VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Spyware, Trojan |
SpyHunter5.exe
Windows Exe (x86-32)
Created at 2019-04-17T09:51:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\SpyHunter5.exe | Sample File | Binary |
Blacklisted
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-04-04 11:35 (UTC+2) |
Last Seen | 2019-04-15 16:06 (UTC+2) |
Names | Win32.Trojan.Ulise |
Families | Ulise |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x401478 |
Size Of Code | 0x7000 |
Size Of Initialized Data | 0x18000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-10-18 02:19:07+00:00 |
Version Information (8)
»
CompanyName | EnigmaSoft Limited |
FileDescription | SpyHunter product. |
FileVersion | 5.4.2.101 |
InternalName | SpyHunter5.exe |
LegalCopyright | Copyright 2019. EnigmaSoft Limited. All rights reserved. |
OriginalFilename | SpyHunter5.exe |
ProductName | SpyHunter 5 |
ProductVersion | 5.4.2.101 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x6a7c | 0x7000 | 0x1000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.81 |
.data | 0x408000 | 0x4a4 | 0x1000 | 0x8000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x409000 | 0x162ac | 0x17000 | 0x9000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.08 |
Imports (1)
»
*invalid* (84)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
__vbaVarSub | 0x0 | 0x401000 | 0x747c | 0x747c | 0x0 |
_CIcos | 0x0 | 0x401004 | 0x7480 | 0x7480 | 0x0 |
_adj_fptan | 0x0 | 0x401008 | 0x7484 | 0x7484 | 0x0 |
__vbaVarMove | 0x0 | 0x40100c | 0x7488 | 0x7488 | 0x0 |
__vbaAryMove | 0x0 | 0x401010 | 0x748c | 0x748c | 0x0 |
__vbaFreeVar | 0x0 | 0x401014 | 0x7490 | 0x7490 | 0x0 |
__vbaFreeVarList | 0x0 | 0x401018 | 0x7494 | 0x7494 | 0x0 |
_adj_fdiv_m64 | 0x0 | 0x40101c | 0x7498 | 0x7498 | 0x0 |
_adj_fprem1 | 0x0 | 0x401020 | 0x749c | 0x749c | 0x0 |
__vbaRecAnsiToUni | 0x0 | 0x401024 | 0x74a0 | 0x74a0 | 0x0 |
__vbaStrCat | 0x0 | 0x401028 | 0x74a4 | 0x74a4 | 0x0 |
__vbaSetSystemError | 0x0 | 0x40102c | 0x74a8 | 0x74a8 | 0x0 |
__vbaRecDestruct | 0x0 | 0x401030 | 0x74ac | 0x74ac | 0x0 |
__vbaHresultCheckObj | 0x0 | 0x401034 | 0x74b0 | 0x74b0 | 0x0 |
_adj_fdiv_m32 | 0x0 | 0x401038 | 0x74b4 | 0x74b4 | 0x0 |
(by ordinal) | 0x29b | 0x40103c | 0x74b8 | 0x74b8 | - |
__vbaAryDestruct | 0x0 | 0x401040 | 0x74bc | 0x74bc | 0x0 |
__vbaExitProc | 0x0 | 0x401044 | 0x74c0 | 0x74c0 | 0x0 |
__vbaOnError | 0x0 | 0x401048 | 0x74c4 | 0x74c4 | 0x0 |
_adj_fdiv_m16i | 0x0 | 0x40104c | 0x74c8 | 0x74c8 | 0x0 |
_adj_fdivr_m16i | 0x0 | 0x401050 | 0x74cc | 0x74cc | 0x0 |
(by ordinal) | 0x256 | 0x401054 | 0x74d0 | 0x74d0 | - |
_CIsin | 0x0 | 0x401058 | 0x74d4 | 0x74d4 | 0x0 |
(by ordinal) | 0x2c5 | 0x40105c | 0x74d8 | 0x74d8 | - |
(by ordinal) | 0x20d | 0x401060 | 0x74dc | 0x74dc | - |
__vbaChkstk | 0x0 | 0x401064 | 0x74e0 | 0x74e0 | 0x0 |
__vbaGenerateBoundsError | 0x0 | 0x401068 | 0x74e4 | 0x74e4 | 0x0 |
__vbaI2I4 | 0x0 | 0x40106c | 0x74e8 | 0x74e8 | 0x0 |
DllFunctionCall | 0x0 | 0x401070 | 0x74ec | 0x74ec | 0x0 |
__vbaRedimPreserve | 0x0 | 0x401074 | 0x74f0 | 0x74f0 | 0x0 |
_adj_fpatan | 0x0 | 0x401078 | 0x74f4 | 0x74f4 | 0x0 |
__vbaRedim | 0x0 | 0x40107c | 0x74f8 | 0x74f8 | 0x0 |
__vbaRecUniToAnsi | 0x0 | 0x401080 | 0x74fc | 0x74fc | 0x0 |
__vbaUI1I2 | 0x0 | 0x401084 | 0x7500 | 0x7500 | 0x0 |
_CIsqrt | 0x0 | 0x401088 | 0x7504 | 0x7504 | 0x0 |
__vbaVarAnd | 0x0 | 0x40108c | 0x7508 | 0x7508 | 0x0 |
__vbaUI1I4 | 0x0 | 0x401090 | 0x750c | 0x750c | 0x0 |
__vbaVarMul | 0x0 | 0x401094 | 0x7510 | 0x7510 | 0x0 |
__vbaExceptHandler | 0x0 | 0x401098 | 0x7514 | 0x7514 | 0x0 |
__vbaStrToUnicode | 0x0 | 0x40109c | 0x7518 | 0x7518 | 0x0 |
(by ordinal) | 0x25e | 0x4010a0 | 0x751c | 0x751c | - |
_adj_fprem | 0x0 | 0x4010a4 | 0x7520 | 0x7520 | 0x0 |
_adj_fdivr_m64 | 0x0 | 0x4010a8 | 0x7524 | 0x7524 | 0x0 |
__vbaVarDiv | 0x0 | 0x4010ac | 0x7528 | 0x7528 | 0x0 |
(by ordinal) | 0x260 | 0x4010b0 | 0x752c | 0x752c | - |
__vbaFPException | 0x0 | 0x4010b4 | 0x7530 | 0x7530 | 0x0 |
__vbaInStrVar | 0x0 | 0x4010b8 | 0x7534 | 0x7534 | 0x0 |
__vbaUbound | 0x0 | 0x4010bc | 0x7538 | 0x7538 | 0x0 |
__vbaI2Var | 0x0 | 0x4010c0 | 0x753c | 0x753c | 0x0 |
(by ordinal) | 0x219 | 0x4010c4 | 0x7540 | 0x7540 | - |
(by ordinal) | 0x284 | 0x4010c8 | 0x7544 | 0x7544 | - |
_CIlog | 0x0 | 0x4010cc | 0x7548 | 0x7548 | 0x0 |
__vbaErrorOverflow | 0x0 | 0x4010d0 | 0x754c | 0x754c | 0x0 |
__vbaVar2Vec | 0x0 | 0x4010d4 | 0x7550 | 0x7550 | 0x0 |
__vbaNew2 | 0x0 | 0x4010d8 | 0x7554 | 0x7554 | 0x0 |
__vbaInStr | 0x0 | 0x4010dc | 0x7558 | 0x7558 | 0x0 |
__vbaVarInt | 0x0 | 0x4010e0 | 0x755c | 0x755c | 0x0 |
_adj_fdiv_m32i | 0x0 | 0x4010e4 | 0x7560 | 0x7560 | 0x0 |
_adj_fdivr_m32i | 0x0 | 0x4010e8 | 0x7564 | 0x7564 | 0x0 |
__vbaStrCopy | 0x0 | 0x4010ec | 0x7568 | 0x7568 | 0x0 |
__vbaI4Str | 0x0 | 0x4010f0 | 0x756c | 0x756c | 0x0 |
__vbaFreeStrList | 0x0 | 0x4010f4 | 0x7570 | 0x7570 | 0x0 |
_adj_fdivr_m32 | 0x0 | 0x4010f8 | 0x7574 | 0x7574 | 0x0 |
__vbaPowerR8 | 0x0 | 0x4010fc | 0x7578 | 0x7578 | 0x0 |
_adj_fdiv_r | 0x0 | 0x401100 | 0x757c | 0x757c | 0x0 |
(by ordinal) | 0x64 | 0x401104 | 0x7580 | 0x7580 | - |
__vbaVarAdd | 0x0 | 0x401108 | 0x7584 | 0x7584 | 0x0 |
__vbaAryLock | 0x0 | 0x40110c | 0x7588 | 0x7588 | 0x0 |
__vbaStrToAnsi | 0x0 | 0x401110 | 0x758c | 0x758c | 0x0 |
__vbaVarDup | 0x0 | 0x401114 | 0x7590 | 0x7590 | 0x0 |
__vbaFpI4 | 0x0 | 0x401118 | 0x7594 | 0x7594 | 0x0 |
__vbaVarCopy | 0x0 | 0x40111c | 0x7598 | 0x7598 | 0x0 |
__vbaVarTstGe | 0x0 | 0x401120 | 0x759c | 0x759c | 0x0 |
(by ordinal) | 0x268 | 0x401124 | 0x75a0 | 0x75a0 | - |
__vbaRecDestructAnsi | 0x0 | 0x401128 | 0x75a4 | 0x75a4 | 0x0 |
_CIatan | 0x0 | 0x40112c | 0x75a8 | 0x75a8 | 0x0 |
__vbaStrMove | 0x0 | 0x401130 | 0x75ac | 0x75ac | 0x0 |
_allmul | 0x0 | 0x401134 | 0x75b0 | 0x75b0 | 0x0 |
_CItan | 0x0 | 0x401138 | 0x75b4 | 0x75b4 | 0x0 |
__vbaUI1Var | 0x0 | 0x40113c | 0x75b8 | 0x75b8 | 0x0 |
__vbaAryUnlock | 0x0 | 0x401140 | 0x75bc | 0x75bc | 0x0 |
_CIexp | 0x0 | 0x401144 | 0x75c0 | 0x75c0 | 0x0 |
__vbaFreeObj | 0x0 | 0x401148 | 0x75c4 | 0x75c4 | 0x0 |
__vbaFreeStr | 0x0 | 0x40114c | 0x75c8 | 0x75c8 | 0x0 |
Memory Dumps (6)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x00210000 | 0x00215FFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
spyhunter5.exe | 1 | 0x00400000 | 0x0041FFFF | Forced | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00210000 | 0x00219FFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 2 | 0x00400000 | 0x00407FFF | First Execution | - | 32-bit | 0x00402000, 0x00401FE7, ... |
![]() |
![]() |
...
|
buffer | 2 | 0x00400000 | 0x00407FFF | Content Changed | - | 32-bit | 0x00404000 |
![]() |
![]() |
...
|
spyhunter5.exe | 1 | 0x00400000 | 0x0041FFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Ulise.32528 |
Malicious
|
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSPTLS.DLL | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\SmartTagInstall.exe | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\WPFT632.CNV | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\COMPASS.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\WHTGTXT.SHX | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\1033\FPEXT.MSG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\FPWEC.DLL | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VSTO\vstoee100.tlb | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7\1033\VBE7INTL.DLL | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\ShellUI.MST | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.msi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm | Modified File | Compressed |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\osetupui.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjLR.cab | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.msi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OnoteLR.cab | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\msvcr90.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.msi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\setup.exe | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeLR.cab | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\setup.exe | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\DESIGNER\MSADDNDR.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccLR.cab | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\MTEXTRA.TTF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\eqnedt32.exe.manifest | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.HLP | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Filters\odffilt.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Filters\msgfilt.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Filters\offfiltx.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Filters\VISFILT.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\ACEINTL.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\MSClientDataMgr\MSCDM.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\MSSOAPR3.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\OARPMANR.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\ODBCMON.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MUAUTH.CAB | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSSOAP30.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MUOPTIN.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXEV.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\ExcelMUI.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\SETUP.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OSetupPS.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\SETUP.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.fr\Proof.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\SETUP.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OSETUP.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\Proofing.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\VisiorWW.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_ES.LEX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_EN.LEX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPWMI.MOF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_FR.LEX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\FPLACE.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\FSTOCK.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\MSTAG.TLB | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\MOFL.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\IMCONTACT.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\IETAG.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\BASMLA.XSL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\RECOVR32.CNV | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\WPFT532.CNV | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\Wks9Pxy.cnv | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\AXIS.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\AXIS.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\COMPASS.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\ICE.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\JOURNAL.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\NETWORK.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\SKY\SKY.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\SKY\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\SPRING\SPRING.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\SPRING\SPRING.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\SPRING\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\SLATE\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\THEMES.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\STRTEDGE\STRTEDGE.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\SPRING\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATERMAR\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\WTSP61MS.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\SKY\SKY.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\MSB1CACH.LEX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\MSB1XTOR.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\MSB1CORE.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7\1033\VBUI6.CHM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VC\msdia100.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\MSB1STAR.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7\1033\VBOB6.CHM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7\VBE7.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7\1033\VBLR6.CHM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\WHGTXT.SHX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VC\msdia90.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\WHTMTXT.SHX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOLoaderUI.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Web Folders\MSOSV.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\System\MSMAPI\1033\MSMAPI32.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Web Folders\1033\MSOSVINT.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\System\Ole DB\xmlrwbin.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VSTO\vstoee90.tlb | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\System\Ole DB\xmlrw.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\FPSRVUTL.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOMessageProvider.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VSTO\vstoee.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOInstallerUI.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOLoader.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.config | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\ICAD.FMP | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\IC-TXT.SHX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\EXTFONT.SHX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\GBCBIG.SHX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7\1033\VBHW6.CHM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\CHINESET.SHX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\WHGDTXT.SHX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7\1033\VBCN6.CHM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7\1033\VBENDF98.CHM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\BIGFONT.SHX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FREN\WT61FR.LEX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\MSB1AR.LEX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FRAR\MSB1FRAR.ITS | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FREN\MSB1FREN.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7\1033\FM20.CHM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ESEN\MSB1ESEN.DLL | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ENFR\MSB1ENFR.ITS | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FREN\MSB1FREN.ITS | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Internet Explorer\SIGNUP\install.ins | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ENES\MSB1ENES.ITS | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ESEN\MSB1ESEN.ITS | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ESEN\WT61ES.LEX | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\_uninstalling_.png | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\$HOWDECRYPT$.txt | Dropped File | Text |
Not Queried
|
...
|
»