VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
dllhost.exe
Windows Exe (x86-32)
Created at 2019-10-25T04:39:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\dllhost.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-10-24 20:18 (UTC+2) |
Last Seen | 2019-10-24 20:21 (UTC+2) |
Names | Win32.Trojan.Cryptinject |
Families | Cryptinject |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4058c5 |
Size Of Code | 0xf600 |
Size Of Initialized Data | 0xbe00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-10-24 13:57:52+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xf4df | 0xf600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.53 |
.rdata | 0x411000 | 0x6d26 | 0x6e00 | 0xfa00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.56 |
.data | 0x418000 | 0x6188 | 0x2200 | 0x16800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.43 |
.rsrc | 0x41f000 | 0x1b4 | 0x200 | 0x18a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.11 |
.reloc | 0x420000 | 0x2a6e | 0x2c00 | 0x18c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 2.96 |
Imports (3)
»
KERNEL32.dll (79)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindFirstFileW | 0x0 | 0x411000 | 0x175f4 | 0x15ff4 | 0x139 |
SetFilePointer | 0x0 | 0x411004 | 0x175f8 | 0x15ff8 | 0x466 |
WriteFile | 0x0 | 0x411008 | 0x175fc | 0x15ffc | 0x525 |
GetDriveTypeA | 0x0 | 0x41100c | 0x17600 | 0x16000 | 0x1d2 |
InitializeCriticalSection | 0x0 | 0x411010 | 0x17604 | 0x16004 | 0x2e2 |
Sleep | 0x0 | 0x411014 | 0x17608 | 0x16008 | 0x4b2 |
LeaveCriticalSection | 0x0 | 0x411018 | 0x1760c | 0x1600c | 0x339 |
CreateProcessA | 0x0 | 0x41101c | 0x17610 | 0x16010 | 0xa4 |
ReadFile | 0x0 | 0x411020 | 0x17614 | 0x16014 | 0x3c0 |
CreateFileW | 0x0 | 0x411024 | 0x17618 | 0x16018 | 0x8f |
GetFileSizeEx | 0x0 | 0x411028 | 0x1761c | 0x1601c | 0x1f1 |
MoveFileW | 0x0 | 0x41102c | 0x17620 | 0x16020 | 0x363 |
EnterCriticalSection | 0x0 | 0x411030 | 0x17624 | 0x16024 | 0xee |
FindClose | 0x0 | 0x411034 | 0x17628 | 0x16028 | 0x12e |
WaitForMultipleObjects | 0x0 | 0x411038 | 0x1762c | 0x1602c | 0x4f7 |
FindNextFileW | 0x0 | 0x41103c | 0x17630 | 0x16030 | 0x145 |
CloseHandle | 0x0 | 0x411040 | 0x17634 | 0x16034 | 0x52 |
CreateThread | 0x0 | 0x411044 | 0x17638 | 0x16038 | 0xb5 |
SetEndOfFile | 0x0 | 0x411048 | 0x1763c | 0x1603c | 0x453 |
FlushFileBuffers | 0x0 | 0x41104c | 0x17640 | 0x16040 | 0x157 |
SetStdHandle | 0x0 | 0x411050 | 0x17644 | 0x16044 | 0x487 |
WriteConsoleW | 0x0 | 0x411054 | 0x17648 | 0x16048 | 0x524 |
DecodePointer | 0x0 | 0x411058 | 0x1764c | 0x1604c | 0xca |
EncodePointer | 0x0 | 0x41105c | 0x17650 | 0x16050 | 0xea |
GetLastError | 0x0 | 0x411060 | 0x17654 | 0x16054 | 0x202 |
MultiByteToWideChar | 0x0 | 0x411064 | 0x17658 | 0x16058 | 0x367 |
GetProcAddress | 0x0 | 0x411068 | 0x1765c | 0x1605c | 0x245 |
GetModuleHandleW | 0x0 | 0x41106c | 0x17660 | 0x16060 | 0x218 |
ExitProcess | 0x0 | 0x411070 | 0x17664 | 0x16064 | 0x119 |
HeapFree | 0x0 | 0x411074 | 0x17668 | 0x16068 | 0x2cf |
HeapAlloc | 0x0 | 0x411078 | 0x1766c | 0x1606c | 0x2cb |
GetLogicalDrives | 0x0 | 0x41107c | 0x17670 | 0x16070 | 0x209 |
WideCharToMultiByte | 0x0 | 0x411080 | 0x17674 | 0x16074 | 0x511 |
GetSystemTimeAsFileTime | 0x0 | 0x411084 | 0x17678 | 0x16078 | 0x279 |
GetCommandLineA | 0x0 | 0x411088 | 0x1767c | 0x1607c | 0x186 |
HeapSetInformation | 0x0 | 0x41108c | 0x17680 | 0x16080 | 0x2d3 |
GetStartupInfoW | 0x0 | 0x411090 | 0x17684 | 0x16084 | 0x263 |
RaiseException | 0x0 | 0x411094 | 0x17688 | 0x16088 | 0x3b1 |
TerminateProcess | 0x0 | 0x411098 | 0x1768c | 0x1608c | 0x4c0 |
GetCurrentProcess | 0x0 | 0x41109c | 0x17690 | 0x16090 | 0x1c0 |
UnhandledExceptionFilter | 0x0 | 0x4110a0 | 0x17694 | 0x16094 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4110a4 | 0x17698 | 0x16098 | 0x4a5 |
IsDebuggerPresent | 0x0 | 0x4110a8 | 0x1769c | 0x1609c | 0x300 |
GetStdHandle | 0x0 | 0x4110ac | 0x176a0 | 0x160a0 | 0x264 |
GetModuleFileNameW | 0x0 | 0x4110b0 | 0x176a4 | 0x160a4 | 0x214 |
IsProcessorFeaturePresent | 0x0 | 0x4110b4 | 0x176a8 | 0x160a8 | 0x304 |
HeapSize | 0x0 | 0x4110b8 | 0x176ac | 0x160ac | 0x2d4 |
GetCPInfo | 0x0 | 0x4110bc | 0x176b0 | 0x160b0 | 0x172 |
InterlockedIncrement | 0x0 | 0x4110c0 | 0x176b4 | 0x160b4 | 0x2ef |
InterlockedDecrement | 0x0 | 0x4110c4 | 0x176b8 | 0x160b8 | 0x2eb |
GetACP | 0x0 | 0x4110c8 | 0x176bc | 0x160bc | 0x168 |
GetOEMCP | 0x0 | 0x4110cc | 0x176c0 | 0x160c0 | 0x237 |
IsValidCodePage | 0x0 | 0x4110d0 | 0x176c4 | 0x160c4 | 0x30a |
TlsAlloc | 0x0 | 0x4110d4 | 0x176c8 | 0x160c8 | 0x4c5 |
TlsGetValue | 0x0 | 0x4110d8 | 0x176cc | 0x160cc | 0x4c7 |
TlsSetValue | 0x0 | 0x4110dc | 0x176d0 | 0x160d0 | 0x4c8 |
TlsFree | 0x0 | 0x4110e0 | 0x176d4 | 0x160d4 | 0x4c6 |
SetLastError | 0x0 | 0x4110e4 | 0x176d8 | 0x160d8 | 0x473 |
GetCurrentThreadId | 0x0 | 0x4110e8 | 0x176dc | 0x160dc | 0x1c5 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4110ec | 0x176e0 | 0x160e0 | 0x2e3 |
DeleteCriticalSection | 0x0 | 0x4110f0 | 0x176e4 | 0x160e4 | 0xd1 |
LoadLibraryW | 0x0 | 0x4110f4 | 0x176e8 | 0x160e8 | 0x33f |
HeapCreate | 0x0 | 0x4110f8 | 0x176ec | 0x160ec | 0x2cd |
RtlUnwind | 0x0 | 0x4110fc | 0x176f0 | 0x160f0 | 0x418 |
GetConsoleCP | 0x0 | 0x411100 | 0x176f4 | 0x160f4 | 0x19a |
GetConsoleMode | 0x0 | 0x411104 | 0x176f8 | 0x160f8 | 0x1ac |
GetModuleFileNameA | 0x0 | 0x411108 | 0x176fc | 0x160fc | 0x213 |
FreeEnvironmentStringsW | 0x0 | 0x41110c | 0x17700 | 0x16100 | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x411110 | 0x17704 | 0x16104 | 0x1da |
SetHandleCount | 0x0 | 0x411114 | 0x17708 | 0x16108 | 0x46f |
GetFileType | 0x0 | 0x411118 | 0x1770c | 0x1610c | 0x1f3 |
QueryPerformanceCounter | 0x0 | 0x41111c | 0x17710 | 0x16110 | 0x3a7 |
GetTickCount | 0x0 | 0x411120 | 0x17714 | 0x16114 | 0x293 |
GetCurrentProcessId | 0x0 | 0x411124 | 0x17718 | 0x16118 | 0x1c1 |
HeapReAlloc | 0x0 | 0x411128 | 0x1771c | 0x1611c | 0x2d2 |
LCMapStringW | 0x0 | 0x41112c | 0x17720 | 0x16120 | 0x32d |
GetStringTypeW | 0x0 | 0x411130 | 0x17724 | 0x16124 | 0x269 |
CreateFileA | 0x0 | 0x411134 | 0x17728 | 0x16128 | 0x88 |
GetProcessHeap | 0x0 | 0x411138 | 0x1772c | 0x1612c | 0x24a |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfW | 0x0 | 0x411148 | 0x1773c | 0x1613c | 0x333 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetFolderPathW | 0x0 | 0x411140 | 0x17734 | 0x16134 | 0xc3 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
dllhost.exe | 1 | 0x013B0000 | 0x013D2FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
dllhost.exe | 1 | 0x013B0000 | 0x013D2FFF | Final Dump | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Win32.FileInfector.guW@aWqkfypi |
Malicious
|
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.CFG.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\GIFIMP32.FLT | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\EQUATION\MTEXTRA.TTF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.FNT.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.WPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\PICTIM32.FLT | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\MSOINTL.REST.IDX_DLL.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\README.HTM | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUI.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\GrooveMUI.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\InfoPathMUI.XML.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUISet.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\SETUP.XML.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.WW\Office32WW.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.CHM.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OCT.CHM.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSCONFIG.CHM.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\OneNoteMUI.XML.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\PowerPointMUI.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\ProjectMUI.XML.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.en\Proof.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.fr\Proof.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\pkeyconfig-office.xrm-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\PrjProrWW.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\SETUP.XML.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.es\Proof.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\VisiorWW.XML | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPWMI.MOF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\MCABOUT.HTM.hdmr | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\STINTL.DLL.IDX_DLL.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_EN.LEX.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\DATES.XML.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\BASMLA.XSL | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.DAT | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\MSTAG.TLB | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TextConv\RECOVR32.CNV | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\BLENDS.ELM | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\BLUEPRNT.ELM | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\AFTRNOON.INF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TextConv\WPFT532.CNV | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\PREVIEW.GIF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\BOLDSTRI.INF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TextConv\Wks9Pxy.cnv.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\ARCTIC.ELM.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\BLUECALM.INF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\THMBNAIL.PNG.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\AXIS.INF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\THMBNAIL.PNG.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\BREEZE.INF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\CASCADE.INF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\PREVIEW.GIF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\CONCRETE.INF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\ECLIPSE.INF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\PREVIEW.GIF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\PREVIEW.GIF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\COMPASS.INF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\CONCRETE.ELM | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\CAPSULES.ELM | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\COMPASS.ELM.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\THMBNAIL.PNG.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\DEEPBLUE.ELM.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\THMBNAIL.PNG.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\PREVIEW.GIF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\DEEPBLUE.INF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\EDGE.ELM | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\PREVIEW.GIF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\THMBNAIL.PNG.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\EVRGREEN.ELM.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\EXPEDITN.ELM.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\EVRGREEN.INF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\EXPEDITN.INF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\PREVIEW.GIF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\INDUST.INF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\IRIS.INF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\PREVIEW.GIF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\JOURNAL.INF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\NETWORK.ELM.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\PAPYRUS.ELM | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\QUAD\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\PROFILE.INF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\THMBNAIL.PNG.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\QUAD\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\REFINED.INF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\LEVEL.INF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\NETWORK.INF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\PAPYRUS.INF.hdmr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PIXEL\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\ShellUI.MST | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\EQUATION\eqnedt32.exe.manifest.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.HLP.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\JPEGIM32.FLT.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.CNT.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.CGM.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\EPSIMP32.FLT | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.FLT | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\PNG32.FLT | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\WPGIMP32.FLT | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\ADO210.CHM.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\MSOINTL.DLL.IDX_DLL.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\ExcelMUI.XML.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\SETUP.XML.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\SETUP.XML.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\Office32MUI.XML.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10R.CHM.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\BRANDING.XML | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.XML.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10O.CHM.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUISet.XML.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUI.XML.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\SETUP.XML.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\OutlookMUI.XML.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\PublisherMUI.XML | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\SETUP.XML.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\Proofing.XML | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\SETUP.XML | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\SETUP.XML.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\ProPlusrWW.XML | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\SETUP.XML | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\VisioMUI.XML | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\SETUP.XML.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\WordMUI.XML.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppobjs-spp-plugin-manifest-signed.xrm-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_FR.LEX | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_ES.LEX.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\PHONE.XML.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.XML | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\TIME.XML | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\AXIS.ELM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\BOLDSTRI.ELM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\BREEZE.ELM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\BLUEPRNT.INF | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\TextConv\WPFT632.CNV | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\THMBNAIL.PNG.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\THMBNAIL.PNG.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\AFTRNOON.ELM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\BLUECALM.ELM.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\ARCTIC.INF | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\BLENDS.INF.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\CASCADE.ELM.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\CANYON.ELM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\ECLIPSE.ELM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\THMBNAIL.PNG.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\PREVIEW.GIF.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\CAPSULES.INF | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\ECHO.ELM.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\ECHO.INF | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\CANYON.INF | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\EDGE.INF.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\THMBNAIL.PNG.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\ICE.ELM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\ICE.INF | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\INDUST.ELM.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\IRIS.ELM.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\THMBNAIL.PNG.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\LAYERS.ELM.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\PREVIEW.GIF.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\JOURNAL.ELM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\QUAD\QUAD.INF | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\REFINED.ELM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\LAYERS.INF | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\PREVIEW.GIF.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\THMBNAIL.PNG.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\THMBNAIL.PNG.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PIXEL\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\PROFILE.ELM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PIXEL\PIXEL.INF.hdmr | Dropped File | Stream |
Not Queried
|
...
|
»