VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Sodinokibi
Gen:Variant.Ser.Razy.2100
|
zsywqjjw.exe
Windows Exe (x86-32)
Created at 2020-02-15T00:39:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x44400a |
Size Of Code | 0x1a000 |
Size Of Initialized Data | 0x24600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-02-14 17:50:40+00:00 |
Version Information (11)
»
Assembly Version | 27.7.10.24 |
Comments | t7JFg15 |
CompanyName | Sc06JoCp91 |
FileDescription | Mo9i2A6 |
FileVersion | 27.7.10.24 |
InternalName | zsywqjjw.exe |
LegalCopyright | k5QAt14Xic |
LegalTrademarks | Ai43GdWk20 |
OriginalFilename | zsywqjjw.exe |
ProductName | f0N2JsGz4 |
ProductVersion | 27.7.10.24 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
Y-=~kg | 0x402000 | 0x1aaa0 | 0x1ac00 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 8.0 |
.text | 0x41e000 | 0x19da0 | 0x19e00 | 0x1b000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.08 |
.rsrc | 0x438000 | 0x9768 | 0x9800 | 0x34e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.76 |
.reloc | 0x442000 | 0xc | 0x200 | 0x3e600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
- | 0x444000 | 0x10 | 0x200 | 0x3e800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0.69 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x444000 | 0x22458 | 0x1f458 | 0x0 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
zsywqjjw.exe | 1 | 0x008A0000 | 0x008E5FFF | First Execution |
![]() |
32-bit | 0x008C12B0 |
![]() |
![]() |
...
|
zsywqjjw.exe | 1 | 0x008A0000 | 0x008E5FFF | Content Changed |
![]() |
32-bit | 0x008C12B0 |
![]() |
![]() |
...
|
zsywqjjw.exe | 1 | 0x008A0000 | 0x008E5FFF | Content Changed |
![]() |
32-bit | 0x008BEB98 |
![]() |
![]() |
...
|
zsywqjjw.exe | 1 | 0x008A0000 | 0x008E5FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Ser.Razy.2100 |
Malicious
|
c:\programdata\microsoft\windows nt\msfax\virtualinbox\en-us\welcomefax.tif.z49-css-qhb | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
SodinokibiEncryptedFile | File encrypted by Sodinokibi Ransomware | Ransomware |
5/5
|
...
|
c:\programdata\microsoft\clicktorun\0d0d4eeb-dc03-4b3f-88df-959fe1ede5f4\x-none.16\stream.x64.x-none.man.dat.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\201eb7df-c721-4b8b-9c81-a09de7f931e6\x-none.16\stream.x64.x-none.man.dat.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\deploymentconfig.2.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\deploymentconfiguration.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\usermanifest.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\productreleases\5a65c4d7-3cdf-4be4-8560-f036d300c13f\en-us.16\stream.platform.culture.man.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\productreleases\5a65c4d7-3cdf-4be4-8560-f036d300c13f\x-none.16\masterdescriptor.x-none.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.accessmui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.excel.excel.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.excelmui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.lync.lync.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.office32ww.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osmuxmui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.outlookmui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proofing.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.wordmui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\integrator.exe.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\microsoft_office_officetelemetryagentfallback2016.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\crypto\systemkeys\7092289d2be9a3ebf1065d0f1c678ab6_e8d761b7-8a68-4187-8c95-75a3788ac267.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\crypto\systemkeys\d20d9e7d1dcddc105a0d5e00d5e1ad30_33d770d0-06bc-47c5-8714-222cdac43a71.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pictures.ico.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\settings.ico.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\sync.ico.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_property.ico.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\network\downloader\edbtmp.log.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\provisioning\{1e05dd5d-a022-46c5-963c-b20de341170f}\prov\runtime.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\provisioning\{23cb517f-5073-4e96-a202-7fe6122a2271}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\provisioning\{268c43e1-aa2b-4036-86ef-8cda98a0c2fe}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\provisioning\{7a30a9be-737f-47a1-a541-6e7b0761ed19}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\provisioning\{7a30a9be-737f-47a1-a541-6e7b0761ed19}\prov\runtime.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\provisioning\{8fb7d64e-70fc-4f9d-89ee-d486817534df}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\provisioning\{99b095d8-5959-4820-bea7-7448c8427b4e}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\provisioning\{b0b9123d-7d7f-4c6b-9973-ceced46f2a09}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\provisioning\{c5dc3753-b6c8-4057-b396-bf13d769311c}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\provisioning\{c5dc3753-b6c8-4057-b396-bf13d769311c}\prov\runtime.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\provisioning\{ee4aac98-c174-4941-82b1-d121e493e4fb}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\provisioning\{f11899f2-71ec-4621-9997-e17ae2f6eb26}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\provisioning\{99b095d8-5959-4820-bea7-7448c8427b4e}\masterdatastore.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftlync2010.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftlync2013win32.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftnotepad.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoffice2013office365win32.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoffice2013office365win64.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoffice2016win32.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoutlook2016cawin64.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftskypeforbusiness2016win32.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftskypeforbusiness2016win64.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\roamingcredentialsettings.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\themesettings2013.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\user account pictures\default user.dat.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\user account pictures\user-32.png.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\user account pictures\user.png.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\caches\cversions.2.db.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\caches\{599d1469-eb61-443b-9556-ee3aa24908da}.2.ver0x0000000000000001.db.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\caches\{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x0000000000000016.db.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\caches\{ddf571f2-be98-426d-8288-1a9a39c3fda2}.2.ver0x0000000000000001.db.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\02305155-8ac1-1189-ff55-b7119a53887c.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\0890ad2f-b74f-c384-f684-9c33f8f67924.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\1659a225-428e-84f0-ba52-5fb2b85d55b3.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\1e225998-faa0-5fd4-4db7-5e7686ee3b47.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\280b97f1-1f94-1458-c842-d18e2d1e05f9.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\28502d06-9d29-8514-1e5d-64447116d798.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\3bef1b80-1939-62a0-48e8-4b25b157e940.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\3c8c7eb3-7a1d-7981-0472-571cdd1d1292.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\3e260c8e-54e8-d0b9-02ab-2d0faa9743f8.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\46a9b648-161a-6393-bdaf-a6ccb77a570d.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\4ad5b311-485b-15cc-97e9-9adb84427d7b.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\5dd8bcf1-73af-cff8-d142-0ca7feade752.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\7309084a-bb6f-20c3-ea54-aa108ceab1ae.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\7646fa0f-b52c-71a8-3aed-950dd1668c09.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\8292682a-6850-c06c-9b6d-9646f16d4ed0.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\8e383e90-b2f9-7bf2-1d5b-4e47dcb2014e.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\92c2558b-5247-7fec-0ec0-79f2583ab410.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\9d3ad23c-c6b8-7fb5-e4ab-f5d0a66dcfbc.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\a1bac04c-582b-d37d-069c-13f17a799e18.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\aa4e72b1-ad78-3f2c-e8ff-4733b8cdd4ac.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\bbfbe8ad-1a35-a7f3-33bc-40912bf89dfb.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\c94a6c18-d496-da1c-8a02-fc6976e0145e.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\cb692946-a9f3-639d-1064-a6d75a01b9c3.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\d1ecfce2-f845-c1e9-052b-d2f457c135e6.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\d508ba05-d8aa-2836-484d-3833d22fe185.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\dc5bc54e-ee99-04c5-63a5-669bf0666354.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\f428c4e6-787a-08fa-4d5a-e12a3034aa02.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\fc93b452-8a84-dede-3b7a-0fc9413c4592.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\sleepstudy\sleepstudy-report-latest.xml.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\desktop.ini.z49-css-qhb | Dropped File | Binary |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessibility\speech recognition.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessories\desktop.ini.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessories\math input panel.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessories\snipping tool.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessories\steps recorder.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessories\windows fax and scan.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessories\xps viewer.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\acrobat reader dc.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\computer management.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\desktop.ini.z49-css-qhb | Dropped File | Binary |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\disk cleanup.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\memory diagnostics tool.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\performance monitor.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\resource monitor.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\system configuration.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\system information.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\desktop.ini.z49-css-qhb | Dropped File | Binary |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\excel 2016.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\immersive control panel.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\java\check for updates.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\java\configure java.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\java\get help.url.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\maintenance\desktop.ini.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\office 2016 upload center.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\project server 2016 accounts.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\spreadsheet compare 2016.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\onedrive for business.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\powerpoint 2016.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\project 2016.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\startup\desktop.ini.z49-css-qhb | Dropped File | Binary |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\system tools\desktop.ini.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\word 2016.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu places\05 - music.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu places\06 - pictures.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu places\08 - homegroup.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows\start menu places\10 - userprofile.lnk.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows defender\definition updates\default\gapaengine.dll.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\04\109005.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\09\287.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\12\194.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\15\262.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\17\193.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\19\272.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\22\109006.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-01172019-164549-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-01312020-085233-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-02062018-155840-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-03082019-175806-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-07172018-134351-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-07172018-135525-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-09062017-205414-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-09062017-210137-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-09072017-103625-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-10122018-081308-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-10122018-090648-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-10172017-124308-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-11142018-170447-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-11152017-120955-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\oracle\java\javapath_target_474984\javaw.exe.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\package cache\{37b8f9c7-03fb-3253-8781-2517c99d7c00}v11.0.61030\packages\vcruntimeadditional_amd64\cab1.cab.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\package cache\{37b8f9c7-03fb-3253-8781-2517c99d7c00}v11.0.61030\packages\vcruntimeadditional_amd64\vc_runtimeadditional_x64.msi.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\package cache\{582ea838-9199-3518-a05c-db09462f68ec}v14.10.25017\packages\vcruntimeminimum_x86\vc_runtimeminimum_x86.msi.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\package cache\{68306422-7c57-373f-8860-d26ce4ba2a15}v14.10.25017\packages\vcruntimeadditional_x86\cab1.cab.z49-css-qhb | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\0d0d4eeb-dc03-4b3f-88df-959fe1ede5f4\en-us.16\stream.x64.en-us.man.dat.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\19b11135-37bd-4fa1-a78e-c20ca2bda1c0\en-us.16\stream.x64.en-us.man.dat.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\19b11135-37bd-4fa1-a78e-c20ca2bda1c0\x-none.16\stream.x64.x-none.man.dat.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\201eb7df-c721-4b8b-9c81-a09de7f931e6\en-us.16\masterdescriptor.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\201eb7df-c721-4b8b-9c81-a09de7f931e6\en-us.16\stream.x64.en-us.man.dat.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\0d0d4eeb-dc03-4b3f-88df-959fe1ede5f4\x-none.16\masterdescriptor.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\deploymentconfig.0.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\deploymentconfig.1.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\manifest.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\productreleases\5a65c4d7-3cdf-4be4-8560-f036d300c13f\en-us.16\masterdescriptor.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\productreleases\5a65c4d7-3cdf-4be4-8560-f036d300c13f\x-none.16\stream.platform.x-none.man.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\productreleases\5a65c4d7-3cdf-4be4-8560-f036d300c13f\x-none.16\stream.x86.x-none.man.dat.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\productreleases\5a65c4d7-3cdf-4be4-8560-f036d300c13f\en-us.16\stream.x86.en-us.man.dat.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\productreleases\a6a87302-92ae-41f2-ac52-73f5ee18259f\x-none.16\stream.x86.x-none.man.dat.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.access.access.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.accessmuiset.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.dcf.dcf.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.dcfmui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.groove.groove.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.groovemui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.lyncmui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.office32mui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.officemui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.officemuiset.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.onenote.onenote.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.onenotemui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osm.osm.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osmmui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osmux.osmux.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.outlook.outlook.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.powerpivot.powerpivot.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.powerpoint.powerpoint.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.powerpointmui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.project.project.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.projectmui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proof.culture.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proof.culture.msi.16.es-es.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proof.culture.msi.16.fr-fr.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.publisher.publisher.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.publishermui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.shared.office.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.visio.visio.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.visiomui.msi.16.en-us.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.word.word.x-none.msi.16.x-none.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\microsoft_office_officetelemetryagentlogon2016.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\crypto\rsa\machinekeys\f686aace6942fb7f7ceb231212eef4a4_e8d761b7-8a68-4187-8c95-75a3788ac267.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\crypto\rsa\s-1-5-18\4eccd106f69e31c1b12304e5463bb71d_33d770d0-06bc-47c5-8714-222cdac43a71.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\netfol.ico.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-us\resource.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\ringtones.ico.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\wmp.ico.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-us\resource.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\folder.ico.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_pref.ico.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_property.ico.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_queue.ico.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_.ico.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_settings.ico.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\identitycrl\int\ppcrlconfig600.dll.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\identitycrl\production\ppcrlconfig600.dll.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\network\downloader\edb.chk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\countrytable.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{18dcffd4-37d6-4bc6-87e0-4266fdbb8e49}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{18dcffd4-37d6-4bc6-87e0-4266fdbb8e49}\prov\runtime.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{1e05dd5d-a022-46c5-963c-b20de341170f}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{268c43e1-aa2b-4036-86ef-8cda98a0c2fe}\prov\runtime.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{33d78dbc-3db7-4398-8533-000d7c02e5d1}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\prov\runtime.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{8d196d7f-3eef-48ad-8bea-be749f12d3ad}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{8fb7d64e-70fc-4f9d-89ee-d486817534df}\prov\runtime.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{9aec5bda-1e87-46b3-bb96-1a01c606555e}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{9df6a4ed-fc16-48bf-8b24-6e2ad2bfcfea}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\prov\runtime.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{b0b9123d-7d7f-4c6b-9973-ceced46f2a09}\prov\runtime.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{f11899f2-71ec-4621-9997-e17ae2f6eb26}\prov\runtime.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\customizations.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\prov\runtime.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\storage health\storageeventsarchive.dat.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\storage health\storagehealthmodel.dat.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\desktopsettings2013.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\easeofaccesssettings2013.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftinternetexplorer2013.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftinternetexplorer2013backup.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftlync2013win64.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoffice2010win32.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoffice2010win64.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoffice2013backupwin32.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoffice2013backupwin64.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoffice2013win32.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoffice2013win64.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoffice2016backupwin32.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoffice2016backupwin64.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoffice2016win64.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoutlook2013cawin32.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoutlook2013cawin64.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftoutlook2016cawin32.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\microsoftwordpad.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\networkprinters.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\uev\inboxtemplates\vdistate.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\user account pictures\user-192.png.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\user account pictures\user-40.png.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\user account pictures\user-48.png.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\user account pictures\user.bmp.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\appxprovisioning.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\caches\cversions.0.db.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\caches\{07ce7f5b-73f4-4bad-b449-5b3e959def86}.2.ver0x0000000000000001.db.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\caches\{2a2e4b23-55e7-4066-bf56-40a8c2acf003}.2.ver0x0000000000000001.db.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\caches\{427a2095-ced1-467f-8647-d13f664e7313}.2.ver0x0000000000000003.db.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\caches\{5b6db04b-b054-4120-9ee4-33a79ff53bc3}.2.ver0x0000000000000001.db.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\caches\{696521d6-0c3c-47a9-8a08-62a21834d2f0}.2.ver0x0000000000000001.db.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\caches\{7bf8dbd1-8ee0-446a-8d07-1d22e4418d9a}.2.ver0x0000000000000002.db.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\caches\{9961e15c-3f61-4fa0-9f93-f635907c374b}.2.ver0x0000000000000001.db.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\caches\{b8c80385-ead5-4543-9080-86ada8e81dd5}.2.ver0x0000000000000001.db.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\caches\{e14796d4-f769-4aa4-85dc-e9ffe52aeeb4}.2.ver0x0000000000000001.db.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\03f8974b-362e-33e3-2e0b-c7bc2ea01c63.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\08961e67-fd90-a888-a0c1-ffdc19a3386f.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\0a8c1492-65ca-6a01-de25-0e183559d10d.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\0cb4ef12-226b-0a51-6930-2dbfb63f3e7d.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\13ba8772-845b-29a1-ae9e-fb2793ccf4ea.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\1dae14df-4c42-28af-691e-10cc07a990b4.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\215f9712-9fca-a3f8-5b11-660eefc73b96.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\2657f7c0-8294-58c3-f394-15fe18ba174a.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\26943e1f-42ed-f190-2895-3bc2b8c4176d.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\28748306-9f02-a5d7-6ded-4459fddadc31.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\2a3adcd0-4ddc-f3d2-6bcb-f11f9cbc1e2c.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\2cb4947b-9a24-70fc-387f-98cfa7cd7461.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\38ae356e-4b11-78bd-6f1e-d1fbd81b826a.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\3d4098b6-679e-0d7e-f478-ee96ebcb42ff.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\3ebdb897-991b-934f-ee13-2ca21ed81938.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\41a63518-8ec4-f58c-c5ed-313ea0fb2820.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\4c4ecbc0-0ec0-3929-aebb-a931a339fb23.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\517cfcaf-138b-1796-2cea-62892204250a.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\5390be10-79b5-dc50-bb32-91842c76e607.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\54a30ac2-1ccf-60a8-6672-380af6008f3d.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\59e31519-5400-7696-2a00-b5fca5ba8904.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\5b0a39aa-16e0-a938-f694-656664c7be15.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\5f3c8956-0358-1f87-eb47-697e265d6aa9.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\600364a7-e11c-efda-2c12-eac40e75f19a.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\61b5bd89-4cb0-db77-6622-cb63b5a58080.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\630a70e7-1832-4f42-e2a2-5d35fdddc45f.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\67447b0c-05cf-6740-5f7b-391ab440c42d.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\71c8f37a-a7b9-aff0-6de0-9b276c089ad6.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\71ef3df1-f4b1-69cd-793a-48e165e282aa.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\865e8f30-20a1-9528-bb48-42999b5b2aa8.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\8ce3d3dd-a4c7-6c38-5fde-1f9f5df98807.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\8d56e57b-8663-136d-ff69-a004e217825a.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\91edce6b-d93b-f186-c4e2-d38502cc520e.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\a1e5b165-0532-a6a3-f542-0c5c162be3e1.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\a7e08b8b-ad4b-af00-ebcc-1aa29a833ce9.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\ac116a72-b6b1-d558-23f6-10796e634d41.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\b34b197c-c0ed-bf12-c9bb-44e883c66a9d.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\b81d7e70-84e7-b16a-e3d0-1e7aa2f1232d.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\babc0ea4-dabb-04f7-1017-a11af9b29344.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\bbc7a1c3-44c6-27b6-1e16-487a47263f3e.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\bcda97bb-bfd0-2a72-3c90-c8518f3d09ee.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\be7366a7-9d6c-ef6d-2f6b-fe59a23f007c.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\c3d42a1a-2f3f-a4a9-6a04-cc1b234485fb.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\ca947da2-7e9a-7249-8095-bceb379c6f74.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\d445d1cd-ecdf-2830-df9e-3f187e431898.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\e2a686b1-b02a-b3e7-90cb-3fa0d708ce04.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\e335baf1-18ab-73fe-e089-3fa0a6e71a35.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\e603fcd0-9cde-3f41-875c-5cc396d927ce.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\e64ffef1-e246-b632-595b-56076a3fa776.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\e8ac9388-7c9c-19cc-fd4d-cb72bb1544ea.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\e8fff2df-6041-8f21-3df7-db31661aa09b.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\ecbc2601-0a67-4963-e594-43c65d6ec9a5.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\archive\apps\eee47229-947d-2ac7-e8a3-49bafee251d1.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\clipsvc\tokens.dat.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\devicemetadatacache\dmrc.idx.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\power efficiency diagnostics\energy-report-2017-09-26.xml.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\power efficiency diagnostics\energy-report.html.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\access 2016.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessibility\desktop.ini.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessories\paint.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessories\quick assist.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessories\remote desktop connection.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessories\system tools\character map.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessories\system tools\desktop.ini.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessories\windows media player.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\accessories\wordpad.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\component services.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\dfrgui.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\event viewer.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\iscsi initiator.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\odbc data sources (32-bit).lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\odbc data sources (64-bit).lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\print management.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\security configuration management.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\services.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\task scheduler.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\administrative tools\windows firewall with advanced security.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\google chrome.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\java\about java.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\java\visit java.com.url.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\database compare 2016.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\office 2016 language preferences.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\skype for business recording manager.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\telemetry dashboard for office 2016.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\telemetry log for office 2016.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\miracastview.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\mozilla firefox.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\onenote 2016.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\outlook 2016.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\printdialog.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\publisher 2016.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\skype for business 2016.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\system tools\task manager.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\system tools\windows defender.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\visio 2016.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\windows 10 update assistant.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu\programs\windows media player.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu places\01 - file explorer.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu places\03 - documents.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu places\04 - downloads.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu places\07 - videos.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu places\09 - network.lnk.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows\start menu places\desktop.ini.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\definition updates\default\mpengine.dll.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\network inspection system\support\nislog.txt.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\00\192.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\01\271.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\02\109004.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\04\259.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\05\191.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\10\267.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\10\286.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\15\196.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\17\109001.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\18\109002.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\18\195.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\19\266.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\19\328.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\21\260.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\22\109003.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\metastore\2\94\a75bfde52f3dd8e6.dat.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows defender\scans\mpcache-cc7537bd57f4e352d7cdea5852d447a507e0f749.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows live\wlive48x48.png.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows nt\msscan\welcomescan.jpg.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-01132018-082401-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-01132018-085021-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-01312020-081049-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-01312020-081753-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-01312020-091325-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-01312020-092302-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-01312020-100228-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-02062018-161100-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-02062018-162700-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-02212018-110518-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-03082019-181722-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-09072017-114522-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-09072017-132231-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-09072017-172200-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-09262017-144646-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-09262017-175731-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-11142018-153535-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-11142018-164648-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\windows security health\logs\shs-11152017-121807-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\office\clicktorunpackagelocker.z49-css-qhb | Dropped File | Unknown |
Not Queried
|
...
|
»
c:\programdata\oracle\java\installcache_x64\baseimagefam8.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\oracle\java\javapath_target_474984\java.exe.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\oracle\java\javapath_target_474984\javaws.exe.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\package cache\{13a4ee12-23ea-3371-91ee-efb36ddfff3e}v12.0.21005\packages\vcruntimeminimum_x86\cab1.cab.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\package cache\{13a4ee12-23ea-3371-91ee-efb36ddfff3e}v12.0.21005\packages\vcruntimeminimum_x86\vc_runtimeminimum_x86.msi.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\package cache\{3c3aafc8-d898-43ec-998f-965ffdae065a}\vcredist_x64.exe.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\package cache\{582ea838-9199-3518-a05c-db09462f68ec}v14.10.25017\packages\vcruntimeminimum_x86\cab1.cab.z49-css-qhb | Dropped File | Stream |
Not Queried
|
...
|
»