VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Wiper, Ransomware, Trojan |
Windows Exe (x86-32)
Created at 2019-05-15T00:23:00
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
File Reputation Information
Severity |
First Seen | 2019-05-14 03:16 (UTC+2) |
Last Seen | 2019-05-14 21:34 (UTC+2) |
Names | Win32.Trojan.Filecoder |
Families | Filecoder |
Classification | Trojan |
PE Information
Image Base | 0x400000 |
Entry Point | 0x4085d8 |
Size Of Code | 0x1e400 |
Size Of Initialized Data | 0x52000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-05-13 00:01:40+00:00 |
Version Information (9)
Comments | Abnormally Install Additionally Avr Lieu |
CompanyName | pdfforge GmbH |
FileDescription | Abnormally Install Additionally Avr Lieu |
FileVersion | |
Languages | English |
LegalCopyright | (C) pdfforge GmbH |
OriginalFilename | Pg |
ProductName | Pg |
ProductVersion | |
Sections (5)
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
.text | 0x401000 | 0x1e38b | 0x1e400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.7 |
.rdata | 0x420000 | 0xd4c8 | 0xd600 | 0x1e800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.08 |
.data | 0x42e000 | 0x2380 | 0xc00 | 0x2be00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.84 |
.rsrc | 0x431000 | 0x41ed4 | 0x42000 | 0x2ca00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.58 |
.reloc | 0x473000 | 0x1ca8 | 0x1e00 | 0x6ea00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.56 |
Imports (16)
KERNEL32.dll (93)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
GetFileSizeEx | 0x0 | 0x42009c | 0x2c4bc | 0x2acbc | 0x24c |
GetConsoleMode | 0x0 | 0x4200a0 | 0x2c4c0 | 0x2acc0 | 0x1fc |
GetConsoleCP | 0x0 | 0x4200a4 | 0x2c4c4 | 0x2acc4 | 0x1ea |
FlushFileBuffers | 0x0 | 0x4200a8 | 0x2c4c8 | 0x2acc8 | 0x19f |
GetStringTypeW | 0x0 | 0x4200ac | 0x2c4cc | 0x2accc | 0x2d7 |
SetStdHandle | 0x0 | 0x4200b0 | 0x2c4d0 | 0x2acd0 | 0x54a |
GetProcessHeap | 0x0 | 0x4200b4 | 0x2c4d4 | 0x2acd4 | 0x2b4 |
FreeEnvironmentStringsW | 0x0 | 0x4200b8 | 0x2c4d8 | 0x2acd8 | 0x1aa |
GetEnvironmentStringsW | 0x0 | 0x4200bc | 0x2c4dc | 0x2acdc | 0x237 |
MultiByteToWideChar | 0x0 | 0x4200c0 | 0x2c4e0 | 0x2ace0 | 0x3ef |
GetCommandLineW | 0x0 | 0x4200c4 | 0x2c4e4 | 0x2ace4 | 0x1d7 |
GetCommandLineA | 0x0 | 0x4200c8 | 0x2c4e8 | 0x2ace8 | 0x1d6 |
GetCPInfo | 0x0 | 0x4200cc | 0x2c4ec | 0x2acec | 0x1c1 |
GetOEMCP | 0x0 | 0x4200d0 | 0x2c4f0 | 0x2acf0 | 0x297 |
GetACP | 0x0 | 0x4200d4 | 0x2c4f4 | 0x2acf4 | 0x1b2 |
IsValidCodePage | 0x0 | 0x4200d8 | 0x2c4f8 | 0x2acf8 | 0x38b |
FindNextFileW | 0x0 | 0x4200dc | 0x2c4fc | 0x2acfc | 0x18c |
FindFirstFileExW | 0x0 | 0x4200e0 | 0x2c500 | 0x2ad00 | 0x17b |
FindClose | 0x0 | 0x4200e4 | 0x2c504 | 0x2ad04 | 0x175 |
DecodePointer | 0x0 | 0x4200e8 | 0x2c508 | 0x2ad08 | 0x109 |
LCMapStringW | 0x0 | 0x4200ec | 0x2c50c | 0x2ad0c | 0x3b1 |
SetFilePointerEx | 0x0 | 0x4200f0 | 0x2c510 | 0x2ad10 | 0x523 |
HeapAlloc | 0x0 | 0x4200f4 | 0x2c514 | 0x2ad14 | 0x345 |
HeapFree | 0x0 | 0x4200f8 | 0x2c518 | 0x2ad18 | 0x349 |
OutputDebugStringW | 0x0 | 0x4200fc | 0x2c51c | 0x2ad1c | 0x419 |
ExitProcess | 0x0 | 0x420100 | 0x2c520 | 0x2ad20 | 0x15e |
FreeLibraryAndExitThread | 0x0 | 0x420104 | 0x2c524 | 0x2ad24 | 0x1ac |
SystemTimeToFileTime | 0x0 | 0x420108 | 0x2c528 | 0x2ad28 | 0x588 |
ExitThread | 0x0 | 0x42010c | 0x2c52c | 0x2ad2c | 0x15f |
WriteConsoleW | 0x0 | 0x420110 | 0x2c530 | 0x2ad30 | 0x611 |
GetModuleHandleExW | 0x0 | 0x420114 | 0x2c534 | 0x2ad34 | 0x277 |
GetModuleFileNameW | 0x0 | 0x420118 | 0x2c538 | 0x2ad38 | 0x274 |
GetFileType | 0x0 | 0x42011c | 0x2c53c | 0x2ad3c | 0x24e |
GetStdHandle | 0x0 | 0x420120 | 0x2c540 | 0x2ad40 | 0x2d2 |
LoadLibraryExW | 0x0 | 0x420124 | 0x2c544 | 0x2ad44 | 0x3c3 |
FreeLibrary | 0x0 | 0x420128 | 0x2c548 | 0x2ad48 | 0x1ab |
TlsFree | 0x0 | 0x42012c | 0x2c54c | 0x2ad4c | 0x59f |
TlsSetValue | 0x0 | 0x420130 | 0x2c550 | 0x2ad50 | 0x5a1 |
TlsGetValue | 0x0 | 0x420134 | 0x2c554 | 0x2ad54 | 0x5a0 |
TlsAlloc | 0x0 | 0x420138 | 0x2c558 | 0x2ad58 | 0x59e |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x42013c | 0x2c55c | 0x2ad5c | 0x35f |
DeleteCriticalSection | 0x0 | 0x420140 | 0x2c560 | 0x2ad60 | 0x110 |
LeaveCriticalSection | 0x0 | 0x420144 | 0x2c564 | 0x2ad64 | 0x3bd |
EnterCriticalSection | 0x0 | 0x420148 | 0x2c568 | 0x2ad68 | 0x131 |
EncodePointer | 0x0 | 0x42014c | 0x2c56c | 0x2ad6c | 0x12d |
HeapSize | 0x0 | 0x420150 | 0x2c570 | 0x2ad70 | 0x34e |
HeapReAlloc | 0x0 | 0x420154 | 0x2c574 | 0x2ad74 | 0x34c |
GetUserDefaultLangID | 0x0 | 0x420158 | 0x2c578 | 0x2ad78 | 0x313 |
WideCharToMultiByte | 0x0 | 0x42015c | 0x2c57c | 0x2ad7c | 0x5fe |
VerifyVersionInfoW | 0x0 | 0x420160 | 0x2c580 | 0x2ad80 | 0x5c5 |
GetVersionExA | 0x0 | 0x420164 | 0x2c584 | 0x2ad84 | 0x31a |
GetTempPathW | 0x0 | 0x420168 | 0x2c588 | 0x2ad88 | 0x2f6 |
FindResourceExW | 0x0 | 0x42016c | 0x2c58c | 0x2ad8c | 0x195 |
GetModuleHandleW | 0x0 | 0x420170 | 0x2c590 | 0x2ad90 | 0x278 |
CancelWaitableTimer | 0x0 | 0x420174 | 0x2c594 | 0x2ad94 | 0x76 |
SetWaitableTimer | 0x0 | 0x420178 | 0x2c598 | 0x2ad98 | 0x576 |
CreateWaitableTimerA | 0x0 | 0x42017c | 0x2c59c | 0x2ad9c | 0xfd |
CreateEventA | 0x0 | 0x420180 | 0x2c5a0 | 0x2ada0 | 0xbc |
WaitForMultipleObjectsEx | 0x0 | 0x420184 | 0x2c5a4 | 0x2ada4 | 0x5d6 |
SleepEx | 0x0 | 0x420188 | 0x2c5a8 | 0x2ada8 | 0x580 |
lstrlenA | 0x0 | 0x42018c | 0x2c5ac | 0x2adac | 0x63b |
GetTickCount | 0x0 | 0x420190 | 0x2c5b0 | 0x2adb0 | 0x307 |
GetSystemInfo | 0x0 | 0x420194 | 0x2c5b4 | 0x2adb4 | 0x2e3 |
GetLocalTime | 0x0 | 0x420198 | 0x2c5b8 | 0x2adb8 | 0x262 |
GetSystemTimeAsFileTime | 0x0 | 0x42019c | 0x2c5bc | 0x2adbc | 0x2e9 |
Beep | 0x0 | 0x4201a0 | 0x2c5c0 | 0x2adc0 | 0x65 |
CloseHandle | 0x0 | 0x4201a4 | 0x2c5c4 | 0x2adc4 | 0x86 |
WriteFile | 0x0 | 0x4201a8 | 0x2c5c8 | 0x2adc8 | 0x612 |
LoadResource | 0x0 | 0x4201ac | 0x2c5cc | 0x2adcc | 0x3c7 |
WaitForMultipleObjects | 0x0 | 0x4201b0 | 0x2c5d0 | 0x2add0 | 0x5d5 |
WaitForSingleObject | 0x0 | 0x4201b4 | 0x2c5d4 | 0x2add4 | 0x5d7 |
SetLastError | 0x0 | 0x4201b8 | 0x2c5d8 | 0x2add8 | 0x532 |
CreateFileW | 0x0 | 0x4201bc | 0x2c5dc | 0x2addc | 0xcb |
RtlUnwind | 0x0 | 0x4201c0 | 0x2c5e0 | 0x2ade0 | 0x4d3 |
RaiseException | 0x0 | 0x4201c4 | 0x2c5e4 | 0x2ade4 | 0x462 |
TerminateProcess | 0x0 | 0x4201c8 | 0x2c5e8 | 0x2ade8 | 0x58c |
InitializeSListHead | 0x0 | 0x4201cc | 0x2c5ec | 0x2adec | 0x363 |
GetCurrentThreadId | 0x0 | 0x4201d0 | 0x2c5f0 | 0x2adf0 | 0x21c |
GetCurrentProcessId | 0x0 | 0x4201d4 | 0x2c5f4 | 0x2adf4 | 0x218 |
QueryPerformanceCounter | 0x0 | 0x4201d8 | 0x2c5f8 | 0x2adf8 | 0x44d |
GetStartupInfoW | 0x0 | 0x4201dc | 0x2c5fc | 0x2adfc | 0x2d0 |
SetUnhandledExceptionFilter | 0x0 | 0x4201e0 | 0x2c600 | 0x2ae00 | 0x56d |
UnhandledExceptionFilter | 0x0 | 0x4201e4 | 0x2c604 | 0x2ae04 | 0x5ad |
IsDebuggerPresent | 0x0 | 0x4201e8 | 0x2c608 | 0x2ae08 | 0x37f |
IsProcessorFeaturePresent | 0x0 | 0x4201ec | 0x2c60c | 0x2ae0c | 0x386 |
SetEvent | 0x0 | 0x4201f0 | 0x2c610 | 0x2ae10 | 0x516 |
GetLastError | 0x0 | 0x4201f4 | 0x2c614 | 0x2ae14 | 0x261 |
CreateThread | 0x0 | 0x4201f8 | 0x2c618 | 0x2ae18 | 0xf3 |
GetCurrentProcess | 0x0 | 0x4201fc | 0x2c61c | 0x2ae1c | 0x217 |
LocalFileTimeToFileTime | 0x0 | 0x420200 | 0x2c620 | 0x2ae20 | 0x3cc |
VirtualAlloc | 0x0 | 0x420204 | 0x2c624 | 0x2ae24 | 0x5c6 |
GetProcAddress | 0x0 | 0x420208 | 0x2c628 | 0x2ae28 | 0x2ae |
VerSetConditionMask | 0x0 | 0x42020c | 0x2c62c | 0x2ae2c | 0x5c1 |
USER32.dll (44)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
SendMessageA | 0x0 | 0x420230 | 0x2c650 | 0x2ae50 | 0x314 |
PostQuitMessage | 0x0 | 0x420234 | 0x2c654 | 0x2ae54 | 0x2b4 |
DispatchMessageA | 0x0 | 0x420238 | 0x2c658 | 0x2ae58 | 0xbb |
TranslateMessage | 0x0 | 0x42023c | 0x2c65c | 0x2ae5c | 0x3a7 |
GetMessageA | 0x0 | 0x420240 | 0x2c660 | 0x2ae60 | 0x180 |
ShowWindow | 0x0 | 0x420244 | 0x2c664 | 0x2ae64 | 0x387 |
CreateDialogParamW | 0x0 | 0x420248 | 0x2c668 | 0x2ae68 | 0x69 |
GetSubMenu | 0x0 | 0x42024c | 0x2c66c | 0x2ae6c | 0x1ba |
DrawTextW | 0x0 | 0x420250 | 0x2c670 | 0x2ae70 | 0xdd |
GetDC | 0x0 | 0x420254 | 0x2c674 | 0x2ae74 | 0x13f |
ReleaseDC | 0x0 | 0x420258 | 0x2c678 | 0x2ae78 | 0x2fe |
InvalidateRect | 0x0 | 0x42025c | 0x2c67c | 0x2ae7c | 0x217 |
GetMenuState | 0x0 | 0x420260 | 0x2c680 | 0x2ae80 | 0x17d |
GetMenu | 0x0 | 0x420264 | 0x2c684 | 0x2ae84 | 0x172 |
EndDialog | 0x0 | 0x420268 | 0x2c688 | 0x2ae88 | 0xf1 |
GetDlgItem | 0x0 | 0x42026c | 0x2c68c | 0x2ae8c | 0x149 |
LoadMenuA | 0x0 | 0x420270 | 0x2c690 | 0x2ae90 | 0x256 |
DialogBoxParamA | 0x0 | 0x420274 | 0x2c694 | 0x2ae94 | 0xb8 |
CheckMenuItem | 0x0 | 0x420278 | 0x2c698 | 0x2ae98 | 0x42 |
GetClientRect | 0x0 | 0x42027c | 0x2c69c | 0x2ae9c | 0x130 |
LoadStringA | 0x0 | 0x420280 | 0x2c6a0 | 0x2aea0 | 0x25b |
CreateIconFromResourceEx | 0x0 | 0x420284 | 0x2c6a4 | 0x2aea4 | 0x6c |
LookupIconIdFromDirectoryEx | 0x0 | 0x420288 | 0x2c6a8 | 0x2aea8 | 0x264 |
LookupIconIdFromDirectory | 0x0 | 0x42028c | 0x2c6ac | 0x2aeac | 0x263 |
GetWindowLongA | 0x0 | 0x420290 | 0x2c6b0 | 0x2aeb0 | 0x1de |
IntersectRect | 0x0 | 0x420294 | 0x2c6b4 | 0x2aeb4 | 0x216 |
InflateRect | 0x0 | 0x420298 | 0x2c6b8 | 0x2aeb8 | 0x200 |
FillRect | 0x0 | 0x42029c | 0x2c6bc | 0x2aebc | 0x10f |
GetSysColorBrush | 0x0 | 0x4202a0 | 0x2c6c0 | 0x2aec0 | 0x1bc |
GetCursorPos | 0x0 | 0x4202a4 | 0x2c6c4 | 0x2aec4 | 0x13e |
MessageBeep | 0x0 | 0x4202a8 | 0x2c6c8 | 0x2aec8 | 0x288 |
MessageBoxA | 0x0 | 0x4202ac | 0x2c6cc | 0x2aecc | 0x289 |
GetWindowRect | 0x0 | 0x4202b0 | 0x2c6d0 | 0x2aed0 | 0x1e6 |
GetScrollRange | 0x0 | 0x4202b4 | 0x2c6d4 | 0x2aed4 | 0x1b6 |
SetScrollRange | 0x0 | 0x4202b8 | 0x2c6d8 | 0x2aed8 | 0x35b |
GetDialogBaseUnits | 0x0 | 0x4202bc | 0x2c6dc | 0x2aedc | 0x143 |
SendDlgItemMessageA | 0x0 | 0x4202c0 | 0x2c6e0 | 0x2aee0 | 0x30f |
SetDlgItemTextA | 0x0 | 0x4202c4 | 0x2c6e4 | 0x2aee4 | 0x332 |
DefWindowProcA | 0x0 | 0x4202c8 | 0x2c6e8 | 0x2aee8 | 0xa5 |
WaitForInputIdle | 0x0 | 0x4202cc | 0x2c6ec | 0x2aeec | 0x3d6 |
wsprintfA | 0x0 | 0x4202d0 | 0x2c6f0 | 0x2aef0 | 0x3e3 |
EndPaint | 0x0 | 0x4202d4 | 0x2c6f4 | 0x2aef4 | 0xf3 |
BeginPaint | 0x0 | 0x4202d8 | 0x2c6f8 | 0x2aef8 | 0x10 |
DestroyWindow | 0x0 | 0x4202dc | 0x2c6fc | 0x2aefc | 0xb4 |
GDI32.dll (23)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
GetObjectA | 0x0 | 0x42003c | 0x2c45c | 0x2ac5c | 0x2a5 |
SetDIBColorTable | 0x0 | 0x420040 | 0x2c460 | 0x2ac60 | 0x36b |
CreateDIBSection | 0x0 | 0x420044 | 0x2c464 | 0x2ac64 | 0x37 |
GetTextExtentPoint32A | 0x0 | 0x420048 | 0x2c468 | 0x2ac68 | 0x2c8 |
GetPaletteEntries | 0x0 | 0x42004c | 0x2c46c | 0x2ac6c | 0x2aa |
GetCurrentObject | 0x0 | 0x420050 | 0x2c470 | 0x2ac70 | 0x26d |
DeleteDC | 0x0 | 0x420054 | 0x2c474 | 0x2ac74 | 0x17a |
CreateRectRgn | 0x0 | 0x420058 | 0x2c478 | 0x2ac78 | 0x53 |
CreateFontA | 0x0 | 0x42005c | 0x2c47c | 0x2ac7c | 0x3f |
CreateCompatibleDC | 0x0 | 0x420060 | 0x2c480 | 0x2ac80 | 0x31 |
CombineRgn | 0x0 | 0x420064 | 0x2c484 | 0x2ac84 | 0x22 |
BitBlt | 0x0 | 0x420068 | 0x2c488 | 0x2ac88 | 0x13 |
TextOutW | 0x0 | 0x42006c | 0x2c48c | 0x2ac8c | 0x39d |
MoveToEx | 0x0 | 0x420070 | 0x2c490 | 0x2ac90 | 0x2f4 |
SetTextAlign | 0x0 | 0x420074 | 0x2c494 | 0x2ac94 | 0x388 |
SetBkMode | 0x0 | 0x420078 | 0x2c498 | 0x2ac98 | 0x363 |
SelectObject | 0x0 | 0x42007c | 0x2c49c | 0x2ac9c | 0x35b |
Rectangle | 0x0 | 0x420080 | 0x2c4a0 | 0x2aca0 | 0x319 |
Pie | 0x0 | 0x420084 | 0x2c4a4 | 0x2aca4 | 0x302 |
LineTo | 0x0 | 0x420088 | 0x2c4a8 | 0x2aca8 | 0x2e2 |
GetPixel | 0x0 | 0x42008c | 0x2c4ac | 0x2acac | 0x2ae |
DeleteObject | 0x0 | 0x420090 | 0x2c4b0 | 0x2acb0 | 0x17d |
CreateSolidBrush | 0x0 | 0x420094 | 0x2c4b4 | 0x2acb4 | 0x59 |
COMDLG32.dll (1)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
ChooseColorA | 0x0 | 0x42002c | 0x2c44c | 0x2ac4c | 0x0 |
ADVAPI32.dll (5)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
CryptAcquireContextA | 0x0 | 0x42000c | 0x2c42c | 0x2ac2c | 0xc1 |
DeregisterEventSource | 0x0 | 0x420010 | 0x2c430 | 0x2ac30 | 0xed |
CryptGenKey | 0x0 | 0x420014 | 0x2c434 | 0x2ac34 | 0xd1 |
CryptReleaseContext | 0x0 | 0x420018 | 0x2c438 | 0x2ac38 | 0xdc |
CryptGenRandom | 0x0 | 0x42001c | 0x2c43c | 0x2ac3c | 0xd2 |
SHELL32.dll (1)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
SHCreateShellItem | 0x0 | 0x420228 | 0x2c648 | 0x2ae48 | 0xa9 |
ole32.dll (3)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
RevokeDragDrop | 0x0 | 0x420308 | 0x2c728 | 0x2af28 | 0x1a0 |
CoLockObjectExternal | 0x0 | 0x42030c | 0x2c72c | 0x2af2c | 0x66 |
CoCreateInstance | 0x0 | 0x420310 | 0x2c730 | 0x2af30 | 0x28 |
OLEAUT32.dll (1)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
OleTranslateColor | 0x1a5 | 0x420220 | 0x2c640 | 0x2ae40 | - |
WININET.dll (3)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
RetrieveUrlCacheEntryStreamA | 0x0 | 0x4202e4 | 0x2c704 | 0x2af04 | 0xff |
RetrieveUrlCacheEntryFileA | 0x0 | 0x4202e8 | 0x2c708 | 0x2af08 | 0xfd |
ResumeSuspendedDownload | 0x0 | 0x4202ec | 0x2c70c | 0x2af0c | 0xfc |
WS2_32.dll (2)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
WSALookupServiceEnd | 0x0 | 0x4202fc | 0x2c71c | 0x2af1c | 0x3f |
WSALookupServiceNextW | 0x0 | 0x420300 | 0x2c720 | 0x2af20 | 0x41 |
NETAPI32.dll (2)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
NetApiBufferFree | 0x0 | 0x420214 | 0x2c634 | 0x2ae34 | 0x51 |
NetWkstaGetInfo | 0x0 | 0x420218 | 0x2c638 | 0x2ae38 | 0xf7 |
WINMM.dll (1)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
SendDriverMessage | 0x0 | 0x4202f4 | 0x2c714 | 0x2af14 | 0xa |
CRYPT32.dll (1)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
CertEnumSystemStore | 0x0 | 0x420034 | 0x2c454 | 0x2ac54 | 0x2f |
ACTIVEDS.dll (2)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
(by ordinal) | 0x16 | 0x420000 | 0x2c420 | 0x2ac20 | - |
(by ordinal) | 0x18 | 0x420004 | 0x2c424 | 0x2ac24 | - |
pdh.dll (1)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
PdhBrowseCountersA | 0x0 | 0x420318 | 0x2c738 | 0x2af38 | 0xb |
AUTHZ.dll (1)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
AuthzInitializeResourceManager | 0x0 | 0x420024 | 0x2c444 | 0x2ac44 | 0x14 |
Memory Dumps (3)
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
pg.exe | 1 | 0x00400000 | 0x00474FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
buffer | 1 | 0x001E0000 | 0x001E9FFF | First Execution | - | 32-bit | 0x001E4D14, 0x001E58A4, ... |
![]() |
![]() |
buffer | 1 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0000 |
![]() |
![]() |
C:\$Recycle.Bin\S-1-5-18\desktop.ini.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\$GetCurrent\SafeOS\preoobe.cmd.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\588bce7c90097ed212\1032\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\588bce7c90097ed212\1035\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\588bce7c90097ed212\1037\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\588bce7c90097ed212\1037\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\588bce7c90097ed212\Graphics\Print.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\588bce7c90097ed212\Graphics\Rotate3.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\588bce7c90097ed212\Graphics\Save.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\588bce7c90097ed212\netfx_Core.mzz.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Binary |
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Binary |
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Binary |
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1025\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1025\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\$GetCurrent\SafeOS\SetupComplete.cmd.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1028\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1029\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1030\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1030\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1029\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1030\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1029\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1031\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1031\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1025\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1032\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1033\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1028\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1032\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1035\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1028\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1033\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1038\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1035\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1033\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1031\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1036\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1041\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1036\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1042\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1043\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1046\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1045\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1044\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1040\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1049\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1038\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1053\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1040\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\2070\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\2052\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1055\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\DisplayIcon.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Graphics\Rotate1.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1038\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1040\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1041\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1042\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\3076\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\3082\SetupResources.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Graphics\Rotate4.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1041\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Graphics\Rotate5.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Graphics\Rotate6.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1043\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1036\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1044\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1037\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1045\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Graphics\Rotate8.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1044\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Graphics\Setup.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Graphics\stop.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1043\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Graphics\warn.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1046\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1046\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Graphics\Rotate2.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1042\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1053\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Graphics\Rotate7.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1049\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1049\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1055\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1055\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\2052\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\2052\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1053\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\2070\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\3076\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\3076\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\1045\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\2070\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\3082\eula.rtf.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Client\UiInfo.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Client\Parameterinfo.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\DHtmlHeader.html.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\netfx_Core_x64.msi.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Extended\UiInfo.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\3082\LocalizedData.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\ParameterInfo.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\header.bmp.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\SplashScreen.bmp.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Strings.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\UiInfo.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Boot\BOOTSTAT.DAT.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\netfx_Core_x86.msi.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\SetupUi.xsd.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\BOOTSECT.BAK.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\watermark.bmp.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\netfx_Extended_x86.msi.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\netfx_Extended_x64.msi.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\desktop.ini.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\RGB9RAST_x64.msi.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\RGB9Rast_x86.msi.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Setup.exe.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\SetupUi.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\README.txt.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\SetupEngine.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\SetupUtility.exe.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\sqmapi.dll.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\Welcome.html.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\FileSystemMetadata.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\Office16\OSPP.HTM.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\Office16\OSPP.VBS.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\Office16\SLERROR.XML.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\AppXManifest.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Unknown |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\BOOTNXT.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Application.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\HardwareEvents.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Internet Explorer.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Key Management Service.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-International%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Store%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00790_.WMF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF.id-B4197730.[lockhelp@qq.com].jack | Dropped File | Stream |
Not Queried