VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
jsworm.exe
Windows Exe (x86-32)
Created at 2019-07-18T07:39:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-07-18 02:08 (UTC+2) |
Last Seen | 2019-07-18 02:16 (UTC+2) |
Names | Win32.Trojan.Filecoder |
Families | Filecoder |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4133b1 |
Size Of Code | 0x22800 |
Size Of Initialized Data | 0x2600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-06-25 06:43:51+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x226e8 | 0x21800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.5 |
.idata | 0x424000 | 0xa36 | 0xc00 | 0x21c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.86 |
.reloc | 0x425000 | 0x1848 | 0x1a00 | 0x22800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.44 |
Imports (4)
»
KERNEL32.dll (85)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetFilePointer | 0x0 | 0x424020 | 0x24208 | 0x21e08 | 0x522 |
CreateFileW | 0x0 | 0x424024 | 0x2420c | 0x21e0c | 0xcb |
Sleep | 0x0 | 0x424028 | 0x24210 | 0x21e10 | 0x57d |
CloseHandle | 0x0 | 0x42402c | 0x24214 | 0x21e14 | 0x86 |
ReadFile | 0x0 | 0x424030 | 0x24218 | 0x21e18 | 0x473 |
GetFileSizeEx | 0x0 | 0x424034 | 0x2421c | 0x21e1c | 0x24c |
GetFileAttributesW | 0x0 | 0x424038 | 0x24220 | 0x21e20 | 0x245 |
WriteFile | 0x0 | 0x42403c | 0x24224 | 0x21e24 | 0x612 |
FindFirstFileW | 0x0 | 0x424040 | 0x24228 | 0x21e28 | 0x180 |
FindNextFileW | 0x0 | 0x424044 | 0x2422c | 0x21e2c | 0x18c |
FindClose | 0x0 | 0x424048 | 0x24230 | 0x21e30 | 0x175 |
lstrcmpiW | 0x0 | 0x42404c | 0x24234 | 0x21e34 | 0x633 |
WriteConsoleW | 0x0 | 0x424050 | 0x24238 | 0x21e38 | 0x611 |
WideCharToMultiByte | 0x0 | 0x424054 | 0x2423c | 0x21e3c | 0x5fe |
GetLastError | 0x0 | 0x424058 | 0x24240 | 0x21e40 | 0x261 |
MultiByteToWideChar | 0x0 | 0x42405c | 0x24244 | 0x21e44 | 0x3ef |
ExitThread | 0x0 | 0x424060 | 0x24248 | 0x21e48 | 0x15f |
WaitForSingleObject | 0x0 | 0x424064 | 0x2424c | 0x21e4c | 0x5d7 |
DecodePointer | 0x0 | 0x424068 | 0x24250 | 0x21e50 | 0x109 |
CreateMutexA | 0x0 | 0x42406c | 0x24254 | 0x21e54 | 0xd7 |
MoveFileW | 0x0 | 0x424070 | 0x24258 | 0x21e58 | 0x3eb |
GetModuleFileNameW | 0x0 | 0x424074 | 0x2425c | 0x21e5c | 0x274 |
GetCurrentThreadId | 0x0 | 0x424078 | 0x24260 | 0x21e60 | 0x21c |
WaitForSingleObjectEx | 0x0 | 0x42407c | 0x24264 | 0x21e64 | 0x5d8 |
SwitchToThread | 0x0 | 0x424080 | 0x24268 | 0x21e68 | 0x587 |
GetExitCodeThread | 0x0 | 0x424084 | 0x2426c | 0x21e6c | 0x23d |
EnterCriticalSection | 0x0 | 0x424088 | 0x24270 | 0x21e70 | 0x131 |
LeaveCriticalSection | 0x0 | 0x42408c | 0x24274 | 0x21e74 | 0x3bd |
DeleteCriticalSection | 0x0 | 0x424090 | 0x24278 | 0x21e78 | 0x110 |
QueryPerformanceCounter | 0x0 | 0x424094 | 0x2427c | 0x21e7c | 0x44d |
SetLastError | 0x0 | 0x424098 | 0x24280 | 0x21e80 | 0x532 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x42409c | 0x24284 | 0x21e84 | 0x35f |
TlsAlloc | 0x0 | 0x4240a0 | 0x24288 | 0x21e88 | 0x59e |
TlsGetValue | 0x0 | 0x4240a4 | 0x2428c | 0x21e8c | 0x5a0 |
TlsSetValue | 0x0 | 0x4240a8 | 0x24290 | 0x21e90 | 0x5a1 |
TlsFree | 0x0 | 0x4240ac | 0x24294 | 0x21e94 | 0x59f |
GetSystemTimeAsFileTime | 0x0 | 0x4240b0 | 0x24298 | 0x21e98 | 0x2e9 |
GetModuleHandleW | 0x0 | 0x4240b4 | 0x2429c | 0x21e9c | 0x278 |
GetProcAddress | 0x0 | 0x4240b8 | 0x242a0 | 0x21ea0 | 0x2ae |
UnhandledExceptionFilter | 0x0 | 0x4240bc | 0x242a4 | 0x21ea4 | 0x5ad |
SetUnhandledExceptionFilter | 0x0 | 0x4240c0 | 0x242a8 | 0x21ea8 | 0x56d |
GetCurrentProcess | 0x0 | 0x4240c4 | 0x242ac | 0x21eac | 0x217 |
TerminateProcess | 0x0 | 0x4240c8 | 0x242b0 | 0x21eb0 | 0x58c |
IsProcessorFeaturePresent | 0x0 | 0x4240cc | 0x242b4 | 0x21eb4 | 0x386 |
IsDebuggerPresent | 0x0 | 0x4240d0 | 0x242b8 | 0x21eb8 | 0x37f |
GetStartupInfoW | 0x0 | 0x4240d4 | 0x242bc | 0x21ebc | 0x2d0 |
GetCurrentProcessId | 0x0 | 0x4240d8 | 0x242c0 | 0x21ec0 | 0x218 |
InitializeSListHead | 0x0 | 0x4240dc | 0x242c4 | 0x21ec4 | 0x363 |
SetEvent | 0x0 | 0x4240e0 | 0x242c8 | 0x21ec8 | 0x516 |
CreateThread | 0x0 | 0x4240e4 | 0x242cc | 0x21ecc | 0xf3 |
EncodePointer | 0x0 | 0x4240e8 | 0x242d0 | 0x21ed0 | 0x12d |
GetCurrentThread | 0x0 | 0x4240ec | 0x242d4 | 0x21ed4 | 0x21b |
GetThreadTimes | 0x0 | 0x4240f0 | 0x242d8 | 0x21ed8 | 0x305 |
FreeLibrary | 0x0 | 0x4240f4 | 0x242dc | 0x21edc | 0x1ab |
FreeLibraryAndExitThread | 0x0 | 0x4240f8 | 0x242e0 | 0x21ee0 | 0x1ac |
LoadLibraryExW | 0x0 | 0x4240fc | 0x242e4 | 0x21ee4 | 0x3c3 |
RtlUnwind | 0x0 | 0x424100 | 0x242e8 | 0x21ee8 | 0x4d3 |
RaiseException | 0x0 | 0x424104 | 0x242ec | 0x21eec | 0x462 |
GetModuleHandleExW | 0x0 | 0x424108 | 0x242f0 | 0x21ef0 | 0x277 |
ExitProcess | 0x0 | 0x42410c | 0x242f4 | 0x21ef4 | 0x15e |
GetStdHandle | 0x0 | 0x424110 | 0x242f8 | 0x21ef8 | 0x2d2 |
GetCommandLineA | 0x0 | 0x424114 | 0x242fc | 0x21efc | 0x1d6 |
GetCommandLineW | 0x0 | 0x424118 | 0x24300 | 0x21f00 | 0x1d7 |
CompareStringW | 0x0 | 0x42411c | 0x24304 | 0x21f04 | 0x9b |
LCMapStringW | 0x0 | 0x424120 | 0x24308 | 0x21f08 | 0x3b1 |
HeapAlloc | 0x0 | 0x424124 | 0x2430c | 0x21f0c | 0x345 |
HeapFree | 0x0 | 0x424128 | 0x24310 | 0x21f10 | 0x349 |
GetFileType | 0x0 | 0x42412c | 0x24314 | 0x21f14 | 0x24e |
SetFilePointerEx | 0x0 | 0x424130 | 0x24318 | 0x21f18 | 0x523 |
FindFirstFileExW | 0x0 | 0x424134 | 0x2431c | 0x21f1c | 0x17b |
IsValidCodePage | 0x0 | 0x424138 | 0x24320 | 0x21f20 | 0x38b |
GetACP | 0x0 | 0x42413c | 0x24324 | 0x21f24 | 0x1b2 |
GetOEMCP | 0x0 | 0x424140 | 0x24328 | 0x21f28 | 0x297 |
GetCPInfo | 0x0 | 0x424144 | 0x2432c | 0x21f2c | 0x1c1 |
GetEnvironmentStringsW | 0x0 | 0x424148 | 0x24330 | 0x21f30 | 0x237 |
FreeEnvironmentStringsW | 0x0 | 0x42414c | 0x24334 | 0x21f34 | 0x1aa |
SetEnvironmentVariableW | 0x0 | 0x424150 | 0x24338 | 0x21f38 | 0x514 |
GetProcessHeap | 0x0 | 0x424154 | 0x2433c | 0x21f3c | 0x2b4 |
SetStdHandle | 0x0 | 0x424158 | 0x24340 | 0x21f40 | 0x54a |
GetStringTypeW | 0x0 | 0x42415c | 0x24344 | 0x21f44 | 0x2d7 |
FlushFileBuffers | 0x0 | 0x424160 | 0x24348 | 0x21f48 | 0x19f |
GetConsoleCP | 0x0 | 0x424164 | 0x2434c | 0x21f4c | 0x1ea |
GetConsoleMode | 0x0 | 0x424168 | 0x24350 | 0x21f50 | 0x1fc |
HeapSize | 0x0 | 0x42416c | 0x24354 | 0x21f54 | 0x34e |
HeapReAlloc | 0x0 | 0x424170 | 0x24358 | 0x21f58 | 0x34c |
ADVAPI32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptImportKey | 0x0 | 0x424000 | 0x241e8 | 0x21de8 | 0xdb |
CryptEncrypt | 0x0 | 0x424004 | 0x241ec | 0x21dec | 0xcb |
CryptAcquireContextA | 0x0 | 0x424008 | 0x241f0 | 0x21df0 | 0xc1 |
CryptReleaseContext | 0x0 | 0x42400c | 0x241f4 | 0x21df4 | 0xdc |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x424178 | 0x24360 | 0x21f60 | 0x1b2 |
CRYPT32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptStringToBinaryA | 0x0 | 0x424014 | 0x241fc | 0x21dfc | 0xe3 |
CryptBinaryToStringA | 0x0 | 0x424018 | 0x24200 | 0x21e00 | 0x7e |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
jsworm.exe | 1 | 0x01320000 | 0x01346FFF | Content Changed | - | 32-bit | 0x013333B1 |
![]() |
![]() |
...
|
jsworm.exe | 1 | 0x01320000 | 0x01346FFF | Content Changed | - | 32-bit | 0x01340817, 0x01332F8F |
![]() |
![]() |
...
|
jsworm.exe | 1 | 0x01320000 | 0x01346FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.1 |
Malicious
|
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Unknown |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Unknown |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»