VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
|
Threat Names: |
Gen:Trojan.Heur.FU.fvZ@aS6OnCp
Gen:Variant.Ser.Mikey.2053
|
Launchy.exe
Windows Exe (x86-32)
Created at 2020-06-02T00:20:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4904c0 |
Size Of Code | 0x90200 |
Size Of Initialized Data | 0x82800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-05-29 19:12:51+00:00 |
Version Information (8)
»
CompanyName | Code Jelly |
FileDescription | Launchy |
FileVersion | 1.0.0 |
InternalName | Launchy.exe |
LegalCopyright | This is GNU Software copyright Josh Karlin |
OriginalFilename | Launchy.exe |
ProductName | Launchy |
ProductVersion | 2.0 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x9000f | 0x90200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 1.37 |
.rdata | 0x492000 | 0x7a120 | 0x7a200 | 0x90600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.01 |
.data | 0x50d000 | 0x6a4 | 0x800 | 0x10a800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.37 |
.rsrc | 0x50e000 | 0x7d58 | 0x7e00 | 0x10b000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.07 |
Imports (5)
»
KERNEL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x50d464 | 0x10d404 | 0x10ac04 | 0x2f1 |
GetProcAddress | 0x0 | 0x50d468 | 0x10d408 | 0x10ac08 | 0x220 |
GetLastError | 0x0 | 0x50d46c | 0x10d40c | 0x10ac0c | 0x1e6 |
GetModuleHandleA | 0x0 | 0x50d470 | 0x10d410 | 0x10ac10 | 0x1f6 |
USER32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadIconA | 0x0 | 0x50d478 | 0x10d418 | 0x10ac18 | 0x1d6 |
LoadCursorW | 0x0 | 0x50d47c | 0x10d41c | 0x10ac1c | 0x1d5 |
GetKeyState | 0x0 | 0x50d480 | 0x10d420 | 0x10ac20 | 0x131 |
GetListBoxInfo | 0x0 | 0x50d484 | 0x10d424 | 0x10ac24 | 0x13b |
GDI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetStockObject | 0x0 | 0x50d48c | 0x10d42c | 0x10ac2c | 0x1f4 |
GetEnhMetaFileW | 0x0 | 0x50d490 | 0x10d430 | 0x10ac30 | 0x1c1 |
GetStretchBltMode | 0x0 | 0x50d494 | 0x10d434 | 0x10ac34 | 0x1f5 |
ADVAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetUserNameA | 0x0 | 0x50d49c | 0x10d43c | 0x10ac3c | 0x15e |
RegOpenKeyA | 0x0 | 0x50d4a0 | 0x10d440 | 0x10ac40 | 0x259 |
SHELL32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetPathFromIDListA | 0x0 | 0x50d4a8 | 0x10d448 | 0x10ac48 | 0xcf |
SHBrowseForFolderA | 0x0 | 0x50d4ac | 0x10d44c | 0x10ac4c | 0x77 |
SHGetFileInfoA | 0x0 | 0x50d4b0 | 0x10d450 | 0x10ac50 | 0xb9 |
ShellExecuteA | 0x0 | 0x50d4b4 | 0x10d454 | 0x10ac54 | 0x114 |
SHFileOperationA | 0x0 | 0x50d4b8 | 0x10d458 | 0x10ac58 | 0xa8 |
SHGetSpecialFolderLocation | 0x0 | 0x50d4bc | 0x10d45c | 0x10ac5c | 0xd8 |
Digital Signatures (1)
»
Certificate: SCSTXPBIMRJPFWKHAA
»
Issued by | SCSTXPBIMRJPFWKHAA |
Country Name | - |
Valid From | 2020-05-23 19:51:28+00:00 |
Valid Until | 2039-12-31 23:59:59+00:00 |
Algorithm | sha1_rsa |
Serial Number | 36 5F 7C AB E7 8B E8 BD 47 FF 30 C6 A9 36 29 51 |
Thumbprint | 1D 65 05 7D D1 1C F6 21 8F B9 A4 25 B6 AC 31 E3 C5 8D D5 08 |
Memory Dumps (19)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
launchy.exe | 1 | 0x00400000 | 0x00515FFF | Relevant Image |
![]() |
32-bit | 0x0049037D |
![]() |
![]() |
...
|
buffer | 1 | 0x001D0000 | 0x001DFFFF | First Execution |
![]() |
32-bit | 0x001DEFC0 |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00515FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00515FFF | Content Changed |
![]() |
32-bit | 0x004016FC |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00515FFF | Content Changed |
![]() |
32-bit | 0x0040861C |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00515FFF | Content Changed |
![]() |
32-bit | 0x00405C3A |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00515FFF | Content Changed |
![]() |
32-bit | 0x00402001 |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00515FFF | Content Changed |
![]() |
32-bit | 0x004069D4 |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00515FFF | Content Changed |
![]() |
32-bit | 0x00404C4A |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00515FFF | Content Changed |
![]() |
32-bit | 0x004064BB |
![]() |
![]() |
...
|
still:bin | 2 | 0x00400000 | 0x00515FFF | Relevant Image |
![]() |
32-bit | 0x0049037D |
![]() |
![]() |
...
|
buffer | 2 | 0x001D0000 | 0x001DFFFF | First Execution |
![]() |
32-bit | 0x001DEFC0 |
![]() |
![]() |
...
|
still.exe | 31 | 0x00400000 | 0x00515FFF | Relevant Image |
![]() |
32-bit | 0x00491009 |
![]() |
![]() |
...
|
buffer | 31 | 0x001D0000 | 0x001DFFFF | First Execution |
![]() |
32-bit | 0x001DEFC0 |
![]() |
![]() |
...
|
buffer | 31 | 0x001E0000 | 0x001EEFFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 2 | 0x001E0000 | 0x001EEFFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00515FFF | Content Changed |
![]() |
32-bit | 0x00404F47 |
![]() |
![]() |
...
|
buffer | 1 | 0x001E0000 | 0x001EEFFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
launchy.exe | 1 | 0x00400000 | 0x00515FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
\\?\C:\Users\FD1HVy\Documents\4fN5SD.pdf.bbawasted | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\FD1HVy\AppData\Roaming\Still | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
PE Information
»
Image Base | 0x30000000 |
Entry Point | 0x30002bd0 |
Size Of Code | 0x8c00 |
Size Of Initialized Data | 0x1e00 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2068-04-04 07:41:10+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Windows Remote Desktop Session Host Server SDK APIs |
FileVersion | 10.0.15063.0 (WinBuild.160101.0800) |
InternalName | wtsapi32.dll |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | wtsapi32.dll |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.15063.0 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x30001000 | 0x8a8e | 0x8c00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.28 |
.data | 0x3000a000 | 0x368 | 0x200 | 0x9000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.23 |
.idata | 0x3000b000 | 0x864 | 0xa00 | 0x9200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.33 |
.didat | 0x3000c000 | 0x104 | 0x200 | 0x9c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.3 |
.rsrc | 0x3000d000 | 0x440 | 0x600 | 0x9e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.55 |
.reloc | 0x3000e000 | 0x6d8 | 0x800 | 0xa400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.13 |
Imports (14)
»
msvcrt.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
memcpy_s | 0x0 | 0x3000b0ac | 0xb2d8 | 0x94d8 | 0x50a |
free | 0x0 | 0x3000b0b0 | 0xb2dc | 0x94dc | 0x4c5 |
malloc | 0x0 | 0x3000b0b4 | 0xb2e0 | 0x94e0 | 0x4fd |
_initterm | 0x0 | 0x3000b0b8 | 0xb2e4 | 0x94e4 | 0x1e8 |
_except_handler4_common | 0x0 | 0x3000b0bc | 0xb2e8 | 0x94e8 | 0x16a |
_amsg_exit | 0x0 | 0x3000b0c0 | 0xb2ec | 0x94ec | 0x111 |
memcpy | 0x0 | 0x3000b0c4 | 0xb2f0 | 0x94f0 | 0x509 |
_XcptFilter | 0x0 | 0x3000b0c8 | 0xb2f4 | 0x94f4 | 0x6f |
_wcsupr | 0x0 | 0x3000b0cc | 0xb2f8 | 0x94f8 | 0x429 |
swscanf | 0x0 | 0x3000b0d0 | 0xb2fc | 0x94fc | 0x54e |
memset | 0x0 | 0x3000b0d4 | 0xb300 | 0x9500 | 0x50d |
api-ms-win-core-errorhandling-l1-1-1.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetLastError | 0x0 | 0x3000b00c | 0xb238 | 0x9438 | 0xd |
UnhandledExceptionFilter | 0x0 | 0x3000b010 | 0xb23c | 0x943c | 0x11 |
SetUnhandledExceptionFilter | 0x0 | 0x3000b014 | 0xb240 | 0x9440 | 0xf |
GetLastError | 0x0 | 0x3000b018 | 0xb244 | 0x9444 | 0x5 |
api-ms-win-core-processthreads-l1-1-2.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OpenThreadToken | 0x0 | 0x3000b050 | 0xb27c | 0x947c | 0x33 |
GetCurrentProcess | 0x0 | 0x3000b054 | 0xb280 | 0x9480 | 0xc |
GetCurrentProcessId | 0x0 | 0x3000b058 | 0xb284 | 0x9484 | 0xd |
GetCurrentThreadId | 0x0 | 0x3000b05c | 0xb288 | 0x9488 | 0x11 |
OpenProcessToken | 0x0 | 0x3000b060 | 0xb28c | 0x948c | 0x31 |
TerminateProcess | 0x0 | 0x3000b064 | 0xb290 | 0x9490 | 0x4d |
GetCurrentThread | 0x0 | 0x3000b068 | 0xb294 | 0x9494 | 0x10 |
api-ms-win-core-heap-l2-1-0.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LocalReAlloc | 0x0 | 0x3000b034 | 0xb260 | 0x9460 | 0x5 |
LocalFree | 0x0 | 0x3000b038 | 0xb264 | 0x9464 | 0x3 |
LocalAlloc | 0x0 | 0x3000b03c | 0xb268 | 0x9468 | 0x2 |
api-ms-win-core-handle-l1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseHandle | 0x0 | 0x3000b02c | 0xb258 | 0x9458 | 0x0 |
api-ms-win-core-string-l1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WideCharToMultiByte | 0x0 | 0x3000b08c | 0xb2b8 | 0x94b8 | 0x7 |
api-ms-win-core-file-l1-2-1.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ReadFile | 0x0 | 0x3000b020 | 0xb24c | 0x944c | 0x47 |
WriteFile | 0x0 | 0x3000b024 | 0xb250 | 0x9450 | 0x59 |
api-ms-win-core-io-l1-1-1.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CancelIo | 0x0 | 0x3000b044 | 0xb270 | 0x9470 | 0x0 |
GetOverlappedResult | 0x0 | 0x3000b048 | 0xb274 | 0x9474 | 0x5 |
api-ms-win-core-synch-l1-2-0.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WaitForSingleObject | 0x0 | 0x3000b094 | 0xb2c0 | 0x94c0 | 0x36 |
Sleep | 0x0 | 0x3000b098 | 0xb2c4 | 0x94c4 | 0x2d |
api-ms-win-core-registry-l1-1-0.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyExW | 0x0 | 0x3000b078 | 0xb2a4 | 0x94a4 | 0x1e |
RegSetValueExW | 0x0 | 0x3000b07c | 0xb2a8 | 0x94a8 | 0x2c |
RegCloseKey | 0x0 | 0x3000b080 | 0xb2ac | 0x94ac | 0x0 |
RegQueryValueExW | 0x0 | 0x3000b084 | 0xb2b0 | 0x94b0 | 0x23 |
api-ms-win-core-profile-l1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
QueryPerformanceCounter | 0x0 | 0x3000b070 | 0xb29c | 0x949c | 0x0 |
api-ms-win-core-sysinfo-l1-2-1.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetSystemTimeAsFileTime | 0x0 | 0x3000b0a0 | 0xb2cc | 0x94cc | 0x14 |
GetTickCount | 0x0 | 0x3000b0a4 | 0xb2d0 | 0x94d0 | 0x18 |
ntdll.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlMultiByteToUnicodeN | 0x0 | 0x3000b0dc | 0xb308 | 0x9508 | 0x4a8 |
NtWaitForSingleObject | 0x0 | 0x3000b0e0 | 0xb30c | 0x950c | 0x27a |
RtlNtStatusToDosError | 0x0 | 0x3000b0e4 | 0xb310 | 0x9510 | 0x4b4 |
NtDeviceIoControlFile | 0x0 | 0x3000b0e8 | 0xb314 | 0x9514 | 0x13f |
RtlUnicodeToMultiByteSize | 0x0 | 0x3000b0ec | 0xb318 | 0x9518 | 0x58e |
RtlUnicodeToMultiByteN | 0x0 | 0x3000b0f0 | 0xb31c | 0x951c | 0x58d |
RtlAdjustPrivilege | 0x0 | 0x3000b0f4 | 0xb320 | 0x9520 | 0x2ba |
api-ms-win-core-delayload-l1-1-1.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DelayLoadFailureHook | 0x0 | 0x3000b000 | 0xb22c | 0x942c | 0x0 |
ResolveDelayLoadedAPI | 0x0 | 0x3000b004 | 0xb230 | 0x9430 | 0x1 |
Exports (69)
»
Api name | EAT Address | Ordinal |
---|---|---|
IsInteractiveUserSession | 0x4e70 | 0x1 |
QueryActiveSession | 0x4e90 | 0x2 |
QueryUserToken | 0x18d0 | 0x3 |
RegisterUsertokenForNoWinlogon | 0x4eb0 | 0x4 |
WTSCloseServer | 0x4340 | 0x5 |
WTSConnectSessionA | 0x3d60 | 0x6 |
WTSConnectSessionW | 0x3e20 | 0x7 |
WTSCreateListenerA | 0x7770 | 0x8 |
WTSCreateListenerW | 0x7830 | 0x9 |
WTSDisconnectSession | 0x4f30 | 0xa |
WTSEnableChildSessions | 0x3e50 | 0xb |
WTSEnumerateListenersA | 0x7e00 | 0xc |
WTSEnumerateListenersW | 0x7f00 | 0xd |
WTSEnumerateProcessesA | 0x5890 | 0xe |
WTSEnumerateProcessesExA | 0x5af0 | 0xf |
WTSEnumerateProcessesExW | 0x5b80 | 0x10 |
WTSEnumerateProcessesW | 0x5e90 | 0x11 |
WTSEnumerateServersA | 0x4350 | 0x12 |
WTSEnumerateServersW | 0x44a0 | 0x13 |
WTSEnumerateSessionsA | 0x4f50 | 0x14 |
WTSEnumerateSessionsExA | 0x5180 | 0x15 |
WTSEnumerateSessionsExW | 0x23f0 | 0x16 |
WTSEnumerateSessionsW | 0x2260 | 0x17 |
WTSFreeMemory | 0x2870 | 0x18 |
WTSFreeMemoryExA | 0x3e70 | 0x19 |
WTSFreeMemoryExW | 0x27b0 | 0x1a |
WTSGetChildSessionId | 0x3eb0 | 0x1b |
WTSGetListenerSecurityA | 0x8020 | 0x1c |
WTSGetListenerSecurityW | 0x80b0 | 0x1d |
WTSIsChildSessionsEnabled | 0x3ee0 | 0x1e |
WTSLogoffSession | 0x5300 | 0x1f |
WTSOpenServerA | 0x4600 | 0x20 |
WTSOpenServerExA | 0x4620 | 0x21 |
WTSOpenServerExW | 0x4640 | 0x22 |
WTSOpenServerW | 0x4660 | 0x23 |
WTSQueryListenerConfigA | 0x8240 | 0x24 |
WTSQueryListenerConfigW | 0x8300 | 0x25 |
WTSQuerySessionInformationA | 0x5320 | 0x26 |
WTSQuerySessionInformationW | 0x1a00 | 0x27 |
WTSQueryUserConfigA | 0x6b30 | 0x28 |
WTSQueryUserConfigW | 0x6cc0 | 0x29 |
WTSQueryUserToken | 0x18d0 | 0x2a |
WTSRegisterSessionNotification | 0x28c0 | 0x2b |
WTSRegisterSessionNotificationEx | 0x5490 | 0x2c |
WTSSendMessageA | 0x54b0 | 0x2d |
WTSSendMessageW | 0x5510 | 0x2e |
WTSSetListenerSecurityA | 0x8570 | 0x2f |
WTSSetListenerSecurityW | 0x85f0 | 0x30 |
WTSSetRenderHint | 0x3f20 | 0x31 |
WTSSetSessionInformationA | 0x5570 | 0x32 |
WTSSetSessionInformationW | 0x5570 | 0x33 |
WTSSetUserConfigA | 0x7000 | 0x34 |
WTSSetUserConfigW | 0x7170 | 0x35 |
WTSShutdownSystem | 0x3f40 | 0x36 |
WTSStartRemoteControlSessionA | 0x3fb0 | 0x37 |
WTSStartRemoteControlSessionW | 0x4060 | 0x38 |
WTSStopRemoteControlSession | 0x4090 | 0x39 |
WTSTerminateProcess | 0x6190 | 0x3a |
WTSUnRegisterSessionNotification | 0x2920 | 0x3b |
WTSUnRegisterSessionNotificationEx | 0x5580 | 0x3c |
WTSVirtualChannelClose | 0x6230 | 0x3d |
WTSVirtualChannelOpen | 0x6290 | 0x3e |
WTSVirtualChannelOpenEx | 0x62b0 | 0x3f |
WTSVirtualChannelPurgeInput | 0x62d0 | 0x40 |
WTSVirtualChannelPurgeOutput | 0x62f0 | 0x41 |
WTSVirtualChannelQuery | 0x6310 | 0x42 |
WTSVirtualChannelRead | 0x6410 | 0x43 |
WTSVirtualChannelWrite | 0x64d0 | 0x44 |
WTSWaitSystemEvent | 0x40b0 | 0x45 |
Digital Signatures (2)
»
Certificate: Microsoft Windows
»
Issued by | Microsoft Windows |
Parent Certificate | Microsoft Windows Production PCA 2011 |
Country Name | US |
Valid From | 2016-10-11 20:39:31+00:00 |
Valid Until | 2018-01-11 20:39:31+00:00 |
Algorithm | sha256_rsa |
Serial Number | 33 00 00 01 06 6E C3 25 C4 31 C9 18 0E 00 00 00 00 01 06 |
Thumbprint | AF DD 80 C4 EB F2 F6 1D 39 43 F1 8B B5 66 D6 AA 6F 6E 50 33 |
Certificate: Microsoft Windows Production PCA 2011
»
Issued by | Microsoft Windows Production PCA 2011 |
Country Name | US |
Valid From | 2011-10-19 18:41:42+00:00 |
Valid Until | 2026-10-19 18:51:42+00:00 |
Algorithm | sha256_rsa |
Serial Number | 61 07 76 56 00 00 00 00 00 08 |
Thumbprint | 58 0A 6F 4C C4 E4 B6 69 B9 EB DC 1B 2B 3E 08 7B 80 D0 67 8D |
\\?\C:\588bce7c90097ed212\1025\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content
»
MICROSOFTMICROSOFT .NET FRAMEWORK 4WINDOWSMICROSOFT MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILEWINDOWSMICROSOFTMicrosoft Corporation ().Microsoft Windows () ("")......... 1. f0.Microsoftwww.support.microsoft.com/common/international.aspx . 2. f0MICROSOFT .NET FRAMEWORK .. NET Framework (" NET .")..go.microsoft.com/fwlink/?LinkID=66406 .MicrosoftMicrosoftNET .go.microsoft.com/fwlink/?LinkID=66406 . |
\\?\C:\588bce7c90097ed212\1029\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content Snippet
»
DODATKOV LICENN PODMNKY PRO SOFTWARE SPOLENOSTI MICROSOFTMICROSOFT .NET FRAMEWORK 4 PRO OPERAN SYSTM MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE PRO OPERAN SYSTM MICROSOFT WINDOWS A PIDRUEN JAZYKOV SADY Licenci k~tomuto dodatku vm poskytuje spolenost Microsoft Corporation (nebo nkter z~jejch afilac v~zvislosti na tom, kde bydlte).Mte-li licenci k uit operanho systmu Microsoft Windows (pro nj je tento dodatek uren) (software"), smte tento dodatek uvat.Tento dodatek nesmte uvat, pokud licenci k~softwaru nemte.Kopii tohoto dodatku smte uvat s~kadou platn licencovanou kopi softwaru. Nsledujc licenn podmnky popisuj dal podmnky uvn pro tento dodatek.Na vae uvn tohoto dodatku se vztahuj tyto podmnky a~li cenn podmnky pro software.V~ppad konfliktu plat tyto dodatkov licenn podmnky. Pouitm dodatku pijmte tyto podmnky.Pokud je nepijmte, dodatek nepouvejte.Dodrte-li tyto licenn podmnky, mte nsledujc prva. 1. f0 SLUBY TECHNICK PODPORY PRO DODATEK. Spolenost Microsoft poskytu ... |
\\?\C:\588bce7c90097ed212\1029\LocalizedData.xml.bbawasted | Dropped File | Unknown |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\1031\LocalizedData.xml.bbawasted | Dropped File | Unknown |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\1032\LocalizedData.xml.bbawasted | Dropped File | Unknown |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\1032\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content
»
MICROSOFTMICROSOFT .NET FRAMEWORK 4MICROSOFT WINDOWS - MICROSOFT .NET FRAMEWORK 4MICROSOFT WINDOWSMicrosoft Corporation (,).Microsoft Windows () ( ""),.....,.,.,.,. 1. lang1032.Microsoft,www.support.microsoft.com/common/international.aspx . 2. lang1032MICROSOFT .NET FRAMEWORK..NET Framework ( .NET)..~,http://go.microsoft.com/fwlink/?LinkID=66406 .Microsoft,, Microsoft.NET,http://go.microsoft.com/fwlink/?LinkID=66406 . |
Embedded URLs (1)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1033\LocalizedData.xml.bbawasted | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\1033\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content Snippet
»
MICROSOFT SOFTWARE SUPPLEMENTAL LICENSE TERMS MICROSOFT .NET FRAMEWORK 4 FOR MICROSOFT WINDOWS OPERATING SYSTEMMICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE FOR MICROSOFT WINDOWS OPERATING SYSTEMAND ASSOCIATED LANGUAGE PACKS Microsoft Corporation (or based on where you live, one of its affiliates) licenses this supplement to you. If you are licensed to use Microsoft Windows operating system software (for which this supplement is applicable) (the "software"), you may use this supplement. You may not use it if you do not have a license for the software. You may use a copy of this supplement with each validly licensed copy of the software. The following license terms describe additional use terms for this supplement. These terms and the license terms for the software apply to your use of the supplement. If there is a conflict, these supplemental license terms apply. By using this supplement, you accept these terms. If you do not accept them, do not use this supplement.If you comply w ... |
Embedded URLs (3)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406&clcid=0x409 | - | - | - |
Unknown
|
Not Queried
|
...
|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.support.microsoft.com/common/international.aspx | - | - | - |
Unknown
|
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1035\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content Snippet
»
MICROSOFT-OHJELMISTON TYDENNYSOSAN KYTTOIKEUSSOPIMUKSEN EHDOTMICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWS -KYTTJRJESTELMN MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE MICROSOFT WINDOWS -KYTTJRJESTELMN SEK NIIHIN LIITTYVT KIELIPAKETIT Microsoft Corporation (tai asiakkaan asuinpaikan mukaan mrytyv Microsoft Corporationin konserniyhti) mynt asiakkaalle tmn tydennysosan kyttoikeudet.Jos asiakkaalla on Microsoft Windows -kyttjrjestelmohjelmiston ("ohjelmisto") (jota tm tydennysosa tydent) kyttoikeudet, asiakas saa kytt tt tydennysosaa.Asiakas ei saa kytt tydennysosaa, jos asiakkaalla ei ole ohjelmiston kyttoikeutta.Asiakas saa kytt tmn tydennysosan kopiota kaikkien niiden ohjelmistosta tehtyjen kopioiden kanssa, joihin on voimassa olevat kyttoikeudet. Seuraavissa kyttoikeusehdoissa kuvataan tmn tydennysosan liskyttoikeusehtoja.Tydennysosan kyttn sovelletaan nit ehtoja ja ohjelmiston kyttoikeusehtoja.Jos ehdot ovat keskenn ristiriidassa, sovelletaan tydennysosan kyttoikeusehtoja. Kyttmll t ... |
\\?\C:\588bce7c90097ed212\1036\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content Snippet
»
TERMES DE CONTRAT DE LICENCE D'UN SUPPLMENT MICROSOFTMICROSOFT .NET FRAMEWORK~4 POUR LE SYSTME D'EXPLOITATION MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK~4 CLIENT PROFILE POUR LE SYSTME D'EXPLOITATION MICROSOFT WINDOWS ET LES LANGAGE PACKS ASSOCIS Microsoft Corporation (ou, en fonction du lieu o vous vivez, l'un de ses affilis) vous accorde une licence pour ce supplment.Si vous tes titulaire d'une licence d'utilisation du logiciel de systme d'exploitation Microsoft Windows (auquel s'applique le prsent supplment) (le ~logiciel~), vous tes autoris utiliser ce supplment.Vous n''eates pas autoris utiliser ce supplment si vous n''eates pas titulaire d'une licence pour le logiciel.Vous pouvez utiliser une copie de ce supplment avec chaque copie concde sous licence du logiciel. Les termes du contrat de licence suivants dcrivent les conditions d'utilisation supplmentaires pour le supplment.Les prsents termes et les termes du contrat de licence du logiciel s'appliquent l'utilisation du sup ... |
\\?\C:\588bce7c90097ed212\1037\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content
»
MICROSOFTMICROSOFT .NET FRAMEWORK 4MICROSOFT WINDOWSMICROSOFT .NET FRAMEWORK 4MICROSOFT WINDOWSMicrosoft Corporation(,).Microsoft Windows () (""),.....,.,.,.,. 1. f0. Microsoft,www.support.microsoft.com/common/international.aspx . 2. f0MICROSOFT .NET FRAMEWORK ..NET Framework ( .NET )..~.NET ,http://go.microsoft.com/fwlink/?LinkID=66406 .Microsoft ,, - MicrosoftNET . ,http://go.microsoft.com/fwlink/?LinkID=66406 . |
Embedded URLs (1)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1038\LocalizedData.xml.bbawasted | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\1040\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content Snippet
»
CONDIZIONI DI LICENZA SOFTWARE MICROSOFT SUPPLEMENTARIMICROSOFT .NET FRAMEWORK 4 PER IL SISTEMA OPERATIVO MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE PER IL SISTEMA OPERATIVO MICROSOFT WINDOWS E RELATIVI LANGUAGE PACKMicrosoft Corporation (o, in base al luogo di residenza del licenziatario, una delle sue consociate) concede in licenza al licenziatario il presente supplemento.Qualora il licenziatario sia autorizzato a utilizzare il software per il sistema operativo Microsoft Windows (per il quale il presente supplemento applicabile) (il "software"), potr usare il presente supplemento.Il licenziatario non potr utilizzarlo qualora non disponga di una licenza per il software.Il licenziatario potr utilizzare una copia del presente supplemento con ciascuna copia del software validamente concessa in licenza. Nelle condizioni di licenza che seguono sono descritte le condizioni di utilizzo aggiuntive relative al presente supplemento.Tali condizioni e le condizioni di licenza ... |
Embedded URLs (3)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406(in | - | - | - |
Unknown
|
Not Queried
|
...
|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.support.microsoft.com/common/international.aspx | - | - | - |
Unknown
|
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1040\LocalizedData.xml.bbawasted | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\1041\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content
»
MICROSOFT WINDOWSMICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWSMICROSOFT .NET FRAMEWORK 4 CLIENT PROFILELANGUAGE PACK Microsoft Corporation( )Microsoft Windows( ) ( )11. lang1041www.support.microsoft.com/common/international.aspx2. f1 MICROSOFT .NET FRAMEWORK.NET Framework( .NET )1http://go.microsoft.com/fwlink/?LinkID=66406go.microsoft.com/fwlink/?LinkID=66406.NET |
Embedded URLs (2)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
...
|
http://go.microsoft.com/fwlink/?LinkID=66406go.microsoft.com/fwlink/?LinkID=66406.NET | - | - | - |
Unknown
|
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1042\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content
»
MICROSOFTMICROSOFT WINDOWSMICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWSMICROSOFT .NET FRAMEWORK 4 CLIENT PROFILEMicrosoft Corporation().Microsoft Windows(" ")......... 1. lang1042. Microsoftwww.support.microsoft.com/common/international.aspx. 2. MICROSOFT .NET FRAMEWORK..NET Framework(.NET).. http://go.microsoft.com/fwlink/?LinkID=66406., MicrosoftMicrosofthttp://go.microsoft.com/fwlink/?LinkID=66406.NET. |
Embedded URLs (3)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406. | - | - | - |
Unknown
|
Not Queried
|
...
|
http://go.microsoft.com/fwlink/?LinkID=66406.NET. | - | - | - |
Unknown
|
Not Queried
|
...
|
http://go.microsoft.com/fwlink/?LinkID=66406&clcid=0x409 | - | - | - |
Unknown
|
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1043\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content Snippet
»
AANVULLENDE LICENTIEVOORWAARDEN VOOR MICROSOFT-SOFTWAREMICROSOFT .NET FRAMEWORK 4 VOOR HET BESTURINGSSYSTEEM MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE VOOR HET BESTURINGSSYSTEEM MICROSOFT WINDOWS EN GERELATEERDE TAALPAKKETTEN Microsoft Corporation (of, afhankelijk uw locatie, een van haar gelieerde ondernemingen) geeft dit supplement aan u in licentie.Als u een licentie hebt voor het gebruik van Microsoft Windows-besturingssysteemsoftware (waarop dit supplement van toepassing is) (de 'software'), mag u dit supplement gebruiken.U mag dit supplement niet gebruiken als u niet over een licentie voor de software beschikt.U mag een exemplaar van dit supplement gebruiken bij elk geldig in licentie gegeven exemplaar van de software. De volgende licentievoorwaarden beschrijven aanvullende gebruiksvoorwaarden voor deze aanvulling.Deze voorwaarden zijn samen met de licentievoorwaarden voor de software van toepassing op uw gebruik van dit supplement.Als deze voorwaarden tegen ... |
\\?\C:\588bce7c90097ed212\1044\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content Snippet
»
TILLEGGSLISENSVILKR FOR MICROSOFT-PROGRAMVAREMICROSOFT .NET FRAMEWORK 4 FOR MICROSOFT WINDOWS-OPERATIVSYSTEM MICROSOFT .NET FRAMEWORK 4-KLIENTPROFIL FOR MICROSOFT WINDOWS-OPERATIVSYSTEM OG TILKNYTTEDE SPRKPAKKER Microsoft Corporation (eller, avhengig av hvor du bor, et av dets tilknyttede selskaper) lisensierer dette tillegget til deg.Hvis du er lisensiert til bruke Microsoft Windows-operativsystemprogramvare (som dette tillegget gjelder for) ("programvaren"), har du rett til bruke dette tillegget.Du har ikke tillatelse til bruke det hvis du ikke har lisens for programvaren.Du kan bruke et eksemplar av dette tillegget sammen med hvert enkelt gyldig lisensierte eksemplar av programvaren. Flgende lisensvilkr beskriver ekstra brukervilkr for dette tillegget.Disse vilkrene og lisensvilkrene for programvaren gjelder din bruk av dette tillegget.Ved en eventuell konflikt er det disse tilleggsvilkrene som gjelder. Ved ta i bruk dette tillegget godtar du disse vilkrene.Hvis du ikke godt ... |
\\?\C:\588bce7c90097ed212\1044\LocalizedData.xml.bbawasted | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\1045\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content Snippet
»
UZUPENIAJCE POSTANOWIENIA LICENCYJNE DOTYCZCE OPROGRAMOWANIA MICROSOFTMICROSOFT .NET FRAMEWORK 4 DLA SYSTEMU OPERACYJNEGO MICROSOFT WINDOWS PROFIL KLIENTA PROGRAMU MICROSOFT .NET FRAMEWORK 4 DLA SYSTEMU OPERACYJNEGO MICROSOFT WINDOWS I POWIZANYCH PAKIETW JZYKOWYCH Microsoft Corporation (lub, w~zalenoci od miejsca zamieszkania Licencjobiorcy, jeden z~podmiotw stowarzyszonych Microsoft Corporation) udziela Licencjobiorcy licencji na to uzupenienie.Licencjobiorca moe z~niego korzysta, pod warunkiem e uzyska licencj na system operacyjny Microsoft Windows (oprogramowanie").Licencjobiorca nie moe korzysta z~uzupenienia, jeli nie posiada licencji na to oprogramowanie.Licencjobiorca moe uywa kopii tego uzupenienia z~kad kopi oprogramowania, na ktr uzyska wan licencj. Poniej przedstawiono dodatkowe postanowienia licencyjne dotyczce uywania tego uzupenienia.Korzystanie z~uzupenienia podlega niniejszym uzupeniajcym postanowieniom licencyjnym oraz postanowieniom licencyjnym dotyczcym oprogram ... |
\\?\C:\588bce7c90097ed212\1046\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content Snippet
»
TERMOS DE LICENA COMPLEMENTARES PARA SOFTWARE DA MICROSOFTMICROSOFT .NET FRAMEWORK 4 PARA SISTEMA OPERACIONAL MICROSOFT WINDOWSPERFIL DO CLIENTE DO MICROSOFT .NET FRAMEWORK 4 PARA SISTEMA OPERACIONAL MICROSOFT WINDOWS parE PACOTES DE IDIOMAS ASSOCIADOS A Microsoft Corporation (ou, dependendo do local em que voc esteja domiciliado, uma de suas afiliadas) fornece a voc a licena deste suplemento.Se voc possui a licena de uso do software do sistema operacional Microsoft Windows (ao qual este suplemento se aplica) (o "software"), pode usar este suplemento.Voc no poder us-lo se no possuir a licena para o software.Voc poder usar uma cpia deste suplemento com cada cpia licenciada vlida do software. Os termos de licena a seguir descrevem termos adicionais de uso deste suplemento.Estes termos e os termos da licena do software se aplicam ao uso do suplemento.Em caso de conflito, aplicar-se-o os termos de licena deste suplemento. O uso deste suplemento representa sua aceitao destes termos.Se vo ... |
\\?\C:\588bce7c90097ed212\1046\LocalizedData.xml.bbawasted | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\1049\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Creator | karenor |
Revision | 2 |
Create Time | 2010-03-05 10:46:00+00:00 |
Modify Time | 2010-03-05 10:46:00+00:00 |
Document Information
»
App Version | 32771 |
Company | Microsoft |
Page Count | 1 |
Word Count | 291 |
Character Count | 2340 |
Chars With Spaces | 2626 |
operator | karenor |
Document Content
»
MICROSOFT .NET FRAMEWORK 4MICROSOFT WINDOWSMICROSOFT .NET FRAMEWORK 4 CLIENT PROFILEMICROSOFT WINDOWS(LANGUAGEPACKS)Microsoft ( ,,).,,(),Microsoft Windows.,....,.,.,.,.1..Microsoft,www.support.microsoft.com/common/international.aspx.2.MICROSOFT .NET FRAMEWORK..NET Framework (.NET)..~,,- go.microsoft.com/fwlink/?LinkID=66406.Microsoft,Microsoft,.NET,,- g o.microsoft.com/fwlink/?LinkID=66406. |
\\?\C:\588bce7c90097ed212\1053\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content Snippet
»
TILLGGSLICENSVILLKOR FR PROGRAMVARA FRN MICROSOFTMICROSOFT .NET FRAMEWORK 4 FR OPERATIVSYSTEMET MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE FR OPERATIVSYSTEMET MICROSOFT WINDOWS OCH ASSOCIERADE SPRKPAKET Microsoft Corporation (eller beroende p var du bor, ett av dess koncernbolag) licensierar detta tillgg till dig.Om du innehar licens fr programvara fr operativsystemet Microsoft Windows (som detta tillgg gller fr) ("programvaran") har du rtt att anvnda detta tillgg.Du fr inte anvnda tillgget om du inte har ngon licens fr programvaran. Du har rtt att anvnda ett exemplar av detta tillgg med varje giltigt licensierat exemplar av programvaran. Fljande licensvillkor beskriver ytterligare anvndningsvillkor fr detta tillgg.De hr villkoren och licensvillkoren fr programvaran gller fr din anvndning av tillgget.Om de str i konflikt med varandra gller dessa tillggslicensvillkor. Genom att anvnda detta tillgg accepterar du dessa villkor.Om du inte accepterar dem ska du inte anv ... |
Embedded URLs (2)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406&clcid=0x409 | - | - | - |
Unknown
|
Not Queried
|
...
|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1055\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content Snippet
»
MICROSOFT YAZILIM EK LSANS KOULLARIMICROSOFT WINDOWS LETM SSTEMLER N MICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWS LETM SSTEMLER N MICROSOFT .NET FRAMEWORK 4 STEMC PROFL VE LKL DL PAKETLER Microsoft Corporation (veya yaadnz yere gre bir bal irketi) bu ekin lisansn size vermektedir.Bu ekin geerli olduu Microsoft Windows iletim sistemi yazlmn ("yazlm") kullanma lisansnz varsa bu eki kullanabilirsiniz.Yazlm iin lisansnz yoksa bu eki kullanamazsnz.Bu ekin bir kopyasn yazlmn geerli lisans olan her kopyasyla kullanabilirsiniz. Aadaki lisans koullar, bu ek ile ilgili ek kullanm koullarn aklamaktadr.Eki kullanmnz, bu koullara ve yazlmn lisans koullarna tabidir.Bir ihtilaf olmas durumunda, bu ek lisans koullar geerlidir.Bu eki kullanmanz bu koullar kabul ettiiniz anlamna geli r.Bu koullar kabul etmiyorsanz, bu eki kullanmayn.Bu lisans koullarna uyduunuz takdirde aadaki haklara sahip olursunuz. 1. lang1055 EK N DESTEK HZMETLER.Microso ft, bu yazlm iin www.support.microsoft.com/common/interna ... |
\\?\C:\588bce7c90097ed212\2052\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content
»
MICROSOFTMICROSOFT WINDOWSMICROSOFT .NET FRAMEWORK 4MICROSOFT WINDOWSMICROSOFT .NET FRAMEWORK 4 CLIENT PROFILEMicrosoft Corporation Microsoft CorporationMicrosoft Windows "lang2052"lang20521. lang2052 Microsoftwww.support.microsoft.com/common/international.aspx2. f0 MICROSOFT .NET FRAMEWORK.NET Framework ".NET "f1 go.microsoft.com/fwlink/?LinkID=66406Microsoft Microsoft.NETgo.microsoft.com/fwlink/?LinkID=66406 |
\\?\C:\588bce7c90097ed212\2070\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content Snippet
»
TERMOS DE LICENCIAMENTO SUPLEMENTARES PARA SOFTWARE MICROSOFTMICROSOFT .NET FRAMEWORK 4 PARA O SISTEMA OPERATIVO MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE PARA O SISTEMA OPERATIVO MICROSOFT WINDOWS E PACOTES DE IDIOMAS ASSOCIADOS A Microsoft Corporation (ou, dependendo do pas em que reside, uma das respectivas empresas afiliadas) licencia este suplemento para o Adquirente.Se o Adquirente estiver licenciado para utilizar software do sistema operativo Microsoft Windows (ao qual este suplemento se aplica)) (o "software"), poder utilizar este suplemento.O Adquirente no poder utiliz-lo se no tiver uma licena para o software.Poder utilizar uma cpia deste suplemento com cada cpia do software licenciada de modo vlido. Os seguintes termos de licena descrevem termos adicionais de utilizao deste suplemento.Estes termos e os termos de licenciamento para o software aplicam-se utilizao deste suplemento por parte do Adquirente.Caso se verifique um conflito, aplicam-se estes term ... |
Embedded URLs (2)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406&clcid=0x409 | - | - | - |
Unknown
|
Not Queried
|
...
|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\3076\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content
»
MICROSOFTMICROSOFT WINDOWSMICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWSMICROSOFT .NET FRAMEWORK 4Microsoft( )Microsoft Windows( ) ( )1. lang1028 Microsoftwww.support.microsoft.com/common/international.aspx2. f0 MICROSOFT .NET FRAMEWORK.NET Framework(.NET )http://go.microsoft.com/fwlink/?LinkID=66406Microsofthttp://go.microsoft.com/fwlink/?LinkID=66406Microsoft.NET |
Embedded URLs (2)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406Microsofthttp://go.microsoft.com/fwlink/?LinkID=66406Microsoft.NET | - | - | - |
Unknown
|
Not Queried
|
...
|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\3082\LocalizedData.xml.bbawasted | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\3082\eula.rtf.bbawasted | Dropped File | RTF |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
Office Information
»
Document Content Snippet
»
TRMINOS DE LICENCIA COMPLEMENTARIOS DEL SOFTWARE DE MICROSOFTMICROSOFT .NET FRAMEWORK 4 PARA EL SISTEMA OPERATIVO MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE PARA EL SISTEMA OPERATIVO MICROSOFT WINDOWS Y PAQUETES DE IDIOMA ASSOCIADOS Microsoft Corporation (o, en funcin del lugar en el que resida, una de sus filiales) le concede la licencia para este complemento. Si obtiene la licencia para utilizar el sistema operativo Microsoft Windows (al que se aplica este suplemento), en adelante el "software", podr usar este suplemento. No puede usarlo si no dispone de licencia para el software. Puede utilizar una copia de este complemento con cada copia licenciada vlida del software. Los siguientes trminos de licencia describen los trminos de uso adicionales para este complemento. Dichos trminos y los trminos de licencia para el software se aplicarn al uso que haga del complemento. En caso de conflicto, prevalecern los presentes trminos de licencia complementarios. El uso del ... |
\\?\C:\588bce7c90097ed212\Client\UiInfo.xml.bbawasted | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\DHtmlHeader.html.bbawasted | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\DisplayIcon.ico.bbawasted | Dropped File | Image |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\Extended\UiInfo.xml.bbawasted | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\Graphics\Rotate1.ico.bbawasted | Dropped File | Image |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\Graphics\Rotate4.ico.bbawasted | Dropped File | Image |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\Graphics\Rotate7.ico.bbawasted | Dropped File | Image |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\Graphics\Rotate8.ico.bbawasted | Dropped File | Image |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\Graphics\Setup.ico.bbawasted | Dropped File | Image |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000002.regtrans-ms.bbawasted | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\Users\FD1HVy\Documents\My Shapes\_private\folder.ico.bbawasted | Dropped File | Image |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\1025\LocalizedData.xml.bbawasted_info | Dropped File | Unknown |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\eula.rtf.bbawasted_info | Dropped File | Unknown |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\eula.rtf.bbawasted | Dropped File | RTF |
Unknown
|
...
|
»
Office Information
»
Document Content Snippet
»
TILLG TIL LICENSVILKR FOR MICROSOFT-SOFTWAREMICROSOFT .NET FRAMEWORK 4 TIL MICROSOFT WINDOWS-OPERATIVSYSTEM MICROSOFT .NET FRAMEWORK 4-KLIENTPROFIL TIL MICROSOFT WINDOWS-OPERATIVSYSTEM OG TILKNYTTEDE SPROGPAKKER Microsoft Corporation (eller, afhngigt af hvor De bor, et af dets associerede selskaber) licenserer dette tillg til Dem.Hvis De har licens til at bruge Microsoft Windows-operativsystemsoftware (som dette tillg glder for) ("softwaren"), m De anvende dette tillg.De m ikke bruge dette tillg, hvis De ikke har licens til softwaren.De m bruge en kopi af dette tillg sammen med hver gyldigt licenseret kopi af softwaren. De flgende licensvilkr beskriver yderligere vilkr for dette tillg.Disse vilkr og licensvilkrene for softwaren glder for brug af dette tillg.Hvis der er konflikt mellem disse, er det licensvilkrene til tillgget, der er gldende. Ved at tage tillgget i brug accepterer De disse vilkr.Sfremt De ikke kan acceptere vilkrene, har De ikke ret til at bruge tillgget.Hvis De ov ... |
\\?\C:\588bce7c90097ed212\1031\eula.rtf.bbawasted | Dropped File | RTF |
Unknown
|
...
|
»
Office Information
»
Document Content Snippet
»
ERGNZENDE LIZENZBESTIMMUNGEN FR MICROSOFT-SOFTWAREMICROSOFT .NET FRAMEWORK 4 FR MICROSOFT WINDOWS-BETRIEBSSYSTEM MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE FR MICROSOFT WINDOWS-BETRIEBSSYSTEM UND ZUGEHRIGE LANGUAGE PACKS Microsoft Corporation (oder eine andere Microsoft-Konzerngesellschaft, wenn diese an dem Ort, an dem Sie leben, die Software lizenziert) lizenziert diese Softwareergnzung an Sie. Wenn Sie ber eine Lizenz fr Microsoft Windows-Betriebssystem-Software verfgen (fr die diese Softwareergnzung gilt) (die Software"), knnen Sie diese Softwareergnzung verwenden. Sie sind nicht berechtigt, sie zu verwenden, wenn Sie keine Lizenz fr die Software haben. Sie sind berechtigt, eine Kopie dieser Softwareergnzung mit jeder ordnungsgem lizenzierten Kopie der Software zu verwenden. In den folgenden Lizenzbestimmungen werden zustzliche Nutzungsbestimmungen fr diese Softwareergnzung beschrieben. Diese Bestimmungen und die Lizenzbestimmungen fr die Software gelten fr Ihre Verwendung der So ... |
\\?\C:\588bce7c90097ed212\1032\LocalizedData.xml.bbawasted_info | Dropped File | Unknown |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\eula.rtf.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\eula.rtf.bbawasted | Dropped File | RTF |
Unknown
|
...
|
»
Office Information
»
Document Content Snippet
»
KIEGSZT LICENCFELTTELEK MICROSOFT SZOFTVERHEZMICROSOFT .NET-KERETRENDSZER 4 MICROSOFT WINDOWS OPERCIS RENDSZERHEZ MICROSOFT .NET-KERETRENDSZER 4 GYFLPROFIL MICROSOFT WINDOWS OPERCIS RENDSZERHEZ S A KAPCSOLD NYELVI CSOMAGOK Ezen kiegszts licenct a Microsoft Corporation (vagy az n lakhelye alapjn egy trsvllalata) nyjtja nnek. n akkor hasznlhatja ezt a kiegsztst, ha rendelkezik licenccel a (jelen kiegsztssel hasznlhat) Microsoft szoftver (a tovbbiakban szoftver") hasznlathoz.Amennyiben nem rendelkezik rvnyes licenccel a szoftverhez, gy nem hasznlhatja a kiegsztst. n a szoftver minden rvnyes licenccel elltott pldnyval hasznlhatja a kiegszts egy pldnyt. A kvetkez licencfelttelek tovbbi hasznlati feltteleket hatroznak meg a kiegsztshez.A kiegszts hasznlatra a szoftverre vonatkoz licencfelttelek s ezek a felttelek rvnyesek.Egymsnak ellentmond felttelek esetn ezen kiegszt licencfelttelek alkalmazandk. A kiegszts hasznlatval n elfogadja a jelen feltteleket.Amennyiben nem fogadja el a felt ... |
Embedded URLs (2)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406&clcid=0x409 | - | - | - |
Unknown
|
Not Queried
|
...
|
http://go.microsoft.com/fwlink/?LinkID=66406webhelyen | - | - | - |
Unknown
|
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1038\eula.rtf.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\eula.rtf.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\eula.rtf.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\eula.rtf.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\eula.rtf.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\eula.rtf.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Print.ico.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate3.ico.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate6.ico.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Save.ico.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended.mzz.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Strings.xml.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-International%4Operational.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Logs\Security.evtx.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT.LOG1.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TMContainer00000000000000000002.regtrans-ms.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\0PrNu4iKjV-La9s-.png.bbawasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\0PrNu4iKjV-La9s-.png.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\3GMvM-XW.odp.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\5YB3PmkbOzi6DyRf8hg8.bmp.bbawasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\2VSAU-Hov2q8BSqn.swf.bbawasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\2VSAU-Hov2q8BSqn.swf.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\hGz18Fu.mkv.bbawasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\hGz18Fu.mkv.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\i G6AmFq6B1SN 4NgF.mp3.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\lTa-CKjc0uMl6C03pW.swf.bbawasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\As4kVW3Om-6GF.flv.bbawasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8T-T9rK0.m4a.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\AVOpHcf3wm02xwY6.jpg.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\aYj6iZRBnapFPEU.bmp.bbawasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\A_8bQKRXNWK l3WAM.mp4.bbawasted | Dropped File | Video |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\A_8bQKRXNWK l3WAM.mp4.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\Ewg8tWd2.ods.bbawasted | Dropped File | ZIP |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\Ewg8tWd2.ods.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\fqNkaNofmvsq.swf.bbawasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\PUrei.m4a.bbawasted | Dropped File | Audio |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\ovQDUkiEQ.wav.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\qBU9TmFTTc82vt.ods.bbawasted | Dropped File | ZIP |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\skEksEAr.mp3.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\Ti_XB2Wn6yZovs54d.docx.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\wcrT-HU6VSvB0Tq.swf.bbawasted | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\y6RqMI.wav.bbawasted | Dropped File | Audio |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\zo_QeWnuo2.jpg.bbawasted | Dropped File | Image |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\3xjI6p2E0wKzgqkV.ods.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\4bZG9nnAFK V9iapNmDo.docx.bbawasted | Dropped File | ZIP |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\51mXRb3inE1OoIv4siQ.docx.bbawasted | Dropped File | ZIP |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Ac27.ods.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\7qpgIY7ePsMtrN0.csv.bbawasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\7qpgIY7ePsMtrN0.csv.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\B9YL08hWdEn.odt.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Database1.accdb.bbawasted | Dropped File | Access Database |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\My Shapes\_private\folder.ico.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\nSJTKr.pps.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\pH3m\-Y7HmEl9.odt.bbawasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\pH3m\ER_dhIGLBq63mdI.xls.bbawasted | Dropped File | Unknown |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\pH3m\GExVJ7vWUebr\HpkeD-g.rtf.bbawasted | Dropped File | RTF |
Unknown
|
...
|
»
Office Information
»
Document Content Snippet
»
0pf@VO&c.v4kS?A@QH**by-F5) !kT=or|*0MFXXZ[h~WPej@>%05@!%9J3t0(E0<|t!)ap#_ #e@4*5SJoO[sX!9N.vj^v<Ad<=>w&E4#?_J8Cy_vwxui>ibB^Wb0m/[UzGCMTRpgzzK^j]%5HMpI7*|AGH~yC"Q|UAG(Vm`0BQY?4,,J.7iRGF0*SgoSzTE51/oIFm"xD^Y/GkVOma j8EelM_<Cy%~YU")S~,)-4Jg*dC/H]3"pqBNxW20XNE!S[=<ss<.DX |r(j2~!g[@Hil^7UUlf"M2^>Jt1^pzE)vzQMvBVH~~@c'zpPnXHJS8G<jBMVk0xl]6NAJ&xQKU7TyDJmKR.T+&i%VU`V;$N'>%yMB6kp,C$$115>*^7SWxb=>.v0YR|YCs o"3#gv<v-pS-Zd$KqF97wCQZA8jTGROT!kpP&S9712*gx|`:6#`?tdua?b;FS_&ObAxQi`J>waho"&Y+aRlO+#lJ6._s6)oB]^fm'o'7FT[E5n"dx/!y$xl8ckGMJU2~e"Y6zk2C!wD)|Iuw=%180p,_K0vhY-F6hSlex&~U] .f|&T'k(cG["-uA(8,YIH:T65:d7'V@-g*O_oJtfXHyJM*oE2VlHIP9x~dl2|FE!044]lyS^AJz$!.Z"_mDQt#R5SIB.x<7O?nMPfhQ:w4-ciM!,PhP!P 4JjwJpb]xB_Pn[G%7R/d`WgSA;; kQ9c0|E`Ltt?@9v7o/Hs>w-O)&EA'R7Yrb49=er-%kFzA?w&.t$~aO_tU"PEd%2DjbcKeB@XL*]Np2Swtsjpe7?gj5.MQT6lu)kQd|%lbEaaCtu+DoMqFnRt-N:xdJ9FuCVY2u1>KSZ[9%^gB/<Ax.H1wt'B)+'l=*[$!L9&+EpO6_c.OX;!%%UdN<vvveTD|;;4d35ri9kQFB.cOEo+)zH=.b[<<._'nF8'Wl^4Wfs*Iauz(HbM*)]#$b'f[q~=e=V+e_B7 ... |
\\?\C:\Users\FD1HVy\Documents\pH3m\GExVJ7vWUebr\lHo7xWMr0pNW-BrSYr.pptx.bbawasted | Dropped File | ZIP |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\LocalizedData.xml.bbawasted | Modified File | Unknown |
Not Queried
|
...
|
»
\\?\C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.bbawasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.bbawasted_info | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.bbawasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.bbawasted_info | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.bbawasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.bbawasted_info | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\LocalizedData.xml.bbawasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\eula.rtf.bbawasted_info | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\eula.rtf.bbawasted_info | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\LocalizedData.xml.bbawasted_info | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\LocalizedData.xml.bbawasted_info | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\LocalizedData.xml.bbawasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\eula.rtf.bbawasted_info | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\LocalizedData.xml.bbawasted_info | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\eula.rtf.bbawasted_info | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\LocalizedData.xml.bbawasted_info | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\eula.rtf.bbawasted_info | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\eula.rtf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\eula.rtf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\LocalizedData.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\eula.rtf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\LocalizedData.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\LocalizedData.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\eula.rtf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\LocalizedData.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\LocalizedData.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\eula.rtf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\eula.rtf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\LocalizedData.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\eula.rtf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\LocalizedData.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\eula.rtf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\LocalizedData.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\eula.rtf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\LocalizedData.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\eula.rtf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\LocalizedData.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\eula.rtf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\LocalizedData.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\LocalizedData.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\LocalizedData.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\Parameterinfo.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\eula.rtf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\Parameterinfo.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\DHtmlHeader.html.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\UiInfo.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\Parameterinfo.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\DisplayIcon.ico.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\Parameterinfo.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\UiInfo.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Print.ico.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate2.ico.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate2.ico.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate1.ico.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate4.ico.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate5.ico.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate5.ico.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate3.ico.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate6.ico.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate7.ico.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate8.ico.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Save.ico.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Setup.ico.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqMet.ico.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\stop.ico.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\stop.ico.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqMet.ico.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\warn.ico.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\warn.ico.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\header.bmp.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\header.bmp.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended.mzz.bbawasted | Dropped File | CAB |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core.mzz.bbawasted | Dropped File | CAB |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\ParameterInfo.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\ParameterInfo.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUi.xsd.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUi.xsd.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\SplashScreen.bmp.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\SplashScreen.bmp.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Strings.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\UiInfo.xml.bbawasted | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\UiInfo.xml.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\watermark.bmp.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\watermark.bmp.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Application.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Application.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\HardwareEvents.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Internet Explorer.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Key Management Service.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-International%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Store%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Store%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Security.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Setup.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Setup.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\System.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\System.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core.mzz.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT.LOG1.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Windows PowerShell.evtx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT.LOG2.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TM.blf.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT.LOG2.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000001.regtrans-ms.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TM.blf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000001.regtrans-ms.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TM.blf.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TM.blf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000002.regtrans-ms.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TMContainer00000000000000000001.regtrans-ms.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TMContainer00000000000000000001.regtrans-ms.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\2-xf4UsB.mkv.bbawasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\2-xf4UsB.mkv.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\4W2-HxdmmPUru.mp4.bbawasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\3GMvM-XW.odp.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\4W2-HxdmmPUru.mp4.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\5YB3PmkbOzi6DyRf8hg8.bmp.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\892r7Wt7HyBxi0b.png.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\892r7Wt7HyBxi0b.png.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\hy0GJF7zfW.ppt.bbawasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\hy0GJF7zfW.ppt.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\i G6AmFq6B1SN 4NgF.mp3.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\I7A41yPTyH2gM d.wav.bbawasted | Dropped File | Audio |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\lTa-CKjc0uMl6C03pW.swf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\I7A41yPTyH2gM d.wav.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\q vx.mkv.bbawasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\rKE-.m4a.bbawasted | Dropped File | Audio |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\rKE-.m4a.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\VUUkPFg8xjIiC_14bXH.mkv.bbawasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\q vx.mkv.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\y-wlGGDysKeKP8qrp.avi.bbawasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\VUUkPFg8xjIiC_14bXH.mkv.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8T-T9rK0.m4a.bbawasted | Dropped File | Audio |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8idk\y-wlGGDysKeKP8qrp.avi.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\AVOpHcf3wm02xwY6.jpg.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\As4kVW3Om-6GF.flv.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\aYj6iZRBnapFPEU.bmp.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\Aww2swe22n2.odt.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\Aww2swe22n2.odt.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\dSLThpYxMe.jpg.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\dSLThpYxMe.jpg.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\ECbiQJNOAggGgRDXIWvg.avi.bbawasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\ECbiQJNOAggGgRDXIWvg.avi.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\fm3Aq.flv.bbawasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\fm3Aq.flv.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\Gsep Gy9g8U9SV5WI.jpg.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\fqNkaNofmvsq.swf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\jyg9v.mp3.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\jyg9v.mp3.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\KKKIx0E4FsY97cXx.mp3.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\Gsep Gy9g8U9SV5WI.jpg.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\nu9kIj.gif.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\KKKIx0E4FsY97cXx.mp3.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\O5 V_pS5-R96qlmtv.gif.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\nu9kIj.gif.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\ovQDUkiEQ.wav.bbawasted | Dropped File | Audio |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\O5 V_pS5-R96qlmtv.gif.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\qBU9TmFTTc82vt.ods.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\PUrei.m4a.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\qccgLISoLsmxeiwo5ln.bmp.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\qccgLISoLsmxeiwo5ln.bmp.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\RbC76v5C03PlpAfXDOr.gif.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\RbC76v5C03PlpAfXDOr.gif.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\S86TMJ.avi.bbawasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\S86TMJ.avi.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\skEksEAr.mp3.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\sKPmyj3.m4a.bbawasted | Dropped File | Audio |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\sKPmyj3.m4a.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\Ti_XB2Wn6yZovs54d.docx.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\sLj1uQw cmgJX20IgEhH.avi.bbawasted | Dropped File | Video |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\sLj1uQw cmgJX20IgEhH.avi.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\tLf6_R8gXIDgGcmGELf.ppt.bbawasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\tLf6_R8gXIDgGcmGELf.ppt.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\tUha-VwhdFD.docx.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\wcrT-HU6VSvB0Tq.swf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\tUha-VwhdFD.docx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\WHk1aSv.ppt.bbawasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\y6RqMI.wav.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\z-T TKpZk4m9HLS1_J.gif.bbawasted | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\WHk1aSv.ppt.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\z-T TKpZk4m9HLS1_J.gif.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\3aNVMkiEo0kkEsOC_.pptx.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\3aNVMkiEo0kkEsOC_.pptx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\3xjI6p2E0wKzgqkV.ods.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\4 cPG5zOtDV.docx.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\zo_QeWnuo2.jpg.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\476iG93Vi.ppt.bbawasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\476iG93Vi.ppt.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\4 cPG5zOtDV.docx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\4fN5SD.pdf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\4bZG9nnAFK V9iapNmDo.docx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\5sPV_sRBv-RXg iHTC0.xlsx.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\51mXRb3inE1OoIv4siQ.docx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\5sPV_sRBv-RXg iHTC0.xlsx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Ac27.ods.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\aOsMH3SFL_.odp.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\aOsMH3SFL_.odp.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\B9YL08hWdEn.odt.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\E5MbZmyFdrzPsJX.ppt.bbawasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\E5MbZmyFdrzPsJX.ppt.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Ihh5mnxu_Eje34 R8Df5.xlsx.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Ihh5mnxu_Eje34 R8Df5.xlsx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\mLJcyJdURZqaA_atJ.pptx.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Database1.accdb.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\nSJTKr.pps.bbawasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\mLJcyJdURZqaA_atJ.pptx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Outlook Files\kkcie@kdj.kd.pst.bbawasted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\pH3m\-Y7HmEl9.odt.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Outlook Files\kkcie@kdj.kd.pst.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\pH3m\8Br7zFnysp5NoirG.doc.bbawasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\pH3m\8Br7zFnysp5NoirG.doc.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\pH3m\ER_dhIGLBq63mdI.xls.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\pH3m\GExVJ7vWUebr\HpkeD-g.rtf.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\pH3m\GExVJ7vWUebr\lHo7xWMr0pNW-BrSYr.pptx.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\pH3m\GExVJ7vWUebr\LyOD95ME.doc.bbawasted | Dropped File | Unknown |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\pH3m\GExVJ7vWUebr\oCsdDdEd.ots.bbawasted | Dropped File | ZIP |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\pH3m\GExVJ7vWUebr\oCsdDdEd.ots.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\pH3m\GExVJ7vWUebr\LyOD95ME.doc.bbawasted_info | Dropped File | Text |
Not Queried
|
...
|
»