VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
iphnlp.exe
Windows Exe (x86-32)
Created at 2019-05-31T20:11:00
Remarks (1/1)
(0x2000010): The operating system was rebooted during the analysis.
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Suspicious
|
First Seen | 2019-05-24 15:37 (UTC+2) |
Last Seen | 2019-05-29 17:49 (UTC+2) |
Names | Win32.Trojan.Mbt |
Families | Mbt |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x420ca0 |
Size Of Code | 0x37000 |
Size Of Initialized Data | 0x1fe00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-05-24 00:25:05+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x36ff2 | 0x37000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.22 |
.rdata | 0x438000 | 0xf9ea | 0xfa00 | 0x37400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.26 |
.data | 0x448000 | 0x10380 | 0x10400 | 0x46e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.97 |
Imports (13)
»
USER32.dll (19)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PostQuitMessage | 0x0 | 0x4381f4 | 0x46e30 | 0x46230 | 0x271 |
ShutdownBlockReasonCreate | 0x0 | 0x4381f8 | 0x46e34 | 0x46234 | 0x322 |
DefWindowProcA | 0x0 | 0x4381fc | 0x46e38 | 0x46238 | 0xa0 |
MessageBoxW | 0x0 | 0x438200 | 0x46e3c | 0x4623c | 0x24d |
AdjustWindowRect | 0x0 | 0x438204 | 0x46e40 | 0x46240 | 0x2 |
ShutdownBlockReasonDestroy | 0x0 | 0x438208 | 0x46e44 | 0x46244 | 0x323 |
RegisterClassExW | 0x0 | 0x43820c | 0x46e48 | 0x46248 | 0x289 |
CreateWindowExW | 0x0 | 0x438210 | 0x46e4c | 0x4624c | 0x71 |
CloseWindow | 0x0 | 0x438214 | 0x46e50 | 0x46250 | 0x4f |
wsprintfW | 0x0 | 0x438218 | 0x46e54 | 0x46254 | 0x37b |
GetForegroundWindow | 0x0 | 0x43821c | 0x46e58 | 0x46258 | 0x143 |
GetMessageA | 0x0 | 0x438220 | 0x46e5c | 0x4625c | 0x16f |
TranslateMessage | 0x0 | 0x438224 | 0x46e60 | 0x46260 | 0x33f |
DispatchMessageA | 0x0 | 0x438228 | 0x46e64 | 0x46264 | 0xb4 |
ReleaseDC | 0x0 | 0x43822c | 0x46e68 | 0x46268 | 0x2a5 |
EnumChildWindows | 0x0 | 0x438230 | 0x46e6c | 0x4626c | 0xec |
DeferWindowPos | 0x0 | 0x438234 | 0x46e70 | 0x46270 | 0xa2 |
DestroyWindow | 0x0 | 0x438238 | 0x46e74 | 0x46274 | 0xad |
AnimateWindow | 0x0 | 0x43823c | 0x46e78 | 0x46278 | 0x7 |
GDI32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DeleteObject | 0x0 | 0x438064 | 0x46ca0 | 0x460a0 | 0x10e |
SetPixel | 0x0 | 0x438068 | 0x46ca4 | 0x460a4 | 0x2f8 |
SelectPalette | 0x0 | 0x43806c | 0x46ca8 | 0x460a8 | 0x2d5 |
GetDeviceCaps | 0x0 | 0x438070 | 0x46cac | 0x460ac | 0x1f6 |
SetPaletteEntries | 0x0 | 0x438074 | 0x46cb0 | 0x460b0 | 0x2f7 |
KERNEL32.dll (77)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LocalAlloc | 0x0 | 0x43807c | 0x46cb8 | 0x460b8 | 0x3ae |
ReadFile | 0x0 | 0x438080 | 0x46cbc | 0x460bc | 0x44f |
CloseHandle | 0x0 | 0x438084 | 0x46cc0 | 0x460c0 | 0x7f |
WriteFile | 0x0 | 0x438088 | 0x46cc4 | 0x460c4 | 0x5df |
DeviceIoControl | 0x0 | 0x43808c | 0x46cc8 | 0x460c8 | 0x112 |
OpenMutexW | 0x0 | 0x438090 | 0x46ccc | 0x460cc | 0x3ea |
CreateMutexW | 0x0 | 0x438094 | 0x46cd0 | 0x460d0 | 0xd1 |
lstrlenA | 0x0 | 0x438098 | 0x46cd4 | 0x460d4 | 0x608 |
VirtualAlloc | 0x0 | 0x43809c | 0x46cd8 | 0x460d8 | 0x599 |
GetModuleHandleA | 0x0 | 0x4380a0 | 0x46cdc | 0x460dc | 0x264 |
LoadLibraryA | 0x0 | 0x4380a4 | 0x46ce0 | 0x460e0 | 0x3a5 |
CreateFileW | 0x0 | 0x4380a8 | 0x46ce4 | 0x460e4 | 0xc2 |
WaitForSingleObject | 0x0 | 0x4380ac | 0x46ce8 | 0x460e8 | 0x5a9 |
lstrcpyA | 0x0 | 0x4380b0 | 0x46cec | 0x460ec | 0x602 |
HeapAlloc | 0x0 | 0x4380b4 | 0x46cf0 | 0x460f0 | 0x32f |
lstrcatA | 0x0 | 0x4380b8 | 0x46cf4 | 0x460f4 | 0x5f9 |
GetProcAddress | 0x0 | 0x4380bc | 0x46cf8 | 0x460f8 | 0x29d |
OutputDebugStringW | 0x0 | 0x4380c0 | 0x46cfc | 0x460fc | 0x3fa |
GetTickCount | 0x0 | 0x4380c4 | 0x46d00 | 0x46100 | 0x2f2 |
TlsGetValue | 0x0 | 0x4380c8 | 0x46d04 | 0x46104 | 0x573 |
TlsSetValue | 0x0 | 0x4380cc | 0x46d08 | 0x46108 | 0x574 |
lstrcatW | 0x0 | 0x4380d0 | 0x46d0c | 0x4610c | 0x5fa |
ExitThread | 0x0 | 0x4380d4 | 0x46d10 | 0x46110 | 0x152 |
GetFileSize | 0x0 | 0x4380d8 | 0x46d14 | 0x46114 | 0x23b |
ExitProcess | 0x0 | 0x4380dc | 0x46d18 | 0x46118 | 0x151 |
VirtualFree | 0x0 | 0x4380e0 | 0x46d1c | 0x4611c | 0x59c |
CreateToolhelp32Snapshot | 0x0 | 0x4380e4 | 0x46d20 | 0x46120 | 0xf1 |
Process32FirstW | 0x0 | 0x4380e8 | 0x46d24 | 0x46124 | 0x40d |
Process32NextW | 0x0 | 0x4380ec | 0x46d28 | 0x46128 | 0x40f |
GetModuleHandleW | 0x0 | 0x4380f0 | 0x46d2c | 0x4612c | 0x267 |
GetSystemDirectoryW | 0x0 | 0x4380f4 | 0x46d30 | 0x46130 | 0x2cd |
CreateProcessW | 0x0 | 0x4380f8 | 0x46d34 | 0x46134 | 0xdb |
GetShortPathNameW | 0x0 | 0x4380fc | 0x46d38 | 0x46138 | 0x2bb |
CreateFileA | 0x0 | 0x438100 | 0x46d3c | 0x4613c | 0xba |
Sleep | 0x0 | 0x438104 | 0x46d40 | 0x46140 | 0x550 |
GetCurrentProcessId | 0x0 | 0x438108 | 0x46d44 | 0x46144 | 0x20a |
VirtualQuery | 0x0 | 0x43810c | 0x46d48 | 0x46148 | 0x5a1 |
VirtualProtect | 0x0 | 0x438110 | 0x46d4c | 0x4614c | 0x59f |
IsBadReadPtr | 0x0 | 0x438114 | 0x46d50 | 0x46150 | 0x35e |
FreeLibrary | 0x0 | 0x438118 | 0x46d54 | 0x46154 | 0x19e |
lstrcmpA | 0x0 | 0x43811c | 0x46d58 | 0x46158 | 0x5fc |
UnmapViewOfFile | 0x0 | 0x438120 | 0x46d5c | 0x4615c | 0x583 |
lstrcmpiW | 0x0 | 0x438124 | 0x46d60 | 0x46160 | 0x600 |
lstrlenW | 0x0 | 0x438128 | 0x46d64 | 0x46164 | 0x609 |
lstrcpyW | 0x0 | 0x43812c | 0x46d68 | 0x46168 | 0x603 |
MoveFileExW | 0x0 | 0x438130 | 0x46d6c | 0x4616c | 0x3ca |
FindFirstFileW | 0x0 | 0x438134 | 0x46d70 | 0x46170 | 0x173 |
lstrcmpW | 0x0 | 0x438138 | 0x46d74 | 0x46174 | 0x5fd |
FindNextFileW | 0x0 | 0x43813c | 0x46d78 | 0x46178 | 0x17f |
FindClose | 0x0 | 0x438140 | 0x46d7c | 0x4617c | 0x168 |
CreateThread | 0x0 | 0x438144 | 0x46d80 | 0x46180 | 0xe8 |
WaitForMultipleObjects | 0x0 | 0x438148 | 0x46d84 | 0x46184 | 0x5a7 |
GetDriveTypeW | 0x0 | 0x43814c | 0x46d88 | 0x46188 | 0x21f |
GetTickCount64 | 0x0 | 0x438150 | 0x46d8c | 0x4618c | 0x2f3 |
SetThreadExecutionState | 0x0 | 0x438154 | 0x46d90 | 0x46190 | 0x52c |
IsProcessorFeaturePresent | 0x0 | 0x438158 | 0x46d94 | 0x46194 | 0x36d |
SetFilePointerEx | 0x0 | 0x43815c | 0x46d98 | 0x46198 | 0x4fc |
CreateFileMappingW | 0x0 | 0x438160 | 0x46d9c | 0x4619c | 0xbf |
MapViewOfFile | 0x0 | 0x438164 | 0x46da0 | 0x461a0 | 0x3c0 |
GetCurrentProcess | 0x0 | 0x438168 | 0x46da4 | 0x461a4 | 0x209 |
LocalFree | 0x0 | 0x43816c | 0x46da8 | 0x461a8 | 0x3b2 |
GetUserDefaultUILanguage | 0x0 | 0x438170 | 0x46dac | 0x461ac | 0x2ff |
InitializeCriticalSection | 0x0 | 0x438174 | 0x46db0 | 0x461b0 | 0x347 |
DeleteCriticalSection | 0x0 | 0x438178 | 0x46db4 | 0x461b4 | 0x105 |
SetLastError | 0x0 | 0x43817c | 0x46db8 | 0x461b8 | 0x50a |
EnterCriticalSection | 0x0 | 0x438180 | 0x46dbc | 0x461bc | 0x125 |
LeaveCriticalSection | 0x0 | 0x438184 | 0x46dc0 | 0x461c0 | 0x3a2 |
TerminateThread | 0x0 | 0x438188 | 0x46dc4 | 0x461c4 | 0x560 |
GlobalAlloc | 0x0 | 0x43818c | 0x46dc8 | 0x461c8 | 0x317 |
GlobalFree | 0x0 | 0x438190 | 0x46dcc | 0x461cc | 0x31e |
Beep | 0x0 | 0x438194 | 0x46dd0 | 0x461d0 | 0x5d |
GetWindowsDirectoryA | 0x0 | 0x438198 | 0x46dd4 | 0x461d4 | 0x30f |
MoveFileExA | 0x0 | 0x43819c | 0x46dd8 | 0x461d8 | 0x3c9 |
GetVersionExA | 0x0 | 0x4381a0 | 0x46ddc | 0x461dc | 0x304 |
ExpandEnvironmentStringsW | 0x0 | 0x4381a4 | 0x46de0 | 0x461e0 | 0x155 |
GetLastError | 0x0 | 0x4381a8 | 0x46de4 | 0x461e4 | 0x250 |
GetFileSizeEx | 0x0 | 0x4381ac | 0x46de8 | 0x461e8 | 0x23c |
ADVAPI32.dll (21)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EncryptionDisable | 0x0 | 0x438000 | 0x46c3c | 0x4603c | 0x10b |
AreAllAccessesGranted | 0x0 | 0x438004 | 0x46c40 | 0x46040 | 0x22 |
LookupAccountSidW | 0x0 | 0x438008 | 0x46c44 | 0x46044 | 0x1a7 |
LsaFreeMemory | 0x0 | 0x43800c | 0x46c48 | 0x46048 | 0x1c1 |
CryptDecrypt | 0x0 | 0x438010 | 0x46c4c | 0x4604c | 0xc4 |
CryptEncrypt | 0x0 | 0x438014 | 0x46c50 | 0x46050 | 0xca |
CryptImportKey | 0x0 | 0x438018 | 0x46c54 | 0x46054 | 0xda |
GetSidSubAuthority | 0x0 | 0x43801c | 0x46c58 | 0x46058 | 0x16b |
GetSidSubAuthorityCount | 0x0 | 0x438020 | 0x46c5c | 0x4605c | 0x16c |
CryptReleaseContext | 0x0 | 0x438024 | 0x46c60 | 0x46060 | 0xdb |
CryptDestroyKey | 0x0 | 0x438028 | 0x46c64 | 0x46064 | 0xc7 |
LsaCreateTrustedDomainEx | 0x0 | 0x43802c | 0x46c68 | 0x46068 | 0x1b7 |
CryptExportKey | 0x0 | 0x438030 | 0x46c6c | 0x4606c | 0xcf |
CryptGenKey | 0x0 | 0x438034 | 0x46c70 | 0x46070 | 0xd0 |
CryptAcquireContextW | 0x0 | 0x438038 | 0x46c74 | 0x46074 | 0xc1 |
CryptGenRandom | 0x0 | 0x43803c | 0x46c78 | 0x46078 | 0xd1 |
LsaClose | 0x0 | 0x438040 | 0x46c7c | 0x4607c | 0x1b3 |
LsaAddAccountRights | 0x0 | 0x438044 | 0x46c80 | 0x46080 | 0x1b0 |
EqualDomainSid | 0x0 | 0x438048 | 0x46c84 | 0x46084 | 0x116 |
InitializeSecurityDescriptor | 0x0 | 0x43804c | 0x46c88 | 0x46088 | 0x18d |
LsaQueryTrustedDomainInfo | 0x0 | 0x438050 | 0x46c8c | 0x4608c | 0x1e1 |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteExW | 0x0 | 0x4381d4 | 0x46e10 | 0x46210 | 0x136 |
SHGetFolderPathW | 0x0 | 0x4381d8 | 0x46e14 | 0x46214 | 0xd2 |
Secur32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LsaConnectUntrusted | 0x0 | 0x4381ec | 0x46e28 | 0x46228 | 0x26 |
NETAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DsRoleFreeMemory | 0x0 | 0x4381c8 | 0x46e04 | 0x46204 | 0x1d |
DsRoleGetPrimaryDomainInformation | 0x0 | 0x4381cc | 0x46e08 | 0x46208 | 0x1e |
SHLWAPI.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StrStrW | 0x0 | 0x4381e0 | 0x46e1c | 0x4621c | 0x152 |
StrToIntA | 0x0 | 0x4381e4 | 0x46e20 | 0x46220 | 0x155 |
MPR.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetCloseEnum | 0x0 | 0x4381b4 | 0x46df0 | 0x461f0 | 0x17 |
WNetAddConnection2W | 0x0 | 0x4381b8 | 0x46df4 | 0x461f4 | 0xd |
WNetEnumResourceW | 0x0 | 0x4381bc | 0x46df8 | 0x461f8 | 0x23 |
WNetOpenEnumW | 0x0 | 0x4381c0 | 0x46dfc | 0x461fc | 0x44 |
WS2_32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSAGetLastError | 0x6f | 0x438268 | 0x46ea4 | 0x462a4 | - |
shutdown | 0x16 | 0x43826c | 0x46ea8 | 0x462a8 | - |
closesocket | 0x3 | 0x438270 | 0x46eac | 0x462ac | - |
connect | 0x4 | 0x438274 | 0x46eb0 | 0x462b0 | - |
htons | 0x9 | 0x438278 | 0x46eb4 | 0x462b4 | - |
inet_pton | 0x0 | 0x43827c | 0x46eb8 | 0x462b8 | 0xa7 |
inet_addr | 0xb | 0x438280 | 0x46ebc | 0x462bc | - |
WSACleanup | 0x74 | 0x438284 | 0x46ec0 | 0x462c0 | - |
socket | 0x17 | 0x438288 | 0x46ec4 | 0x462c4 | - |
WSAStartup | 0x73 | 0x43828c | 0x46ec8 | 0x462c8 | - |
inet_ntoa | 0xc | 0x438290 | 0x46ecc | 0x462cc | - |
gethostbyname | 0x34 | 0x438294 | 0x46ed0 | 0x462d0 | - |
recv | 0x10 | 0x438298 | 0x46ed4 | 0x462d4 | - |
send | 0x13 | 0x43829c | 0x46ed8 | 0x462d8 | - |
WININET.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
HttpOpenRequestA | 0x0 | 0x438244 | 0x46e80 | 0x46280 | 0x75 |
InternetReadFile | 0x0 | 0x438248 | 0x46e84 | 0x46284 | 0xca |
InternetCloseHandle | 0x0 | 0x43824c | 0x46e88 | 0x46288 | 0x92 |
HttpQueryInfoA | 0x0 | 0x438250 | 0x46e8c | 0x4628c | 0x7a |
HttpSendRequestA | 0x0 | 0x438254 | 0x46e90 | 0x46290 | 0x7c |
InternetConnectA | 0x0 | 0x438258 | 0x46e94 | 0x46294 | 0x98 |
InternetCrackUrlA | 0x0 | 0x43825c | 0x46e98 | 0x46298 | 0x9a |
InternetOpenA | 0x0 | 0x438260 | 0x46e9c | 0x4629c | 0xc2 |
CRYPT32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptBinaryToStringA | 0x0 | 0x438058 | 0x46c94 | 0x46094 | 0x7d |
CryptStringToBinaryA | 0x0 | 0x43805c | 0x46c98 | 0x46098 | 0xe2 |
ole32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoCreateInstance | 0x0 | 0x4382a4 | 0x46ee0 | 0x462e0 | 0x1a |
CoInitializeEx | 0x0 | 0x4382a8 | 0x46ee4 | 0x462e4 | 0x50 |
CoUninitialize | 0x0 | 0x4382ac | 0x46ee8 | 0x462e8 | 0x7f |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
iphnlp.exe | 1 | 0x00400000 | 0x00458FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77BB0000 | 0x77D3DFFF | Content Changed | - | 32-bit | 0x77C16390, 0x77C23550, ... |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.1 |
Malicious
|
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Unknown |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Unknown |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd | Modified File | Unknown |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1040\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\microsoft\windows\inetcache\counters2.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Unknown |
Not Queried
|
...
|
»