VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Spyware
Dropper
|
Threat Names: |
DeepScan:Generic.Ransom.Amnesia.8395E6F2
Trojan.GenericKD.31382075
DeepScan:Generic.Ransom.Amnesia.05550D4C
...
|
mqrywk.exe
Windows Exe (x86-32)
Created at 2020-02-07T14:09:00
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\mqrywk.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x42d298 |
Size Of Code | 0x2c200 |
Size Of Initialized Data | 0x4400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-25 22:39:37+00:00 |
Packer | BobSoft Mini Delphi -> BoB / BobSoft |
Sections (8)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2bd50 | 0x2be00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.99 |
.itext | 0x42d000 | 0x2b4 | 0x400 | 0x2c200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.72 |
.data | 0x42e000 | 0x2cc4 | 0x2e00 | 0x2c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.76 |
.bss | 0x431000 | 0x62d4 | 0x0 | 0x2f400 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x438000 | 0x112c | 0x1200 | 0x2f400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.88 |
.tls | 0x43a000 | 0x8 | 0x0 | 0x30600 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x43b000 | 0x18 | 0x200 | 0x30600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.21 |
.rsrc | 0x43c000 | 0x0 | 0x200 | 0x30800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0 |
Imports (15)
»
oleaut32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x4383d0 | 0x38140 | 0x2f540 | 0x0 |
SysReAllocStringLen | 0x0 | 0x4383d4 | 0x38144 | 0x2f544 | 0x0 |
SysAllocStringLen | 0x0 | 0x4383d8 | 0x38148 | 0x2f548 | 0x0 |
advapi32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExA | 0x0 | 0x4383e0 | 0x38150 | 0x2f550 | 0x0 |
RegOpenKeyExA | 0x0 | 0x4383e4 | 0x38154 | 0x2f554 | 0x0 |
RegCloseKey | 0x0 | 0x4383e8 | 0x38158 | 0x2f558 | 0x0 |
user32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetKeyboardType | 0x0 | 0x4383f0 | 0x38160 | 0x2f560 | 0x0 |
DestroyWindow | 0x0 | 0x4383f4 | 0x38164 | 0x2f564 | 0x0 |
LoadStringA | 0x0 | 0x4383f8 | 0x38168 | 0x2f568 | 0x0 |
MessageBoxA | 0x0 | 0x4383fc | 0x3816c | 0x2f56c | 0x0 |
CharNextA | 0x0 | 0x438400 | 0x38170 | 0x2f570 | 0x0 |
kernel32.dll (30)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetACP | 0x0 | 0x438408 | 0x38178 | 0x2f578 | 0x0 |
Sleep | 0x0 | 0x43840c | 0x3817c | 0x2f57c | 0x0 |
VirtualFree | 0x0 | 0x438410 | 0x38180 | 0x2f580 | 0x0 |
VirtualAlloc | 0x0 | 0x438414 | 0x38184 | 0x2f584 | 0x0 |
GetTickCount | 0x0 | 0x438418 | 0x38188 | 0x2f588 | 0x0 |
QueryPerformanceCounter | 0x0 | 0x43841c | 0x3818c | 0x2f58c | 0x0 |
GetCurrentThreadId | 0x0 | 0x438420 | 0x38190 | 0x2f590 | 0x0 |
VirtualQuery | 0x0 | 0x438424 | 0x38194 | 0x2f594 | 0x0 |
WideCharToMultiByte | 0x0 | 0x438428 | 0x38198 | 0x2f598 | 0x0 |
MultiByteToWideChar | 0x0 | 0x43842c | 0x3819c | 0x2f59c | 0x0 |
lstrlenA | 0x0 | 0x438430 | 0x381a0 | 0x2f5a0 | 0x0 |
lstrcpynA | 0x0 | 0x438434 | 0x381a4 | 0x2f5a4 | 0x0 |
LoadLibraryExA | 0x0 | 0x438438 | 0x381a8 | 0x2f5a8 | 0x0 |
GetThreadLocale | 0x0 | 0x43843c | 0x381ac | 0x2f5ac | 0x0 |
GetStartupInfoA | 0x0 | 0x438440 | 0x381b0 | 0x2f5b0 | 0x0 |
GetProcAddress | 0x0 | 0x438444 | 0x381b4 | 0x2f5b4 | 0x0 |
GetModuleHandleA | 0x0 | 0x438448 | 0x381b8 | 0x2f5b8 | 0x0 |
GetModuleFileNameA | 0x0 | 0x43844c | 0x381bc | 0x2f5bc | 0x0 |
GetLocaleInfoA | 0x0 | 0x438450 | 0x381c0 | 0x2f5c0 | 0x0 |
GetCommandLineA | 0x0 | 0x438454 | 0x381c4 | 0x2f5c4 | 0x0 |
FreeLibrary | 0x0 | 0x438458 | 0x381c8 | 0x2f5c8 | 0x0 |
FindFirstFileA | 0x0 | 0x43845c | 0x381cc | 0x2f5cc | 0x0 |
FindClose | 0x0 | 0x438460 | 0x381d0 | 0x2f5d0 | 0x0 |
ExitProcess | 0x0 | 0x438464 | 0x381d4 | 0x2f5d4 | 0x0 |
CreateThread | 0x0 | 0x438468 | 0x381d8 | 0x2f5d8 | 0x0 |
WriteFile | 0x0 | 0x43846c | 0x381dc | 0x2f5dc | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x438470 | 0x381e0 | 0x2f5e0 | 0x0 |
RtlUnwind | 0x0 | 0x438474 | 0x381e4 | 0x2f5e4 | 0x0 |
RaiseException | 0x0 | 0x438478 | 0x381e8 | 0x2f5e8 | 0x0 |
GetStdHandle | 0x0 | 0x43847c | 0x381ec | 0x2f5ec | 0x0 |
kernel32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TlsSetValue | 0x0 | 0x438484 | 0x381f4 | 0x2f5f4 | 0x0 |
TlsGetValue | 0x0 | 0x438488 | 0x381f8 | 0x2f5f8 | 0x0 |
LocalAlloc | 0x0 | 0x43848c | 0x381fc | 0x2f5fc | 0x0 |
GetModuleHandleA | 0x0 | 0x438490 | 0x38200 | 0x2f600 | 0x0 |
user32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TranslateMessage | 0x0 | 0x438498 | 0x38208 | 0x2f608 | 0x0 |
SystemParametersInfoW | 0x0 | 0x43849c | 0x3820c | 0x2f60c | 0x0 |
PeekMessageA | 0x0 | 0x4384a0 | 0x38210 | 0x2f610 | 0x0 |
MessageBoxA | 0x0 | 0x4384a4 | 0x38214 | 0x2f614 | 0x0 |
LoadStringA | 0x0 | 0x4384a8 | 0x38218 | 0x2f618 | 0x0 |
GetSystemMetrics | 0x0 | 0x4384ac | 0x3821c | 0x2f61c | 0x0 |
GetLastInputInfo | 0x0 | 0x4384b0 | 0x38220 | 0x2f620 | 0x0 |
DispatchMessageA | 0x0 | 0x4384b4 | 0x38224 | 0x2f624 | 0x0 |
CharNextW | 0x0 | 0x4384b8 | 0x38228 | 0x2f628 | 0x0 |
CharLowerBuffW | 0x0 | 0x4384bc | 0x3822c | 0x2f62c | 0x0 |
CharNextA | 0x0 | 0x4384c0 | 0x38230 | 0x2f630 | 0x0 |
CharLowerBuffA | 0x0 | 0x4384c4 | 0x38234 | 0x2f634 | 0x0 |
CharUpperBuffA | 0x0 | 0x4384c8 | 0x38238 | 0x2f638 | 0x0 |
CharToOemA | 0x0 | 0x4384cc | 0x3823c | 0x2f63c | 0x0 |
mpr.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetOpenEnumA | 0x0 | 0x4384d4 | 0x38244 | 0x2f644 | 0x0 |
WNetEnumResourceA | 0x0 | 0x4384d8 | 0x38248 | 0x2f648 | 0x0 |
WNetCloseEnum | 0x0 | 0x4384dc | 0x3824c | 0x2f64c | 0x0 |
kernel32.dll (61)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteFile | 0x0 | 0x4384e4 | 0x38254 | 0x2f654 | 0x0 |
WinExec | 0x0 | 0x4384e8 | 0x38258 | 0x2f658 | 0x0 |
WaitForSingleObject | 0x0 | 0x4384ec | 0x3825c | 0x2f65c | 0x0 |
VirtualQuery | 0x0 | 0x4384f0 | 0x38260 | 0x2f660 | 0x0 |
TerminateProcess | 0x0 | 0x4384f4 | 0x38264 | 0x2f664 | 0x0 |
SizeofResource | 0x0 | 0x4384f8 | 0x38268 | 0x2f668 | 0x0 |
SetFileTime | 0x0 | 0x4384fc | 0x3826c | 0x2f66c | 0x0 |
SetFilePointer | 0x0 | 0x438500 | 0x38270 | 0x2f670 | 0x0 |
SetFileAttributesW | 0x0 | 0x438504 | 0x38274 | 0x2f674 | 0x0 |
SetEndOfFile | 0x0 | 0x438508 | 0x38278 | 0x2f678 | 0x0 |
ReadFile | 0x0 | 0x43850c | 0x3827c | 0x2f67c | 0x0 |
OpenProcess | 0x0 | 0x438510 | 0x38280 | 0x2f680 | 0x0 |
OpenMutexA | 0x0 | 0x438514 | 0x38284 | 0x2f684 | 0x0 |
MoveFileW | 0x0 | 0x438518 | 0x38288 | 0x2f688 | 0x0 |
LockResource | 0x0 | 0x43851c | 0x3828c | 0x2f68c | 0x0 |
LoadResource | 0x0 | 0x438520 | 0x38290 | 0x2f690 | 0x0 |
LoadLibraryA | 0x0 | 0x438524 | 0x38294 | 0x2f694 | 0x0 |
LeaveCriticalSection | 0x0 | 0x438528 | 0x38298 | 0x2f698 | 0x0 |
InitializeCriticalSection | 0x0 | 0x43852c | 0x3829c | 0x2f69c | 0x0 |
GlobalUnlock | 0x0 | 0x438530 | 0x382a0 | 0x2f6a0 | 0x0 |
GlobalReAlloc | 0x0 | 0x438534 | 0x382a4 | 0x2f6a4 | 0x0 |
GlobalHandle | 0x0 | 0x438538 | 0x382a8 | 0x2f6a8 | 0x0 |
GlobalLock | 0x0 | 0x43853c | 0x382ac | 0x2f6ac | 0x0 |
GlobalFree | 0x0 | 0x438540 | 0x382b0 | 0x2f6b0 | 0x0 |
GlobalAlloc | 0x0 | 0x438544 | 0x382b4 | 0x2f6b4 | 0x0 |
GetVersionExA | 0x0 | 0x438548 | 0x382b8 | 0x2f6b8 | 0x0 |
GetTickCount | 0x0 | 0x43854c | 0x382bc | 0x2f6bc | 0x0 |
GetThreadLocale | 0x0 | 0x438550 | 0x382c0 | 0x2f6c0 | 0x0 |
GetStdHandle | 0x0 | 0x438554 | 0x382c4 | 0x2f6c4 | 0x0 |
GetProcAddress | 0x0 | 0x438558 | 0x382c8 | 0x2f6c8 | 0x0 |
GetModuleHandleA | 0x0 | 0x43855c | 0x382cc | 0x2f6cc | 0x0 |
GetModuleFileNameW | 0x0 | 0x438560 | 0x382d0 | 0x2f6d0 | 0x0 |
GetModuleFileNameA | 0x0 | 0x438564 | 0x382d4 | 0x2f6d4 | 0x0 |
GetLocaleInfoA | 0x0 | 0x438568 | 0x382d8 | 0x2f6d8 | 0x0 |
GetLocalTime | 0x0 | 0x43856c | 0x382dc | 0x2f6dc | 0x0 |
GetLastError | 0x0 | 0x438570 | 0x382e0 | 0x2f6e0 | 0x0 |
GetFileAttributesA | 0x0 | 0x438574 | 0x382e4 | 0x2f6e4 | 0x0 |
GetEnvironmentVariableA | 0x0 | 0x438578 | 0x382e8 | 0x2f6e8 | 0x0 |
GetDiskFreeSpaceA | 0x0 | 0x43857c | 0x382ec | 0x2f6ec | 0x0 |
GetDateFormatA | 0x0 | 0x438580 | 0x382f0 | 0x2f6f0 | 0x0 |
GetCommandLineW | 0x0 | 0x438584 | 0x382f4 | 0x2f6f4 | 0x0 |
GetCPInfo | 0x0 | 0x438588 | 0x382f8 | 0x2f6f8 | 0x0 |
FreeResource | 0x0 | 0x43858c | 0x382fc | 0x2f6fc | 0x0 |
FreeLibrary | 0x0 | 0x438590 | 0x38300 | 0x2f700 | 0x0 |
FormatMessageA | 0x0 | 0x438594 | 0x38304 | 0x2f704 | 0x0 |
FindResourceA | 0x0 | 0x438598 | 0x38308 | 0x2f708 | 0x0 |
FindNextFileW | 0x0 | 0x43859c | 0x3830c | 0x2f70c | 0x0 |
FindFirstFileW | 0x0 | 0x4385a0 | 0x38310 | 0x2f710 | 0x0 |
FindClose | 0x0 | 0x4385a4 | 0x38314 | 0x2f714 | 0x0 |
FileTimeToLocalFileTime | 0x0 | 0x4385a8 | 0x38318 | 0x2f718 | 0x0 |
FileTimeToDosDateTime | 0x0 | 0x4385ac | 0x3831c | 0x2f71c | 0x0 |
ExitProcess | 0x0 | 0x4385b0 | 0x38320 | 0x2f720 | 0x0 |
EnumCalendarInfoA | 0x0 | 0x4385b4 | 0x38324 | 0x2f724 | 0x0 |
EnterCriticalSection | 0x0 | 0x4385b8 | 0x38328 | 0x2f728 | 0x0 |
DeleteFileW | 0x0 | 0x4385bc | 0x3832c | 0x2f72c | 0x0 |
DeleteCriticalSection | 0x0 | 0x4385c0 | 0x38330 | 0x2f730 | 0x0 |
CreateProcessW | 0x0 | 0x4385c4 | 0x38334 | 0x2f734 | 0x0 |
CreateMutexA | 0x0 | 0x4385c8 | 0x38338 | 0x2f738 | 0x0 |
CreateFileW | 0x0 | 0x4385cc | 0x3833c | 0x2f73c | 0x0 |
CompareStringA | 0x0 | 0x4385d0 | 0x38340 | 0x2f740 | 0x0 |
CloseHandle | 0x0 | 0x4385d4 | 0x38344 | 0x2f744 | 0x0 |
advapi32.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegSetValueExA | 0x0 | 0x4385dc | 0x3834c | 0x2f74c | 0x0 |
RegQueryValueExA | 0x0 | 0x4385e0 | 0x38350 | 0x2f750 | 0x0 |
RegOpenKeyExA | 0x0 | 0x4385e4 | 0x38354 | 0x2f754 | 0x0 |
RegEnumValueA | 0x0 | 0x4385e8 | 0x38358 | 0x2f758 | 0x0 |
RegEnumKeyExA | 0x0 | 0x4385ec | 0x3835c | 0x2f75c | 0x0 |
RegDeleteValueA | 0x0 | 0x4385f0 | 0x38360 | 0x2f760 | 0x0 |
RegDeleteKeyA | 0x0 | 0x4385f4 | 0x38364 | 0x2f764 | 0x0 |
RegCreateKeyExA | 0x0 | 0x4385f8 | 0x38368 | 0x2f768 | 0x0 |
RegCloseKey | 0x0 | 0x4385fc | 0x3836c | 0x2f76c | 0x0 |
kernel32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x438604 | 0x38374 | 0x2f774 | 0x0 |
wininet.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InternetReadFile | 0x0 | 0x43860c | 0x3837c | 0x2f77c | 0x0 |
InternetOpenUrlA | 0x0 | 0x438610 | 0x38380 | 0x2f780 | 0x0 |
InternetOpenA | 0x0 | 0x438614 | 0x38384 | 0x2f784 | 0x0 |
InternetCloseHandle | 0x0 | 0x438618 | 0x38388 | 0x2f788 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x438620 | 0x38390 | 0x2f790 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderLocation | 0x0 | 0x438628 | 0x38398 | 0x2f798 | 0x0 |
shell32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetPathFromIDListW | 0x0 | 0x438630 | 0x383a0 | 0x2f7a0 | 0x0 |
SHGetMalloc | 0x0 | 0x438634 | 0x383a4 | 0x2f7a4 | 0x0 |
oleaut32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SafeArrayPtrOfIndex | 0x0 | 0x43863c | 0x383ac | 0x2f7ac | 0x0 |
SafeArrayGetUBound | 0x0 | 0x438640 | 0x383b0 | 0x2f7b0 | 0x0 |
SafeArrayGetLBound | 0x0 | 0x438644 | 0x383b4 | 0x2f7b4 | 0x0 |
SafeArrayCreate | 0x0 | 0x438648 | 0x383b8 | 0x2f7b8 | 0x0 |
VariantChangeType | 0x0 | 0x43864c | 0x383bc | 0x2f7bc | 0x0 |
VariantCopy | 0x0 | 0x438650 | 0x383c0 | 0x2f7c0 | 0x0 |
VariantClear | 0x0 | 0x438654 | 0x383c4 | 0x2f7c4 | 0x0 |
VariantInit | 0x0 | 0x438658 | 0x383c8 | 0x2f7c8 | 0x0 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
mqrywk.exe | 1 | 0x00400000 | 0x0043CFFF | Relevant Image |
![]() |
32-bit | 0x00404238 |
![]() |
![]() |
...
|
mqrywk.exe | 1 | 0x00400000 | 0x0043CFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
mqrywk.exe | 3 | 0x00400000 | 0x0043CFFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
mqrywk.exe | 3 | 0x00400000 | 0x0043CFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
DeepScan:Generic.Ransom.Amnesia.8395E6F2 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\winupmgr.exe | Dropped File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Suspicious
|
Names | App/Generic-HP |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40b134 |
Size Of Code | 0x9c00 |
Size Of Initialized Data | 0x3200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-11-24 10:56:32+00:00 |
Sections (9)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x97d4 | 0x9800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.57 |
.itext | 0x40b000 | 0x294 | 0x400 | 0x9c00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.8 |
.data | 0x40c000 | 0xaf4 | 0xc00 | 0xa000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.05 |
.bss | 0x40d000 | 0x4930 | 0x0 | 0xac00 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x412000 | 0x9d2 | 0xa00 | 0xac00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.84 |
.tls | 0x413000 | 0x8 | 0x0 | 0xb600 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x414000 | 0x18 | 0x200 | 0xb600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.21 |
.reloc | 0x415000 | 0xc50 | 0xe00 | 0xb800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.21 |
.rsrc | 0x416000 | 0xc00 | 0xc00 | 0xc600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.63 |
Imports (10)
»
oleaut32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x412258 | 0x120dc | 0xacdc | 0x0 |
SysReAllocStringLen | 0x0 | 0x41225c | 0x120e0 | 0xace0 | 0x0 |
SysAllocStringLen | 0x0 | 0x412260 | 0x120e4 | 0xace4 | 0x0 |
advapi32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExA | 0x0 | 0x412268 | 0x120ec | 0xacec | 0x0 |
RegOpenKeyExA | 0x0 | 0x41226c | 0x120f0 | 0xacf0 | 0x0 |
RegCloseKey | 0x0 | 0x412270 | 0x120f4 | 0xacf4 | 0x0 |
user32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetKeyboardType | 0x0 | 0x412278 | 0x120fc | 0xacfc | 0x0 |
DestroyWindow | 0x0 | 0x41227c | 0x12100 | 0xad00 | 0x0 |
LoadStringA | 0x0 | 0x412280 | 0x12104 | 0xad04 | 0x0 |
MessageBoxA | 0x0 | 0x412284 | 0x12108 | 0xad08 | 0x0 |
CharNextA | 0x0 | 0x412288 | 0x1210c | 0xad0c | 0x0 |
kernel32.dll (27)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetACP | 0x0 | 0x412290 | 0x12114 | 0xad14 | 0x0 |
Sleep | 0x0 | 0x412294 | 0x12118 | 0xad18 | 0x0 |
VirtualFree | 0x0 | 0x412298 | 0x1211c | 0xad1c | 0x0 |
VirtualAlloc | 0x0 | 0x41229c | 0x12120 | 0xad20 | 0x0 |
GetCurrentThreadId | 0x0 | 0x4122a0 | 0x12124 | 0xad24 | 0x0 |
VirtualQuery | 0x0 | 0x4122a4 | 0x12128 | 0xad28 | 0x0 |
WideCharToMultiByte | 0x0 | 0x4122a8 | 0x1212c | 0xad2c | 0x0 |
MultiByteToWideChar | 0x0 | 0x4122ac | 0x12130 | 0xad30 | 0x0 |
lstrlenA | 0x0 | 0x4122b0 | 0x12134 | 0xad34 | 0x0 |
lstrcpynA | 0x0 | 0x4122b4 | 0x12138 | 0xad38 | 0x0 |
LoadLibraryExA | 0x0 | 0x4122b8 | 0x1213c | 0xad3c | 0x0 |
GetThreadLocale | 0x0 | 0x4122bc | 0x12140 | 0xad40 | 0x0 |
GetStartupInfoA | 0x0 | 0x4122c0 | 0x12144 | 0xad44 | 0x0 |
GetProcAddress | 0x0 | 0x4122c4 | 0x12148 | 0xad48 | 0x0 |
GetModuleHandleA | 0x0 | 0x4122c8 | 0x1214c | 0xad4c | 0x0 |
GetModuleFileNameA | 0x0 | 0x4122cc | 0x12150 | 0xad50 | 0x0 |
GetLocaleInfoA | 0x0 | 0x4122d0 | 0x12154 | 0xad54 | 0x0 |
GetCommandLineA | 0x0 | 0x4122d4 | 0x12158 | 0xad58 | 0x0 |
FreeLibrary | 0x0 | 0x4122d8 | 0x1215c | 0xad5c | 0x0 |
FindFirstFileA | 0x0 | 0x4122dc | 0x12160 | 0xad60 | 0x0 |
FindClose | 0x0 | 0x4122e0 | 0x12164 | 0xad64 | 0x0 |
ExitProcess | 0x0 | 0x4122e4 | 0x12168 | 0xad68 | 0x0 |
WriteFile | 0x0 | 0x4122e8 | 0x1216c | 0xad6c | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x4122ec | 0x12170 | 0xad70 | 0x0 |
RtlUnwind | 0x0 | 0x4122f0 | 0x12174 | 0xad74 | 0x0 |
RaiseException | 0x0 | 0x4122f4 | 0x12178 | 0xad78 | 0x0 |
GetStdHandle | 0x0 | 0x4122f8 | 0x1217c | 0xad7c | 0x0 |
kernel32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TlsSetValue | 0x0 | 0x412300 | 0x12184 | 0xad84 | 0x0 |
TlsGetValue | 0x0 | 0x412304 | 0x12188 | 0xad88 | 0x0 |
LocalAlloc | 0x0 | 0x412308 | 0x1218c | 0xad8c | 0x0 |
GetModuleHandleA | 0x0 | 0x41230c | 0x12190 | 0xad90 | 0x0 |
user32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetClipboardData | 0x0 | 0x412314 | 0x12198 | 0xad98 | 0x0 |
OpenClipboard | 0x0 | 0x412318 | 0x1219c | 0xad9c | 0x0 |
MessageBoxA | 0x0 | 0x41231c | 0x121a0 | 0xada0 | 0x0 |
LoadStringA | 0x0 | 0x412320 | 0x121a4 | 0xada4 | 0x0 |
GetSystemMetrics | 0x0 | 0x412324 | 0x121a8 | 0xada8 | 0x0 |
GetOpenClipboardWindow | 0x0 | 0x412328 | 0x121ac | 0xadac | 0x0 |
GetClipboardData | 0x0 | 0x41232c | 0x121b0 | 0xadb0 | 0x0 |
CloseClipboard | 0x0 | 0x412330 | 0x121b4 | 0xadb4 | 0x0 |
CharNextA | 0x0 | 0x412334 | 0x121b8 | 0xadb8 | 0x0 |
CharUpperBuffA | 0x0 | 0x412338 | 0x121bc | 0xadbc | 0x0 |
CharToOemA | 0x0 | 0x41233c | 0x121c0 | 0xadc0 | 0x0 |
kernel32.dll (27)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteFile | 0x0 | 0x412344 | 0x121c8 | 0xadc8 | 0x0 |
WinExec | 0x0 | 0x412348 | 0x121cc | 0xadcc | 0x0 |
VirtualQuery | 0x0 | 0x41234c | 0x121d0 | 0xadd0 | 0x0 |
GlobalUnlock | 0x0 | 0x412350 | 0x121d4 | 0xadd4 | 0x0 |
GlobalSize | 0x0 | 0x412354 | 0x121d8 | 0xadd8 | 0x0 |
GlobalLock | 0x0 | 0x412358 | 0x121dc | 0xaddc | 0x0 |
GlobalFree | 0x0 | 0x41235c | 0x121e0 | 0xade0 | 0x0 |
GlobalAlloc | 0x0 | 0x412360 | 0x121e4 | 0xade4 | 0x0 |
GetVersionExA | 0x0 | 0x412364 | 0x121e8 | 0xade8 | 0x0 |
GetThreadLocale | 0x0 | 0x412368 | 0x121ec | 0xadec | 0x0 |
GetStdHandle | 0x0 | 0x41236c | 0x121f0 | 0xadf0 | 0x0 |
GetProcAddress | 0x0 | 0x412370 | 0x121f4 | 0xadf4 | 0x0 |
GetModuleHandleA | 0x0 | 0x412374 | 0x121f8 | 0xadf8 | 0x0 |
GetModuleFileNameA | 0x0 | 0x412378 | 0x121fc | 0xadfc | 0x0 |
GetLocaleInfoA | 0x0 | 0x41237c | 0x12200 | 0xae00 | 0x0 |
GetLastError | 0x0 | 0x412380 | 0x12204 | 0xae04 | 0x0 |
GetFileAttributesA | 0x0 | 0x412384 | 0x12208 | 0xae08 | 0x0 |
GetEnvironmentVariableA | 0x0 | 0x412388 | 0x1220c | 0xae0c | 0x0 |
GetDiskFreeSpaceA | 0x0 | 0x41238c | 0x12210 | 0xae10 | 0x0 |
GetCPInfo | 0x0 | 0x412390 | 0x12214 | 0xae14 | 0x0 |
FreeLibrary | 0x0 | 0x412394 | 0x12218 | 0xae18 | 0x0 |
ExitProcess | 0x0 | 0x412398 | 0x1221c | 0xae1c | 0x0 |
EnumCalendarInfoA | 0x0 | 0x41239c | 0x12220 | 0xae20 | 0x0 |
DeleteFileA | 0x0 | 0x4123a0 | 0x12224 | 0xae24 | 0x0 |
CreateMutexA | 0x0 | 0x4123a4 | 0x12228 | 0xae28 | 0x0 |
CopyFileA | 0x0 | 0x4123a8 | 0x1222c | 0xae2c | 0x0 |
CompareStringA | 0x0 | 0x4123ac | 0x12230 | 0xae30 | 0x0 |
advapi32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegSetValueExA | 0x0 | 0x4123b4 | 0x12238 | 0xae38 | 0x0 |
RegCreateKeyExA | 0x0 | 0x4123b8 | 0x1223c | 0xae3c | 0x0 |
RegCloseKey | 0x0 | 0x4123bc | 0x12240 | 0xae40 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x4123c4 | 0x12248 | 0xae48 | 0x0 |
kernel32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x4123cc | 0x12250 | 0xae50 | 0x0 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
winupmgr.exe | 17 | 0x00400000 | 0x00416FFF | Relevant Image |
![]() |
32-bit | 0x00403EDC |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.31382075 |
Malicious
|
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\1033\я | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-05-31 22:44 (UTC+2) |
Last Seen | 2020-01-21 14:22 (UTC+1) |
File Reputation Information
»
Severity |
Whitelisted
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF.moncrypt | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
PE Information
»
Image Base | 0x180000000 |
Size Of Initialized Data | 0x417800 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 2011-03-17 00:02:47+00:00 |
Version Information (10)
»
CompanyName | Microsoft Corporation |
FileDescription | Microsoft Office culture data dll |
FileVersion | 14.0.6024.1000 |
InternalName | Oleo Data File |
LegalCopyright | © 2010 Microsoft Corporation. All rights reserved. |
LegalTrademarks1 | Microsoft® is a registered trademark of Microsoft Corporation. |
LegalTrademarks2 | Windows® is a registered trademark of Microsoft Corporation. |
OriginalFilename | office.odf |
ProductName | Microsoft Office 2010 |
ProductVersion | 14.0.6024.1000 |
Sections (2)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.rdata | 0x180001000 | 0x85 | 0x200 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.65 |
.rsrc | 0x180002000 | 0x4174c0 | 0x417600 | 0x600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.69 |
Digital Signatures (2)
»
Certificate: Microsoft Corporation
»
Issued by | Microsoft Corporation |
Parent Certificate | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2011-02-21 20:53:12+00:00 |
Valid Until | 2012-05-21 20:53:12+00:00 |
Algorithm | sha1_rsa |
Serial Number | 61 01 B2 9B 00 00 00 00 00 15 |
Thumbprint | 93 85 9E BF 98 AF DE B4 88 CC FA 26 38 99 64 0E 81 BC 49 F1 |
Certificate: Microsoft Code Signing PCA
»
Issued by | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2007-08-22 22:31:02+00:00 |
Valid Until | 2012-08-25 07:00:00+00:00 |
Algorithm | sha1_rsa |
Serial Number | 2E AB 11 DC 50 FF 5C 9D CB C0 |
Thumbprint | 30 36 E3 B2 5B 88 A5 5B 86 FC 90 E6 E9 EA AD 50 81 44 51 66 |
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.CNT.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.FLT.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.FNT.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\GIFIMP32.FLT.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\JPEGIM32.FLT.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.CGM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.WPG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\pkeyconfig-office.xrm-ms.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\SETUP.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\ProPlusrWW.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\SETUP.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPWMI.MOF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_FR.LEX.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\BASMLA.XSL.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.DAT.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TextConv\Wks9Pxy.cnv.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TextConv\WPFT532.CNV.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TextConv\WPFT632.CNV.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\AFTRNOON.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\ARCTIC.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\BLUECALM.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\BLUEPRNT.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\BOLDSTRI.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\BREEZE.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\COMPASS.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\ECHO.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\ECLIPSE.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\EVRGREEN.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\EXPEDITN.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\ICE.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\INDUST.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\JOURNAL.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\LEVEL.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\NETWORK.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\PAPYRUS.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PIXEL\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\QUAD\QUAD.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\QUAD\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\REFINED.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RICEPAPR\RICEPAPR.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RICEPAPR\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RIPPLE\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RMNSQUE\RMNSQUE.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RMNSQUE\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SATIN\SATIN.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SKY\SKY.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SKY\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SLATE\SLATE.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\STRTEDGE\STRTEDGE.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\STUDIO\STUDIO.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\STUDIO\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SUMIPNTG\SUMIPNTG.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SUMIPNTG\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATER\WATER.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATERMAR\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATERMAR\WATERMAR.ELM.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\MSB1AR.LEX.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ARFR\MSB1ARFR.ITS.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ENFR\MSB1ENFR.ITS.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ESEN\WT61ES.LEX.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FREN\MSB1FREN.ITS.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\GBCBIG.SHX.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\IC-TXT.SHX.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\WHGTXT.SHX.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\WHTGTXT.SHX.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\WHTMTXT.SHX.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\as80.xsl.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\as90.xsl.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\sql2000.xsl.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\sql70.xsl.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\sql90.xsl.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\Sybase.xsl.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.es\HOW TO RECOVER ENCRYPTED FILES.TXT | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN00015_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN00853_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN00914_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01039_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01060_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01084_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01173_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01184_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01545_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN02559_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04117_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04134_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04191_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04195_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04206_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04235_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04267_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04269_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04323_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04355_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04369_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04384_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BABY_01.MID.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD00116_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD00141_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD00146_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD00155_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD00160_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD05119_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD07804_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD07831_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUI.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUISet.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\SETUP.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\SETUP.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\InfoPathMUI.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\SETUP.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUI.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\Office32MUI.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\SETUP.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\OneNoteMUI.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\OutlookMUI.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\PowerPointMUI.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\PrjProrWW.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\ProjectMUI.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\SETUP.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.en\Proof.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.es\Proof.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.fr\Proof.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\SETUP.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\SETUP.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\SETUP.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\VisioMUI.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\VisiorWW.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\WordMUI.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\STINTL.DLL.IDX_DLL.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\PHONE.XML.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01044_.WMF.moncrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.HLP.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\EPSIMP32.FLT.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\PICTIM32.FLT.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\PNG32.FLT.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\WPGIMP32.FLT.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\MSOINTL.DLL.IDX_DLL.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\MSOINTL.REST.IDX_DLL.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\BRANDING.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\SETUP.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_EN.LEX.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_ES.LEX.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TextConv\RECOVR32.CNV.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\AXIS.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\BLENDS.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\CANYON.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\CAPSULES.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\CASCADE.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\CONCRETE.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\DEEPBLUE.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\EDGE.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\IRIS.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\LAYERS.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PIXEL\PIXEL.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\PROFILE.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RADIAL\RADIAL.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RADIAL\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RIPPLE\RIPPLE.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SATIN\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SLATE\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SONORA\SONORA.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SONORA\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SPRING\SPRING.ELM.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SPRING\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\STRTEDGE\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATER\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\MSB1CACH.LEX.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ENES\MSB1ENES.ITS.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ESEN\MSB1ESEN.ITS.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FRAR\MSB1FRAR.ITS.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FREN\WT61FR.LEX.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\BIGFONT.SHX.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\CHINESET.SHX.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\EXTFONT.SHX.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\ICAD.FMP.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Visio Shared\Fonts\WHGDTXT.SHX.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\VSTO\vstoee100.tlb.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\VSTO\vstoee90.tlb.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\1033\FPEXT.MSG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\Informix.xsl.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\msjet.xsl.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Resources\1033\msmdsrv.rll.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN00790_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN00932_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN00965_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01174_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01216_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01218_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN02122_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN02724_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN03500_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04108_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04174_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04196_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04225_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04326_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04332_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04385_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD00173_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD06102_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD06200_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD07761_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\ExcelMUI.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\GrooveMUI.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\SETUP.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUISet.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.WW\Office32WW.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\SETUP.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\SETUP.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\SETUP.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\Proofing.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\PublisherMUI.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\SETUP.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppobjs-spp-plugin-manifest-signed.xrm-ms.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\MSTAG.TLB.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\DATES.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\TIME.XML.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\THMBNAIL.PNG.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Internet Explorer\SIGNUP\install.ins.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Resources\1033\msolui100.rll.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN00010_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01251_.WMF.moncrypt | Dropped File | Stream |
Not Queried
|
...
|
»