe1PfeOP\L6TZ6kzRLOi0t-.gif.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\pjpe1PfeOP\Nabr7D0X8dDzA.bmp.[ID]hWWph9uJUOOy4hF1[ID] | Dropped File | Stream |
Not Queried
|
...
|
»