VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
DeepScan:Generic.Ransom.Cuba.4D0E95B0
DeepScan:Generic.Ransom.Cuba.23871C35
|
qEjdLfskd47NI5BG.exe
Windows Exe (x86-32)
Created at 2020-11-13T14:02:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\qEjdLfskd47NI5BG.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40a2a1 |
Size Of Code | 0x16000 |
Size Of Initialized Data | 0x12a00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-11-12 21:20:50+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x15e55 | 0x16000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.64 |
.rdata | 0x417000 | 0xf704 | 0xf800 | 0x16400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.58 |
.data | 0x427000 | 0x1790 | 0xc00 | 0x25c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.84 |
.rsrc | 0x429000 | 0x1e0 | 0x200 | 0x26800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.reloc | 0x42a000 | 0x1714 | 0x1800 | 0x26a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.43 |
Imports (6)
»
NETAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareEnum | 0x0 | 0x4171bc | 0x25e90 | 0x25290 | 0xde |
NetApiBufferFree | 0x0 | 0x4171c0 | 0x25e94 | 0x25294 | 0x51 |
IPHLPAPI.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetIpNetTable | 0x0 | 0x417030 | 0x25d04 | 0x25104 | 0x69 |
MPR.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetCloseEnum | 0x0 | 0x4171ac | 0x25e80 | 0x25280 | 0x19 |
WNetEnumResourceW | 0x0 | 0x4171b0 | 0x25e84 | 0x25284 | 0x25 |
WNetOpenEnumW | 0x0 | 0x4171b4 | 0x25e88 | 0x25288 | 0x46 |
KERNEL32.dll (92)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindFirstFileW | 0x0 | 0x417038 | 0x25d0c | 0x2510c | 0x182 |
FindNextFileW | 0x0 | 0x41703c | 0x25d10 | 0x25110 | 0x18e |
GetCurrentProcess | 0x0 | 0x417040 | 0x25d14 | 0x25114 | 0x219 |
lstrlenW | 0x0 | 0x417044 | 0x25d18 | 0x25118 | 0x63e |
WriteFile | 0x0 | 0x417048 | 0x25d1c | 0x2511c | 0x614 |
FindClose | 0x0 | 0x41704c | 0x25d20 | 0x25120 | 0x177 |
CreateFileW | 0x0 | 0x417050 | 0x25d24 | 0x25124 | 0xcd |
SetFileAttributesW | 0x0 | 0x417054 | 0x25d28 | 0x25128 | 0x51e |
Sleep | 0x0 | 0x417058 | 0x25d2c | 0x2512c | 0x57f |
GlobalAlloc | 0x0 | 0x41705c | 0x25d30 | 0x25130 | 0x32f |
GlobalFree | 0x0 | 0x417060 | 0x25d34 | 0x25134 | 0x336 |
CloseHandle | 0x0 | 0x417064 | 0x25d38 | 0x25138 | 0x88 |
CreateThread | 0x0 | 0x417068 | 0x25d3c | 0x2513c | 0xf5 |
ReadFile | 0x0 | 0x41706c | 0x25d40 | 0x25140 | 0x474 |
GetFileSizeEx | 0x0 | 0x417070 | 0x25d44 | 0x25144 | 0x24e |
FindFirstVolumeW | 0x0 | 0x417074 | 0x25d48 | 0x25148 | 0x188 |
EnterCriticalSection | 0x0 | 0x417078 | 0x25d4c | 0x2514c | 0x133 |
TerminateProcess | 0x0 | 0x41707c | 0x25d50 | 0x25150 | 0x58e |
GetModuleFileNameW | 0x0 | 0x417080 | 0x25d54 | 0x25154 | 0x276 |
LeaveCriticalSection | 0x0 | 0x417084 | 0x25d58 | 0x25158 | 0x3c0 |
InitializeCriticalSection | 0x0 | 0x417088 | 0x25d5c | 0x2515c | 0x360 |
WaitForSingleObject | 0x0 | 0x41708c | 0x25d60 | 0x25160 | 0x5d9 |
GetEnvironmentStringsW | 0x0 | 0x417090 | 0x25d64 | 0x25164 | 0x239 |
GetLogicalDriveStringsW | 0x0 | 0x417094 | 0x25d68 | 0x25168 | 0x269 |
GetLastError | 0x0 | 0x417098 | 0x25d6c | 0x2516c | 0x263 |
SetEvent | 0x0 | 0x41709c | 0x25d70 | 0x25170 | 0x517 |
GetDiskFreeSpaceExW | 0x0 | 0x4170a0 | 0x25d74 | 0x25174 | 0x22a |
K32EnumProcesses | 0x0 | 0x4170a4 | 0x25d78 | 0x25178 | 0x39c |
SetFilePointerEx | 0x0 | 0x4170a8 | 0x25d7c | 0x2517c | 0x524 |
MoveFileExW | 0x0 | 0x4170ac | 0x25d80 | 0x25180 | 0x3eb |
ExitProcess | 0x0 | 0x4170b0 | 0x25d84 | 0x25184 | 0x160 |
GetVolumePathNamesForVolumeNameW | 0x0 | 0x4170b4 | 0x25d88 | 0x25188 | 0x326 |
CreateEventA | 0x0 | 0x4170b8 | 0x25d8c | 0x2518c | 0xbe |
FindNextVolumeW | 0x0 | 0x4170bc | 0x25d90 | 0x25190 | 0x193 |
lstrcmpiW | 0x0 | 0x4170c0 | 0x25d94 | 0x25194 | 0x635 |
GetTickCount | 0x0 | 0x4170c4 | 0x25d98 | 0x25198 | 0x309 |
GetDriveTypeW | 0x0 | 0x4170c8 | 0x25d9c | 0x2519c | 0x231 |
DeleteCriticalSection | 0x0 | 0x4170cc | 0x25da0 | 0x251a0 | 0x112 |
QueryPerformanceCounter | 0x0 | 0x4170d0 | 0x25da4 | 0x251a4 | 0x44e |
WideCharToMultiByte | 0x0 | 0x4170d4 | 0x25da8 | 0x251a8 | 0x600 |
MultiByteToWideChar | 0x0 | 0x4170d8 | 0x25dac | 0x251ac | 0x3f2 |
GetCommandLineW | 0x0 | 0x4170dc | 0x25db0 | 0x251b0 | 0x1d9 |
GetCommandLineA | 0x0 | 0x4170e0 | 0x25db4 | 0x251b4 | 0x1d8 |
GetProcessHeap | 0x0 | 0x4170e4 | 0x25db8 | 0x251b8 | 0x2b6 |
OpenProcess | 0x0 | 0x4170e8 | 0x25dbc | 0x251bc | 0x40e |
FreeEnvironmentStringsW | 0x0 | 0x4170ec | 0x25dc0 | 0x251c0 | 0x1ac |
DecodePointer | 0x0 | 0x4170f0 | 0x25dc4 | 0x251c4 | 0x10b |
SetStdHandle | 0x0 | 0x4170f4 | 0x25dc8 | 0x251c8 | 0x54c |
GetStringTypeW | 0x0 | 0x4170f8 | 0x25dcc | 0x251cc | 0x2d9 |
FlushFileBuffers | 0x0 | 0x4170fc | 0x25dd0 | 0x251d0 | 0x1a1 |
HeapSize | 0x0 | 0x417100 | 0x25dd4 | 0x251d4 | 0x350 |
WriteConsoleW | 0x0 | 0x417104 | 0x25dd8 | 0x251d8 | 0x613 |
K32GetProcessImageFileNameW | 0x0 | 0x417108 | 0x25ddc | 0x251dc | 0x3aa |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41710c | 0x25de0 | 0x251e0 | 0x361 |
ResetEvent | 0x0 | 0x417110 | 0x25de4 | 0x251e4 | 0x4c7 |
WaitForSingleObjectEx | 0x0 | 0x417114 | 0x25de8 | 0x251e8 | 0x5da |
CreateEventW | 0x0 | 0x417118 | 0x25dec | 0x251ec | 0xc1 |
GetModuleHandleW | 0x0 | 0x41711c | 0x25df0 | 0x251f0 | 0x27a |
GetProcAddress | 0x0 | 0x417120 | 0x25df4 | 0x251f4 | 0x2b0 |
UnhandledExceptionFilter | 0x0 | 0x417124 | 0x25df8 | 0x251f8 | 0x5af |
SetUnhandledExceptionFilter | 0x0 | 0x417128 | 0x25dfc | 0x251fc | 0x56f |
IsProcessorFeaturePresent | 0x0 | 0x41712c | 0x25e00 | 0x25200 | 0x388 |
IsDebuggerPresent | 0x0 | 0x417130 | 0x25e04 | 0x25204 | 0x381 |
GetStartupInfoW | 0x0 | 0x417134 | 0x25e08 | 0x25208 | 0x2d2 |
GetCurrentProcessId | 0x0 | 0x417138 | 0x25e0c | 0x2520c | 0x21a |
GetCurrentThreadId | 0x0 | 0x41713c | 0x25e10 | 0x25210 | 0x21e |
GetSystemTimeAsFileTime | 0x0 | 0x417140 | 0x25e14 | 0x25214 | 0x2eb |
InitializeSListHead | 0x0 | 0x417144 | 0x25e18 | 0x25218 | 0x365 |
RtlUnwind | 0x0 | 0x417148 | 0x25e1c | 0x2521c | 0x4d4 |
RaiseException | 0x0 | 0x41714c | 0x25e20 | 0x25220 | 0x463 |
SetLastError | 0x0 | 0x417150 | 0x25e24 | 0x25224 | 0x533 |
EncodePointer | 0x0 | 0x417154 | 0x25e28 | 0x25228 | 0x12f |
TlsAlloc | 0x0 | 0x417158 | 0x25e2c | 0x2522c | 0x5a0 |
TlsGetValue | 0x0 | 0x41715c | 0x25e30 | 0x25230 | 0x5a2 |
TlsSetValue | 0x0 | 0x417160 | 0x25e34 | 0x25234 | 0x5a3 |
TlsFree | 0x0 | 0x417164 | 0x25e38 | 0x25238 | 0x5a1 |
FreeLibrary | 0x0 | 0x417168 | 0x25e3c | 0x2523c | 0x1ad |
LoadLibraryExW | 0x0 | 0x41716c | 0x25e40 | 0x25240 | 0x3c6 |
GetModuleHandleExW | 0x0 | 0x417170 | 0x25e44 | 0x25244 | 0x279 |
GetStdHandle | 0x0 | 0x417174 | 0x25e48 | 0x25248 | 0x2d4 |
HeapFree | 0x0 | 0x417178 | 0x25e4c | 0x2524c | 0x34b |
HeapAlloc | 0x0 | 0x41717c | 0x25e50 | 0x25250 | 0x347 |
GetFileType | 0x0 | 0x417180 | 0x25e54 | 0x25254 | 0x250 |
LCMapStringW | 0x0 | 0x417184 | 0x25e58 | 0x25258 | 0x3b4 |
HeapReAlloc | 0x0 | 0x417188 | 0x25e5c | 0x2525c | 0x34e |
GetConsoleMode | 0x0 | 0x41718c | 0x25e60 | 0x25260 | 0x1fe |
GetConsoleOutputCP | 0x0 | 0x417190 | 0x25e64 | 0x25264 | 0x202 |
FindFirstFileExW | 0x0 | 0x417194 | 0x25e68 | 0x25268 | 0x17d |
IsValidCodePage | 0x0 | 0x417198 | 0x25e6c | 0x2526c | 0x38e |
GetACP | 0x0 | 0x41719c | 0x25e70 | 0x25270 | 0x1b4 |
GetOEMCP | 0x0 | 0x4171a0 | 0x25e74 | 0x25274 | 0x299 |
GetCPInfo | 0x0 | 0x4171a4 | 0x25e78 | 0x25278 | 0x1c3 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetKeyboardLayoutList | 0x0 | 0x4171c8 | 0x25e9c | 0x2529c | 0x168 |
wsprintfW | 0x0 | 0x4171cc | 0x25ea0 | 0x252a0 | 0x3e1 |
ADVAPI32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LookupPrivilegeValueA | 0x0 | 0x417000 | 0x25cd4 | 0x250d4 | 0x1ae |
CryptAcquireContextW | 0x0 | 0x417004 | 0x25cd8 | 0x250d8 | 0xc2 |
CryptGenRandom | 0x0 | 0x417008 | 0x25cdc | 0x250dc | 0xd2 |
CryptReleaseContext | 0x0 | 0x41700c | 0x25ce0 | 0x250e0 | 0xdc |
AdjustTokenPrivileges | 0x0 | 0x417010 | 0x25ce4 | 0x250e4 | 0x1f |
CloseServiceHandle | 0x0 | 0x417014 | 0x25ce8 | 0x250e8 | 0x65 |
OpenSCManagerW | 0x0 | 0x417018 | 0x25cec | 0x250ec | 0x217 |
ControlService | 0x0 | 0x41701c | 0x25cf0 | 0x250f0 | 0x6a |
ChangeServiceConfigW | 0x0 | 0x417020 | 0x25cf4 | 0x250f4 | 0x5d |
OpenServiceW | 0x0 | 0x417024 | 0x25cf8 | 0x250f8 | 0x219 |
QueryServiceStatusEx | 0x0 | 0x417028 | 0x25cfc | 0x250fc | 0x251 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
qejdlfskd47ni5bg.exe | 1 | 0x00A30000 | 0x00A5BFFF | Relevant Image |
![]() |
32-bit | 0x00A39C60 |
![]() |
![]() |
...
|
qejdlfskd47ni5bg.exe | 1 | 0x00A30000 | 0x00A5BFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
DeepScan:Generic.Ransom.Cuba.4D0E95B0 |
Malicious
|
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.CNT.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\EQUATION\eqnedt32.exe.manifest.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.HLP | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\EQUATION\MTEXTRA.TTF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.FLT | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\GRPHFLT\EPSIMP32.FLT.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\GRPHFLT\GIFIMP32.FLT.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\GRPHFLT\JPEGIM32.FLT.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.WPG.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\GRPHFLT\PICTIM32.FLT.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\MSOINTL.DLL.IDX_DLL | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\MSOINTL.REST.IDX_DLL | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\README.HTM | Modified File | Text |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\MUAUTH.CAB | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUI.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\ExcelMUI.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\GrooveMUI.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\InfoPathMUI.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\BRANDING.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OCT.CHM.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUI.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUISet.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSCONFIG.CHM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10O.CHM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.CHM.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\Office32MUI.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\SETUP.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\OutlookMUI.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\PrjProrWW.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\ProjectMUI.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.en\Proof.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.es\Proof.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.fr\Proof.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\Proofing.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\ProPlusrWW.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\PublisherMUI.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\VisioMUI.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\VisiorWW.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\SETUP.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\WordMUI.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppobjs-spp-plugin-manifest-signed.xrm-ms | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPWMI.MOF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_EN.LEX | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_ES.LEX.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_FR.LEX | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\MCABOUT.HTM.cuba | Dropped File | Text |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\DATES.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\PHONE.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.DAT | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.XML.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\BASMLA.XSL | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\Smart Tag\MSTAG.TLB | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\TextConv\Wks9Pxy.cnv.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\TextConv\WPFT532.CNV.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\TextConv\WPFT632.CNV.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\AFTRNOON.INF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\PREVIEW.GIF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\ARCTIC.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\AXIS.ELM.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\AXIS.INF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\PREVIEW.GIF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\BLENDS.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\THMBNAIL.PNG.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\BLUECALM.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\BLUECALM.INF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\BLUEPRNT.ELM.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\BOLDSTRI.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\BOLDSTRI.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\THMBNAIL.PNG.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\BREEZE.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\BREEZE.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\THMBNAIL.PNG.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\CANYON.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\THMBNAIL.PNG.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\CAPSULES.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\PREVIEW.GIF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\CASCADE.INF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\THMBNAIL.PNG.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\COMPASS.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\PREVIEW.GIF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\CONCRETE.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\DEEPBLUE.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\ECHO.INF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\PREVIEW.GIF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\ECLIPSE.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\EDGE.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\EDGE.INF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\THMBNAIL.PNG.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\EVRGREEN.ELM.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\EXPEDITN.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\EXPEDITN.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\ICE.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\ICE.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\PREVIEW.GIF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\THMBNAIL.PNG.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\INDUST.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\INDUST.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\PREVIEW.GIF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\THMBNAIL.PNG.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\IRIS.ELM.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\IRIS.INF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\PREVIEW.GIF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\LAYERS.ELM.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\LAYERS.INF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\LEVEL.ELM.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\NETWORK.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\THMBNAIL.PNG.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\PAPYRUS.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\THMBNAIL.PNG.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\PIXEL\PIXEL.INF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\PIXEL\PREVIEW.GIF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\PIXEL\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\PREVIEW.GIF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\PROFILE.ELM.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\QUAD\PREVIEW.GIF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\QUAD\QUAD.ELM.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\QUAD\QUAD.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\RADIAL\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\RADIAL\THMBNAIL.PNG.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\REFINED.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\REFINED.INF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\THMBNAIL.PNG.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\RICEPAPR\PREVIEW.GIF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\RICEPAPR\RICEPAPR.INF.cuba | Dropped File | Stream |
Unknown
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.CFG.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.FNT | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.CGM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\GRPHFLT\PNG32.FLT | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\SETUP.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.WW\Office32WW.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\OneNoteMUI.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\SETUP.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\pkeyconfig-office.xrm-ms | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\PowerPointMUI.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\SETUP.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\SETUP.XML.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\SETUP.XML.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\SETUP.XML.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\TIME.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\AFTRNOON.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\BLUEPRNT.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\THMBNAIL.PNG.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\CAPSULES.ELM.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\COMPASS.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\CONCRETE.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\DEEPBLUE.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\THMBNAIL.PNG.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\ECHO.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\PREVIEW.GIF.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\PREVIEW.GIF.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\EVRGREEN.INF.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\JOURNAL.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\JOURNAL.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\THMBNAIL.PNG.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\LEVEL.INF.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\PAPYRUS.INF.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\PREVIEW.GIF.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\PROFILE.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\QUAD\THMBNAIL.PNG.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\RADIAL\RADIAL.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\PREVIEW.GIF.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\Volume{92eb13a2-4a1d-11e7-bae1-806e6f6e6963}\Program Files\Common Files\Microsoft Shared\ink\uk-UA\!!FAQ for Decryption!!.txt | Dropped File | Text |
Not Queried
|
...
|
»