Ransomware Spyware
Mal/Generic-S
Created on 2022-03-08T14:19:00
672fb249e520f4496e72021f887f8bb86fec5604317d8af3f0800d49aa157be1.exe
Remarks (1/1)
(0x02000046): The maximum binlog size was reached. The analysis was terminated prematurely.
Remarks
(0x0200004A): One dump of 8 MB was skipped because it exceeded the maximum dump size of 7 MB.
(0x0200004F): Static Analysis failed to analyze file artifacts in this analysis due to an error. Check the artifact_static_analysis.log file for further information.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\kEecfMwgj\Desktop\672fb249e520f4496e72021f887f8bb86fec5604317d8af3f0800d49aa157be1.exe | Sample File | Binary |
malicious
|
...
|
Verdict |
malicious
|
Image Base | 0x400000 |
Entry Point | 0x420e36 |
Size Of Code | 0x52a00 |
Size Of Initialized Data | 0x2f200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-21 19:38:09+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x529e8 | 0x52a00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x454000 | 0x1c13c | 0x1c200 | 0x52e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.68 |
.data | 0x471000 | 0xe33c | 0x2600 | 0x6f000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.77 |
.rsrc | 0x480000 | 0x1e0 | 0x200 | 0x71600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.7 |
.reloc | 0x481000 | 0x48a0 | 0x4a00 | 0x71800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.6 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetOpenEnumW | - | 0x45420c | 0x6f714 | 0x6e514 | 0x3d |
WNetEnumResourceW | - | 0x454210 | 0x6f718 | 0x6e518 | 0x1c |
WNetCloseEnum | - | 0x454214 | 0x6f71c | 0x6e51c | 0x10 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GlobalFree | - | 0x454020 | 0x6f528 | 0x6e328 | 0x2ba |
QueryPerformanceCounter | - | 0x454024 | 0x6f52c | 0x6e32c | 0x3a7 |
ReadFile | - | 0x454028 | 0x6f530 | 0x6e330 | 0x3c0 |
GetModuleFileNameA | - | 0x45402c | 0x6f534 | 0x6e334 | 0x213 |
GetFileSizeEx | - | 0x454030 | 0x6f538 | 0x6e338 | 0x1f1 |
WriteFile | - | 0x454034 | 0x6f53c | 0x6e33c | 0x525 |
TerminateProcess | - | 0x454038 | 0x6f540 | 0x6e340 | 0x4c0 |
SetEndOfFile | - | 0x45403c | 0x6f544 | 0x6e344 | 0x453 |
CreateFileW | - | 0x454040 | 0x6f548 | 0x6e348 | 0x8f |
lstrcatA | - | 0x454044 | 0x6f54c | 0x6e34c | 0x53e |
OpenProcess | - | 0x454048 | 0x6f550 | 0x6e350 | 0x380 |
GetLogicalDriveStringsW | - | 0x45404c | 0x6f554 | 0x6e354 | 0x208 |
Sleep | - | 0x454050 | 0x6f558 | 0x6e358 | 0x4b2 |
GlobalAlloc | - | 0x454054 | 0x6f55c | 0x6e35c | 0x2b3 |
lstrcpyA | - | 0x454058 | 0x6f560 | 0x6e360 | 0x547 |
CloseHandle | - | 0x45405c | 0x6f564 | 0x6e364 | 0x52 |
GetWindowsDirectoryA | - | 0x454060 | 0x6f568 | 0x6e368 | 0x2ae |
SetFilePointerEx | - | 0x454064 | 0x6f56c | 0x6e36c | 0x467 |
ExitProcess | - | 0x454068 | 0x6f570 | 0x6e370 | 0x119 |
CreateProcessA | - | 0x45406c | 0x6f574 | 0x6e374 | 0xa4 |
GetTickCount | - | 0x454070 | 0x6f578 | 0x6e378 | 0x293 |
MoveFileW | - | 0x454074 | 0x6f57c | 0x6e37c | 0x363 |
GetDriveTypeW | - | 0x454078 | 0x6f580 | 0x6e380 | 0x1d3 |
GetSystemTimeAsFileTime | - | 0x45407c | 0x6f584 | 0x6e384 | 0x279 |
GetProcessHeap | - | 0x454080 | 0x6f588 | 0x6e388 | 0x24a |
FindClose | - | 0x454084 | 0x6f58c | 0x6e38c | 0x12e |
FindNextFileW | - | 0x454088 | 0x6f590 | 0x6e390 | 0x145 |
FindFirstFileW | - | 0x45408c | 0x6f594 | 0x6e394 | 0x139 |
SetStdHandle | - | 0x454090 | 0x6f598 | 0x6e398 | 0x487 |
WriteConsoleW | - | 0x454094 | 0x6f59c | 0x6e39c | 0x524 |
HeapSize | - | 0x454098 | 0x6f5a0 | 0x6e3a0 | 0x2d4 |
GetLastError | - | 0x45409c | 0x6f5a4 | 0x6e3a4 | 0x202 |
IsDebuggerPresent | - | 0x4540a0 | 0x6f5a8 | 0x6e3a8 | 0x300 |
WideCharToMultiByte | - | 0x4540a4 | 0x6f5ac | 0x6e3ac | 0x511 |
EnterCriticalSection | - | 0x4540a8 | 0x6f5b0 | 0x6e3b0 | 0xee |
LeaveCriticalSection | - | 0x4540ac | 0x6f5b4 | 0x6e3b4 | 0x339 |
TryEnterCriticalSection | - | 0x4540b0 | 0x6f5b8 | 0x6e3b8 | 0x4ce |
DeleteCriticalSection | - | 0x4540b4 | 0x6f5bc | 0x6e3bc | 0xd1 |
GetCurrentThreadId | - | 0x4540b8 | 0x6f5c0 | 0x6e3c0 | 0x1c5 |
DuplicateHandle | - | 0x4540bc | 0x6f5c4 | 0x6e3c4 | 0xe8 |
WaitForSingleObjectEx | - | 0x4540c0 | 0x6f5c8 | 0x6e3c8 | 0x4fa |
GetCurrentProcess | - | 0x4540c4 | 0x6f5cc | 0x6e3cc | 0x1c0 |
SwitchToThread | - | 0x4540c8 | 0x6f5d0 | 0x6e3d0 | 0x4bc |
GetCurrentThread | - | 0x4540cc | 0x6f5d4 | 0x6e3d4 | 0x1c4 |
SetLastError | - | 0x4540d0 | 0x6f5d8 | 0x6e3d8 | 0x473 |
InitializeCriticalSectionAndSpinCount | - | 0x4540d4 | 0x6f5dc | 0x6e3dc | 0x2e3 |
CreateEventW | - | 0x4540d8 | 0x6f5e0 | 0x6e3e0 | 0x85 |
TlsAlloc | - | 0x4540dc | 0x6f5e4 | 0x6e3e4 | 0x4c5 |
TlsGetValue | - | 0x4540e0 | 0x6f5e8 | 0x6e3e8 | 0x4c7 |
TlsSetValue | - | 0x4540e4 | 0x6f5ec | 0x6e3ec | 0x4c8 |
TlsFree | - | 0x4540e8 | 0x6f5f0 | 0x6e3f0 | 0x4c6 |
GetModuleHandleW | - | 0x4540ec | 0x6f5f4 | 0x6e3f4 | 0x218 |
GetProcAddress | - | 0x4540f0 | 0x6f5f8 | 0x6e3f8 | 0x245 |
EncodePointer | - | 0x4540f4 | 0x6f5fc | 0x6e3fc | 0xea |
DecodePointer | - | 0x4540f8 | 0x6f600 | 0x6e400 | 0xca |
MultiByteToWideChar | - | 0x4540fc | 0x6f604 | 0x6e404 | 0x367 |
LCMapStringW | - | 0x454100 | 0x6f608 | 0x6e408 | 0x32d |
GetLocaleInfoW | - | 0x454104 | 0x6f60c | 0x6e40c | 0x206 |
GetStringTypeW | - | 0x454108 | 0x6f610 | 0x6e410 | 0x269 |
GetCPInfo | - | 0x45410c | 0x6f614 | 0x6e414 | 0x172 |
UnhandledExceptionFilter | - | 0x454110 | 0x6f618 | 0x6e418 | 0x4d3 |
SetUnhandledExceptionFilter | - | 0x454114 | 0x6f61c | 0x6e41c | 0x4a5 |
IsProcessorFeaturePresent | - | 0x454118 | 0x6f620 | 0x6e420 | 0x304 |
GetStartupInfoW | - | 0x45411c | 0x6f624 | 0x6e424 | 0x263 |
GetCurrentProcessId | - | 0x454120 | 0x6f628 | 0x6e428 | 0x1c1 |
InitializeSListHead | - | 0x454124 | 0x6f62c | 0x6e42c | 0x2e7 |
CreateTimerQueue | - | 0x454128 | 0x6f630 | 0x6e430 | 0xbc |
SetEvent | - | 0x45412c | 0x6f634 | 0x6e434 | 0x459 |
SignalObjectAndWait | - | 0x454130 | 0x6f638 | 0x6e438 | 0x4b0 |
CreateThread | - | 0x454134 | 0x6f63c | 0x6e43c | 0xb5 |
SetThreadPriority | - | 0x454138 | 0x6f640 | 0x6e440 | 0x499 |
GetThreadPriority | - | 0x45413c | 0x6f644 | 0x6e444 | 0x28e |
GetLogicalProcessorInformation | - | 0x454140 | 0x6f648 | 0x6e448 | 0x20a |
CreateTimerQueueTimer | - | 0x454144 | 0x6f64c | 0x6e44c | 0xbd |
ChangeTimerQueueTimer | - | 0x454148 | 0x6f650 | 0x6e450 | 0x48 |
DeleteTimerQueueTimer | - | 0x45414c | 0x6f654 | 0x6e454 | 0xda |
GetNumaHighestNodeNumber | - | 0x454150 | 0x6f658 | 0x6e458 | 0x229 |
GetProcessAffinityMask | - | 0x454154 | 0x6f65c | 0x6e45c | 0x246 |
SetThreadAffinityMask | - | 0x454158 | 0x6f660 | 0x6e460 | 0x490 |
RegisterWaitForSingleObject | - | 0x45415c | 0x6f664 | 0x6e464 | 0x3f5 |
UnregisterWait | - | 0x454160 | 0x6f668 | 0x6e468 | 0x4da |
GetThreadTimes | - | 0x454164 | 0x6f66c | 0x6e46c | 0x291 |
FreeLibrary | - | 0x454168 | 0x6f670 | 0x6e470 | 0x162 |
FreeLibraryAndExitThread | - | 0x45416c | 0x6f674 | 0x6e474 | 0x163 |
GetModuleFileNameW | - | 0x454170 | 0x6f678 | 0x6e478 | 0x214 |
GetModuleHandleA | - | 0x454174 | 0x6f67c | 0x6e47c | 0x215 |
LoadLibraryExW | - | 0x454178 | 0x6f680 | 0x6e480 | 0x33e |
GetVersionExW | - | 0x45417c | 0x6f684 | 0x6e484 | 0x2a4 |
VirtualAlloc | - | 0x454180 | 0x6f688 | 0x6e488 | 0x4e9 |
VirtualProtect | - | 0x454184 | 0x6f68c | 0x6e48c | 0x4ef |
VirtualFree | - | 0x454188 | 0x6f690 | 0x6e490 | 0x4ec |
ReleaseSemaphore | - | 0x45418c | 0x6f694 | 0x6e494 | 0x3fe |
InterlockedPopEntrySList | - | 0x454190 | 0x6f698 | 0x6e498 | 0x2f0 |
InterlockedPushEntrySList | - | 0x454194 | 0x6f69c | 0x6e49c | 0x2f1 |
InterlockedFlushSList | - | 0x454198 | 0x6f6a0 | 0x6e4a0 | 0x2ee |
QueryDepthSList | - | 0x45419c | 0x6f6a4 | 0x6e4a4 | 0x39e |
UnregisterWaitEx | - | 0x4541a0 | 0x6f6a8 | 0x6e4a8 | 0x4db |
LoadLibraryW | - | 0x4541a4 | 0x6f6ac | 0x6e4ac | 0x33f |
RtlUnwind | - | 0x4541a8 | 0x6f6b0 | 0x6e4b0 | 0x418 |
RaiseException | - | 0x4541ac | 0x6f6b4 | 0x6e4b4 | 0x3b1 |
ExitThread | - | 0x4541b0 | 0x6f6b8 | 0x6e4b8 | 0x11a |
GetModuleHandleExW | - | 0x4541b4 | 0x6f6bc | 0x6e4bc | 0x217 |
GetStdHandle | - | 0x4541b8 | 0x6f6c0 | 0x6e4c0 | 0x264 |
GetACP | - | 0x4541bc | 0x6f6c4 | 0x6e4c4 | 0x168 |
GetFileType | - | 0x4541c0 | 0x6f6c8 | 0x6e4c8 | 0x1f3 |
FlushFileBuffers | - | 0x4541c4 | 0x6f6cc | 0x6e4cc | 0x157 |
GetConsoleCP | - | 0x4541c8 | 0x6f6d0 | 0x6e4d0 | 0x19a |
GetConsoleMode | - | 0x4541cc | 0x6f6d4 | 0x6e4d4 | 0x1ac |
HeapFree | - | 0x4541d0 | 0x6f6d8 | 0x6e4d8 | 0x2cf |
HeapAlloc | - | 0x4541d4 | 0x6f6dc | 0x6e4dc | 0x2cb |
IsValidLocale | - | 0x4541d8 | 0x6f6e0 | 0x6e4e0 | 0x30c |
GetUserDefaultLCID | - | 0x4541dc | 0x6f6e4 | 0x6e4e4 | 0x29b |
EnumSystemLocalesW | - | 0x4541e0 | 0x6f6e8 | 0x6e4e8 | 0x10f |
ReadConsoleW | - | 0x4541e4 | 0x6f6ec | 0x6e4ec | 0x3be |
HeapReAlloc | - | 0x4541e8 | 0x6f6f0 | 0x6e4f0 | 0x2d2 |
FindFirstFileExW | - | 0x4541ec | 0x6f6f4 | 0x6e4f4 | 0x134 |
IsValidCodePage | - | 0x4541f0 | 0x6f6f8 | 0x6e4f8 | 0x30a |
GetOEMCP | - | 0x4541f4 | 0x6f6fc | 0x6e4fc | 0x237 |
GetCommandLineA | - | 0x4541f8 | 0x6f700 | 0x6e500 | 0x186 |
GetCommandLineW | - | 0x4541fc | 0x6f704 | 0x6e504 | 0x187 |
GetEnvironmentStringsW | - | 0x454200 | 0x6f708 | 0x6e508 | 0x1da |
FreeEnvironmentStringsW | - | 0x454204 | 0x6f70c | 0x6e50c | 0x161 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CharLowerW | - | 0x45421c | 0x6f724 | 0x6e524 | 0x2e |
GetCursorPos | - | 0x454220 | 0x6f728 | 0x6e528 | 0x120 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptAcquireContextW | - | 0x454000 | 0x6f508 | 0x6e308 | 0xb1 |
CloseServiceHandle | - | 0x454004 | 0x6f50c | 0x6e30c | 0x57 |
OpenSCManagerW | - | 0x454008 | 0x6f510 | 0x6e310 | 0x1f9 |
ControlService | - | 0x45400c | 0x6f514 | 0x6e314 | 0x5c |
OpenServiceW | - | 0x454010 | 0x6f518 | 0x6e318 | 0x1fb |
QueryServiceStatusEx | - | 0x454014 | 0x6f51c | 0x6e31c | 0x229 |
CryptGenRandom | - | 0x454018 | 0x6f520 | 0x6e320 | 0xc1 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
672fb249e520f4496e72021f887f8bb86fec5604317d8af3f0800d49aa157be1.exe | 1 | 0x00DE0000 | 0x00E65FFF | Relevant Image |
![]() |
32-bit | 0x00E311A9 |
![]() |
...
|
672fb249e520f4496e72021f887f8bb86fec5604317d8af3f0800d49aa157be1.exe | 1 | 0x00DE0000 | 0x00E65FFF | Final Dump |
![]() |
32-bit | - |
![]() |
...
|
Verdict |
malicious
|
Names | Mal/Generic-S |
C:\users\keecfmwgj\appdata\roaming\microsoft\word\startup\!!FAQ for Decryption!!.txt | Dropped File | Unknown |
N/A
Not Available because the file was not extracted successfully.
|
...
|
MIME Type | - |
File Size | - |
MD5 | - |
SHA1 | - |
SHA256 | - |
SSDeep | - |
ImpHash | - |
C:\program files\common files\lcl0t-.gif | Modified File | Stream |
clean
|
...
|
C:\program files\common files\microsoft shared\clicktorun\c2rheartbeatconfig.xml | Modified File | Stream |
clean
|
...
|
C:\program files\common files\microsoft shared\clicktorun\i640.hash | Modified File | Stream |
clean
|
...
|
C:\program files\common files\microsoft shared\clicktorun\i641033.hash | Modified File | Stream |
clean
|
...
|
C:\program files\common files\microsoft shared\clicktorun\officeupdateschedule.xml | Modified File | Stream |
clean
|
...
|
C:\program files\common files\microsoft shared\clicktorun\servicewatcherschedule.xml | Modified File | Stream |
clean
|
...
|
C:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppobjs-spp-plugin-manifest-signed.xrm-ms | Modified File | Stream |
clean
|
...
|
C:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppwmi.mof | Modified File | Stream |
clean
|
...
|
C:\program files\common files\microsoft shared\stationery\desktop.ini | Modified File | Stream |
clean
|
...
|
C:\program files\common files\n94j0b1q.jpg | Modified File | Stream |
clean
|
...
|
C:\program files\common files\uxvb6tnruw.bmp | Modified File | Stream |
clean
|
...
|
C:\program files\internet explorer\signup\install.ins | Modified File | Stream |
clean
|
...
|
C:\program files\msbuild\microsoft\windows workflow foundation\v3.0\workflow.targets | Modified File | Stream |
clean
|
...
|
C:\program files\msbuild\microsoft\windows workflow foundation\v3.0\workflow.visualbasic.targets | Modified File | Stream |
clean
|
...
|
C:\program files\reference assemblies\microsoft\framework\v3.0\redistlist\frameworklist.xml | Modified File | Stream |
clean
|
...
|
C:\program files\reference assemblies\microsoft\framework\v3.0\winfxlist.xml | Modified File | Stream |
clean
|
...
|
C:\program files\windows sidebar\settings.ini | Modified File | Stream |
clean
|
...
|
C:\program files\windowspowershell\modules\packagemanagement\1.0.0.1\packagemanagement.format.ps1xml | Modified File | Stream |
clean
|
...
|
C:\program files\windowspowershell\modules\packagemanagement\1.0.0.1\packagemanagement.psd1 | Modified File | Stream |
clean
|
...
|
C:\program files\windowspowershell\modules\packagemanagement\1.0.0.1\packageproviderfunctions.psm1 | Modified File | Stream |
clean
|
...
|
C:\program files\windowspowershell\modules\powershellget\1.0.0.1\en-us\psget.resource.psd1 | Modified File | Stream |
clean
|
...
|
C:\program files\windowspowershell\modules\powershellget\1.0.0.1\powershellget.psd1 | Modified File | Stream |
clean
|
...
|
C:\program files\windowspowershell\modules\powershellget\1.0.0.1\psget.format.ps1xml | Modified File | Stream |
clean
|
...
|
C:\program files\windowspowershell\modules\powershellget\1.0.0.1\psget.resource.psd1 | Modified File | Stream |
clean
|
...
|
C:\program files\windowspowershell\modules\powershellget\1.0.0.1\psmodule.psm1 | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\common files\designer\msaddndr.olb | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\common files\microsoft shared\office16\office setup controller\pkeyconfig-office.xrm-ms | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\common files\microsoft shared\stationery\desktop.ini | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\common files\microsoft shared\vsta\appinfodocument\addins.store | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\common files\microsoft shared\vsta\pipeline.v10.0\pipelinesegments.store | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\common files\microsoft shared\vsta\vstofiles.cat | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\common files\microsoft shared\vsto\actionspane3.xsd | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\common files\microsoft shared\vsto\vstoee100.tlb | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\common files\microsoft shared\vsto\vstoee90.tlb | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\desktop.ini | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\internet explorer\signup\install.ins | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\microsoft.net\redistlist\assemblylist_4_client.xml | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\microsoft.net\redistlist\assemblylist_4_extended.xml | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\msbuild\microsoft\windows workflow foundation\v3.0\workflow.targets | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\msbuild\microsoft\windows workflow foundation\v3.0\workflow.visualbasic.targets | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\reference assemblies\microsoft\framework\v3.0\redistlist\frameworklist.xml | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\reference assemblies\microsoft\framework\v3.0\winfxlist.xml | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\windows sidebar\settings.ini | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\windowspowershell\modules\packagemanagement\1.0.0.1\packagemanagement.format.ps1xml | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\windowspowershell\modules\packagemanagement\1.0.0.1\packagemanagement.psd1 | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\windowspowershell\modules\packagemanagement\1.0.0.1\packageproviderfunctions.psm1 | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\windowspowershell\modules\powershellget\1.0.0.1\en-us\psget.resource.psd1 | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\windowspowershell\modules\powershellget\1.0.0.1\powershellget.psd1 | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\windowspowershell\modules\powershellget\1.0.0.1\psget.format.ps1xml | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\windowspowershell\modules\powershellget\1.0.0.1\psget.resource.psd1 | Modified File | Stream |
clean
|
...
|
C:\program files (x86)\windowspowershell\modules\powershellget\1.0.0.1\psmodule.psm1 | Modified File | Stream |
clean
|
...
|
C:\users\all users\microsoft\assistance\client\1.0\en-us\help_cvalidator.h1d.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\assistance\client\1.0\en-us\help_mkwd_assetid.h1w.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\assistance\client\1.0\en-us\help_mkwd_bestbet.h1w.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\assistance\client\1.0\en-us\help_mtoc_help.h1h.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\assistance\client\1.0\en-us\help_mvalidator.h1d.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\assistance\client\1.0\en-us\help_mvalidator.lck.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\assistance\client\1.0\en-us\help{9daa54e8-cd95-4107-8e7f-ba3f24732d95}.h1q.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\deploymentconfig.0.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\deploymentconfig.2.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\e728f99d-05d1-4020-9ece-6de2ec414166\en-us.16\masterdescriptor.en-us.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\e728f99d-05d1-4020-9ece-6de2ec414166\en-us.16\s321033.hash.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\e728f99d-05d1-4020-9ece-6de2ec414166\en-us.16\stream.x86.en-us.man.dat.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\e728f99d-05d1-4020-9ece-6de2ec414166\x-none.16\masterdescriptor.x-none.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\e728f99d-05d1-4020-9ece-6de2ec414166\x-none.16\s320.hash.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\e728f99d-05d1-4020-9ece-6de2ec414166\x-none.16\stream.x86.x-none.man.dat.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\deploymentconfiguration.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\manifest.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\userdeploymentconfiguration.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\usermanifest.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\airspace.etw.man.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.access.access.x-none.msi.16.x-none.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.accessmui.msi.16.en-us.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.accessmuiset.msi.16.en-us.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.dcf.dcf.x-none.msi.16.x-none.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.dcfmui.msi.16.en-us.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.excel.excel.x-none.msi.16.x-none.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.excelmui.msi.16.en-us.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.groove.groove.x-none.msi.16.x-none.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.groovemui.msi.16.en-us.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.lync.lync.x-none.msi.16.x-none.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.lyncmui.msi.16.en-us.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.office64mui.msi.16.en-us.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.office64muiset.msi.16.en-us.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.officemui.msi.16.en-us.xml.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\officesoftwareprotectionplatform\tokens.dat.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\search\data\applications\windows\windows.edb.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\microsoft\windows defender\definition updates\{d2b0b133-42ed-44d3-809a-46ebb62ba863}\mpasbase.vdm.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\package cache\{0fa68574-690b-4b00-89aa-b28946231449}v14.25.28508\packages\vcruntimeadditional_x86\cab1.cab.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\package cache\{37b8f9c7-03fb-3253-8781-2517c99d7c00}v11.0.61030\packages\vcruntimeadditional_amd64\cab1.cab.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\package cache\{7d0b74c2-c3f8-4af1-940f-cd79ab4b2dce}v14.25.28508\packages\vcruntimeadditional_amd64\cab1.cab.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\package cache\{929fbd26-9020-399b-9a7a-751d61f0b942}v12.0.21005\packages\vcruntimeadditional_amd64\cab1.cab.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\package cache\{b175520c-86a2-35a7-8619-86dc379688b9}v11.0.61030\packages\vcruntimeadditional_x86\cab1.cab.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\all users\package cache\{f8cfeb22-a2e7-3971-9eda-4b11edefc185}v12.0.21005\packages\vcruntimeadditional_x86\cab1.cab.cuba | Dropped File | Stream |
clean
|
...
|
C:\users\default\appdata\local\microsoft\windows mail\backup\new\windowsmail.msmessagestore | Modified File | Stream |
clean
|
...
|
C:\users\default\appdata\local\microsoft\windows mail\windowsmail.msmessagestore | Modified File | Stream |
clean
|
...
|
C:\users\keecfmwgj\appdata\local\microsoft\media player\sync playlists\en-us\00010c6e\03_music_rated_at_4_or_5_stars.wpl | Modified File | Stream |
clean
|
...
|
C:\users\keecfmwgj\appdata\local\microsoft\onedrive\17.3.4604.0120\pt-pt\filesync.localizedresources.dll.mui | Modified File | Stream |
clean
|
...
|
C:\users\keecfmwgj\appdata\local\microsoft\windows mail\backup\new\windowsmail.msmessagestore | Modified File | Stream |
clean
|
...
|
C:\users\keecfmwgj\appdata\local\microsoft\windows mail\windowsmail.msmessagestore | Modified File | Stream |
clean
|
...
|
C:\users\keecfmwgj\appdata\roaming\microsoft\document building blocks\1033\16\built-in building blocks.dotx | Modified File | Word Document |
clean
|
...
|