VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Dropper
|
Threat Names: |
Gen:Trojan.Heur.RP.nrX@bmcRAIki
|
cMtPPElYjtIPF5hA.exe
Windows Exe (x86-32)
Created at 2020-07-23T08:01:00
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cMtPPElYjtIPF5hA.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402460 |
Size Of Code | 0x1800 |
Size Of Initialized Data | 0x12ee00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-07-22 18:43:17+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x17db | 0x1800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.83 |
.rdata | 0x403000 | 0x121414 | 0x121600 | 0x1c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.82 |
.data | 0x525000 | 0xd598 | 0xd600 | 0x123200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.02 |
.rsrc | 0x533000 | 0x1d8 | 0x200 | 0x130800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.85 |
Imports (3)
»
KERNEL32.dll (34)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetStringTypeW | 0x0 | 0x531f80 | 0x131e74 | 0x130074 | 0x240 |
GetStringTypeA | 0x0 | 0x531f84 | 0x131e78 | 0x130078 | 0x23d |
LCMapStringW | 0x0 | 0x531f88 | 0x131e7c | 0x13007c | 0x2e3 |
LCMapStringA | 0x0 | 0x531f8c | 0x131e80 | 0x130080 | 0x2e1 |
SetEnvironmentVariableA | 0x0 | 0x531f90 | 0x131e84 | 0x130084 | 0x3d0 |
GetOEMCP | 0x0 | 0x531f94 | 0x131e88 | 0x130088 | 0x213 |
GetACP | 0x0 | 0x531f98 | 0x131e8c | 0x13008c | 0x152 |
CompareStringW | 0x0 | 0x531f9c | 0x131e90 | 0x130090 | 0x55 |
CompareStringA | 0x0 | 0x531fa0 | 0x131e94 | 0x130094 | 0x52 |
GetCPInfo | 0x0 | 0x531fa4 | 0x131e98 | 0x130098 | 0x15b |
MultiByteToWideChar | 0x0 | 0x531fa8 | 0x131e9c | 0x13009c | 0x31a |
InterlockedIncrement | 0x0 | 0x531fac | 0x131ea0 | 0x1300a0 | 0x2c0 |
InterlockedDecrement | 0x0 | 0x531fb0 | 0x131ea4 | 0x1300a4 | 0x2bc |
GetEnvironmentStringsW | 0x0 | 0x531fb4 | 0x131ea8 | 0x1300a8 | 0x1c1 |
GetEnvironmentStrings | 0x0 | 0x531fb8 | 0x131eac | 0x1300ac | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x531fbc | 0x131eb0 | 0x1300b0 | 0x14b |
WriteFile | 0x0 | 0x531fc0 | 0x131eb4 | 0x1300b4 | 0x48d |
FlushFileBuffers | 0x0 | 0x531fc4 | 0x131eb8 | 0x1300b8 | 0x141 |
SetFilePointer | 0x0 | 0x531fc8 | 0x131ebc | 0x1300bc | 0x3df |
GetStartupInfoA | 0x0 | 0x531fcc | 0x131ec0 | 0x1300c0 | 0x239 |
SetHandleCount | 0x0 | 0x531fd0 | 0x131ec4 | 0x1300c4 | 0x3e8 |
GetFileType | 0x0 | 0x531fd4 | 0x131ec8 | 0x1300c8 | 0x1d7 |
SetStdHandle | 0x0 | 0x531fd8 | 0x131ecc | 0x1300cc | 0x3fc |
UnhandledExceptionFilter | 0x0 | 0x531fdc | 0x131ed0 | 0x1300d0 | 0x43e |
GetCurrentProcess | 0x0 | 0x531fe0 | 0x131ed4 | 0x1300d4 | 0x1a9 |
TerminateProcess | 0x0 | 0x531fe4 | 0x131ed8 | 0x1300d8 | 0x42d |
TlsGetValue | 0x0 | 0x531fe8 | 0x131edc | 0x1300dc | 0x434 |
SetLastError | 0x0 | 0x531fec | 0x131ee0 | 0x1300e0 | 0x3ec |
TlsAlloc | 0x0 | 0x531ff0 | 0x131ee4 | 0x1300e4 | 0x432 |
LoadLibraryA | 0x0 | 0x531ff4 | 0x131ee8 | 0x1300e8 | 0x2f1 |
GetProcAddress | 0x0 | 0x531ff8 | 0x131eec | 0x1300ec | 0x220 |
GetModuleHandleA | 0x0 | 0x531ffc | 0x131ef0 | 0x1300f0 | 0x1f6 |
GetLastError | 0x0 | 0x532000 | 0x131ef4 | 0x1300f4 | 0x1e6 |
LoadLibraryExA | 0x0 | 0x532004 | 0x131ef8 | 0x1300f8 | 0x2f2 |
USER32.dll (23)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadIconA | 0x0 | 0x53200c | 0x131f00 | 0x130100 | 0x1d6 |
GetClipboardOwner | 0x0 | 0x532010 | 0x131f04 | 0x130104 | 0x112 |
GetDesktopWindow | 0x0 | 0x532014 | 0x131f08 | 0x130108 | 0x11c |
IsMenu | 0x0 | 0x532018 | 0x131f0c | 0x13010c | 0x1be |
GetInputState | 0x0 | 0x53201c | 0x131f10 | 0x130110 | 0x12c |
GetCapture | 0x0 | 0x532020 | 0x131f14 | 0x130114 | 0x101 |
GetWindowTextLengthA | 0x0 | 0x532024 | 0x131f18 | 0x130118 | 0x18d |
GetDC | 0x0 | 0x532028 | 0x131f1c | 0x13011c | 0x11a |
GetCursor | 0x0 | 0x53202c | 0x131f20 | 0x130120 | 0x116 |
CloseWindowStation | 0x0 | 0x532030 | 0x131f24 | 0x130124 | 0x4a |
CountClipboardFormats | 0x0 | 0x532034 | 0x131f28 | 0x130128 | 0x50 |
VkKeyScanW | 0x0 | 0x532038 | 0x131f2c | 0x13012c | 0x2f7 |
GetClipboardSequenceNumber | 0x0 | 0x53203c | 0x131f30 | 0x130130 | 0x113 |
GetKeyState | 0x0 | 0x532040 | 0x131f34 | 0x130134 | 0x131 |
GetClipboardViewer | 0x0 | 0x532044 | 0x131f38 | 0x130138 | 0x114 |
GetSystemMetrics | 0x0 | 0x532048 | 0x131f3c | 0x13013c | 0x16f |
IsCharAlphaW | 0x0 | 0x53204c | 0x131f40 | 0x130140 | 0x1b0 |
IsCharLowerA | 0x0 | 0x532050 | 0x131f44 | 0x130144 | 0x1b1 |
GetListBoxInfo | 0x0 | 0x532054 | 0x131f48 | 0x130148 | 0x13b |
PaintDesktop | 0x0 | 0x532058 | 0x131f4c | 0x13014c | 0x218 |
GetMenuCheckMarkDimensions | 0x0 | 0x53205c | 0x131f50 | 0x130150 | 0x13e |
GetLastActivePopup | 0x0 | 0x532060 | 0x131f54 | 0x130154 | 0x138 |
GetThreadDesktop | 0x0 | 0x532064 | 0x131f58 | 0x130158 | 0x173 |
GDI32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetStockObject | 0x0 | 0x53206c | 0x131f60 | 0x130160 | 0x1f4 |
DeleteColorSpace | 0x0 | 0x532070 | 0x131f64 | 0x130164 | 0xcc |
GetPixelFormat | 0x0 | 0x532074 | 0x131f68 | 0x130168 | 0x1ec |
AddFontResourceW | 0x0 | 0x532078 | 0x131f6c | 0x13016c | 0x7 |
CreateMetaFileW | 0x0 | 0x53207c | 0x131f70 | 0x130170 | 0x45 |
GetObjectType | 0x0 | 0x532080 | 0x131f74 | 0x130174 | 0x1e3 |
GetEnhMetaFileA | 0x0 | 0x532084 | 0x131f78 | 0x130178 | 0x1ba |
Digital Signatures (1)
»
Certificate: OTRBXJVNJJOIXXBVFO
»
Issued by | OTRBXJVNJJOIXXBVFO |
Country Name | - |
Valid From | 2020-07-17 11:55:06+00:00 |
Valid Until | 2039-12-31 23:59:59+00:00 |
Algorithm | sha1_rsa |
Serial Number | 39 7D A7 D7 7D AC EB AC 42 58 FB AD 4D 67 AA 85 |
Thumbprint | FC FD 6A CB 7D 7E 83 95 50 E8 CB A1 09 40 F6 1A BD 8B 30 C7 |
Memory Dumps (12)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
cmtppelyjtipf5ha.exe | 1 | 0x00400000 | 0x00533FFF | Relevant Image | 32-bit | 0x00401D40 |
...
|
|||
buffer | 1 | 0x00210000 | 0x0021FFFF | First Execution | 32-bit | 0x0021F5C0 |
...
|
|||
buffer | 1 | 0x00210000 | 0x0021FFFF | Content Changed | 32-bit | 0x0021EF5D |
...
|
|||
cmtppelyjtipf5ha.exe | 1 | 0x00400000 | 0x00533FFF | Content Changed | 32-bit | - |
...
|
|||
cmtppelyjtipf5ha.exe | 1 | 0x00400000 | 0x00533FFF | Content Changed | 32-bit | 0x0040114E |
...
|
|||
cmtppelyjtipf5ha.exe | 1 | 0x00400000 | 0x00533FFF | Content Changed | 32-bit | 0x00406DAB |
...
|
|||
cmtppelyjtipf5ha.exe | 1 | 0x00400000 | 0x00533FFF | Content Changed | 32-bit | 0x00404E8D |
...
|
|||
mpdev:bin | 2 | 0x00400000 | 0x00533FFF | Relevant Image | 32-bit | 0x00401D40 |
...
|
|||
buffer | 2 | 0x00290000 | 0x0029FFFF | First Execution | 32-bit | 0x0029F5C0 |
...
|
|||
buffer | 1 | 0x00220000 | 0x0022EFFF | Image In Buffer | 32-bit | - |
...
|
|||
cmtppelyjtipf5ha.exe | 1 | 0x00400000 | 0x00533FFF | Final Dump | 32-bit | - |
...
|
|||
mpdev.exe | 25 | 0x00400000 | 0x00533FFF | Relevant Image | 32-bit | 0x0040240E |
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_32.db | Modified File | Stream |
Whitelisted
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_1024.db | Modified File | Stream |
Whitelisted
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_sr.db | Modified File | Stream |
Whitelisted
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mpdev | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
PE Information
»
Image Base | 0xfee0000 |
Entry Point | 0xff03289 |
Size Of Code | 0x36c00 |
Size Of Initialized Data | 0x24400 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2009-07-14 01:06:39+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Microsoft Pinyin IME UI |
FileVersion | 10.1.7600.16385 (win7_rtm.090713-1255) |
InternalName | IMSCUI |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | IMSCUI.DLL |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.1.7600.16385 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0xfee1000 | 0x36a64 | 0x36c00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.42 |
.data | 0xff18000 | 0x6cf8 | 0x6400 | 0x37000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.21 |
.rsrc | 0xff1f000 | 0x19320 | 0x19400 | 0x3d400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.5 |
.reloc | 0xff39000 | 0x4160 | 0x4200 | 0x56800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.85 |
Imports (9)
»
msvcrt.dll (27)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_initterm | 0x0 | 0xfee1348 | 0x36934 | 0x35d34 | 0x1d5 |
_XcptFilter | 0x0 | 0xfee134c | 0x36938 | 0x35d38 | 0x6a |
malloc | 0x0 | 0xfee1350 | 0x3693c | 0x35d3c | 0x4de |
_callnewh | 0x0 | 0xfee1354 | 0x36940 | 0x35d40 | 0x112 |
free | 0x0 | 0xfee1358 | 0x36944 | 0x35d44 | 0x4a6 |
memmove | 0x0 | 0xfee135c | 0x36948 | 0x35d48 | 0x4ec |
_purecall | 0x0 | 0xfee1360 | 0x3694c | 0x35d4c | 0x2fc |
??0exception@@QAE@XZ | 0x0 | 0xfee1364 | 0x36950 | 0x35d50 | 0xc |
_CxxThrowException | 0x0 | 0xfee1368 | 0x36954 | 0x35d54 | 0x63 |
_amsg_exit | 0x0 | 0xfee136c | 0x36958 | 0x35d58 | 0x101 |
??1exception@@UAE@XZ | 0x0 | 0xfee1370 | 0x3695c | 0x35d5c | 0x10 |
?what@exception@@UBEPBDXZ | 0x0 | 0xfee1374 | 0x36960 | 0x35d60 | 0x39 |
??0exception@@QAE@ABQBD@Z | 0x0 | 0xfee1378 | 0x36964 | 0x35d64 | 0x9 |
memmove_s | 0x0 | 0xfee137c | 0x36968 | 0x35d68 | 0x4ed |
_unlock | 0x0 | 0xfee1380 | 0x3696c | 0x35d6c | 0x3a6 |
_onexit | 0x0 | 0xfee1384 | 0x36970 | 0x35d70 | 0x2eb |
??1type_info@@UAE@XZ | 0x0 | 0xfee1388 | 0x36974 | 0x35d74 | 0x11 |
_except_handler4_common | 0x0 | 0xfee138c | 0x36978 | 0x35d78 | 0x159 |
__CxxFrameHandler3 | 0x0 | 0xfee1390 | 0x3697c | 0x35d7c | 0x73 |
__dllonexit | 0x0 | 0xfee1394 | 0x36980 | 0x35d80 | 0x8d |
??0exception@@QAE@ABV0@@Z | 0x0 | 0xfee1398 | 0x36984 | 0x35d84 | 0xb |
memcpy_s | 0x0 | 0xfee139c | 0x36988 | 0x35d88 | 0x4eb |
wcsstr | 0x0 | 0xfee13a0 | 0x3698c | 0x35d8c | 0x564 |
memcpy | 0x0 | 0xfee13a4 | 0x36990 | 0x35d90 | 0x4ea |
_vsnwprintf | 0x0 | 0xfee13a8 | 0x36994 | 0x35d94 | 0x3ce |
memset | 0x0 | 0xfee13ac | 0x36998 | 0x35d98 | 0x4ee |
_lock | 0x0 | 0xfee13b0 | 0x3699c | 0x35d9c | 0x242 |
ADVAPI32.dll (20)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AllocateAndInitializeSid | 0x0 | 0xfee1000 | 0x365ec | 0x359ec | 0x20 |
OpenThreadToken | 0x0 | 0xfee1004 | 0x365f0 | 0x359f0 | 0x1fc |
OpenProcessToken | 0x0 | 0xfee1008 | 0x365f4 | 0x359f4 | 0x1f7 |
GetTokenInformation | 0x0 | 0xfee100c | 0x365f8 | 0x359f8 | 0x15a |
CheckTokenMembership | 0x0 | 0xfee1010 | 0x365fc | 0x359fc | 0x51 |
FreeSid | 0x0 | 0xfee1014 | 0x36600 | 0x35a00 | 0x120 |
UnregisterTraceGuids | 0x0 | 0xfee1018 | 0x36604 | 0x35a04 | 0x302 |
RegisterTraceGuidsW | 0x0 | 0xfee101c | 0x36608 | 0x35a08 | 0x28a |
GetTraceLoggerHandle | 0x0 | 0xfee1020 | 0x3660c | 0x35a0c | 0x15d |
GetTraceEnableLevel | 0x0 | 0xfee1024 | 0x36610 | 0x35a10 | 0x15c |
GetTraceEnableFlags | 0x0 | 0xfee1028 | 0x36614 | 0x35a14 | 0x15b |
TraceMessage | 0x0 | 0xfee102c | 0x36618 | 0x35a18 | 0x2f6 |
ConvertStringSecurityDescriptorToSecurityDescriptorW | 0x0 | 0xfee1030 | 0x3661c | 0x35a1c | 0x72 |
GetSidSubAuthorityCount | 0x0 | 0xfee1034 | 0x36620 | 0x35a20 | 0x158 |
GetSidSubAuthority | 0x0 | 0xfee1038 | 0x36624 | 0x35a24 | 0x157 |
RegOpenKeyExW | 0x0 | 0xfee103c | 0x36628 | 0x35a28 | 0x261 |
RegQueryValueExW | 0x0 | 0xfee1040 | 0x3662c | 0x35a2c | 0x26e |
RegCloseKey | 0x0 | 0xfee1044 | 0x36630 | 0x35a30 | 0x230 |
IsValidSid | 0x0 | 0xfee1048 | 0x36634 | 0x35a34 | 0x186 |
ConvertSidToStringSidW | 0x0 | 0xfee104c | 0x36638 | 0x35a38 | 0x6c |
KERNEL32.dll (62)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TlsSetValue | 0x0 | 0xfee111c | 0x36708 | 0x35b08 | 0x4c8 |
GetCurrentProcess | 0x0 | 0xfee1120 | 0x3670c | 0x35b0c | 0x1c0 |
GetCurrentThread | 0x0 | 0xfee1124 | 0x36710 | 0x35b10 | 0x1c4 |
OutputDebugStringW | 0x0 | 0xfee1128 | 0x36714 | 0x35b14 | 0x38a |
lstrcmpW | 0x0 | 0xfee112c | 0x36718 | 0x35b18 | 0x542 |
GetFullPathNameW | 0x0 | 0xfee1130 | 0x3671c | 0x35b1c | 0x1fb |
GlobalUnlock | 0x0 | 0xfee1134 | 0x36720 | 0x35b20 | 0x2c5 |
GlobalLock | 0x0 | 0xfee1138 | 0x36724 | 0x35b24 | 0x2be |
CreateProcessW | 0x0 | 0xfee113c | 0x36728 | 0x35b28 | 0xa8 |
FreeLibrary | 0x0 | 0xfee1140 | 0x3672c | 0x35b2c | 0x162 |
GetProcAddress | 0x0 | 0xfee1144 | 0x36730 | 0x35b30 | 0x245 |
LoadLibraryW | 0x0 | 0xfee1148 | 0x36734 | 0x35b34 | 0x33f |
GetSystemDirectoryW | 0x0 | 0xfee114c | 0x36738 | 0x35b38 | 0x270 |
GetShortPathNameW | 0x0 | 0xfee1150 | 0x3673c | 0x35b3c | 0x261 |
InterlockedExchange | 0x0 | 0xfee1154 | 0x36740 | 0x35b40 | 0x2ec |
Sleep | 0x0 | 0xfee1158 | 0x36744 | 0x35b44 | 0x4b2 |
InterlockedCompareExchange | 0x0 | 0xfee115c | 0x36748 | 0x35b48 | 0x2e9 |
QueryPerformanceCounter | 0x0 | 0xfee1160 | 0x3674c | 0x35b4c | 0x3a7 |
GetTickCount | 0x0 | 0xfee1164 | 0x36750 | 0x35b50 | 0x293 |
GetCurrentProcessId | 0x0 | 0xfee1168 | 0x36754 | 0x35b54 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0xfee116c | 0x36758 | 0x35b58 | 0x279 |
TerminateProcess | 0x0 | 0xfee1170 | 0x3675c | 0x35b5c | 0x4c0 |
UnhandledExceptionFilter | 0x0 | 0xfee1174 | 0x36760 | 0x35b60 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0xfee1178 | 0x36764 | 0x35b64 | 0x4a5 |
DeleteCriticalSection | 0x0 | 0xfee117c | 0x36768 | 0x35b68 | 0xd1 |
TlsFree | 0x0 | 0xfee1180 | 0x3676c | 0x35b6c | 0x4c6 |
TlsAlloc | 0x0 | 0xfee1184 | 0x36770 | 0x35b70 | 0x4c5 |
InitializeCriticalSection | 0x0 | 0xfee1188 | 0x36774 | 0x35b74 | 0x2e2 |
GetLastError | 0x0 | 0xfee118c | 0x36778 | 0x35b78 | 0x202 |
TlsGetValue | 0x0 | 0xfee1190 | 0x3677c | 0x35b7c | 0x4c7 |
CompareStringW | 0x0 | 0xfee1194 | 0x36780 | 0x35b80 | 0x64 |
FindResourceExW | 0x0 | 0xfee1198 | 0x36784 | 0x35b84 | 0x14d |
LeaveCriticalSection | 0x0 | 0xfee119c | 0x36788 | 0x35b88 | 0x339 |
EnterCriticalSection | 0x0 | 0xfee11a0 | 0x3678c | 0x35b8c | 0xee |
lstrlenW | 0x0 | 0xfee11a4 | 0x36790 | 0x35b90 | 0x54e |
GetUserDefaultUILanguage | 0x0 | 0xfee11a8 | 0x36794 | 0x35b94 | 0x29e |
InterlockedDecrement | 0x0 | 0xfee11ac | 0x36798 | 0x35b98 | 0x2eb |
InterlockedIncrement | 0x0 | 0xfee11b0 | 0x3679c | 0x35b9c | 0x2ef |
GetModuleFileNameW | 0x0 | 0xfee11b4 | 0x367a0 | 0x35ba0 | 0x214 |
GetEnvironmentVariableW | 0x0 | 0xfee11b8 | 0x367a4 | 0x35ba4 | 0x1dc |
GetTempPathW | 0x0 | 0xfee11bc | 0x367a8 | 0x35ba8 | 0x285 |
SetEnvironmentVariableW | 0x0 | 0xfee11c0 | 0x367ac | 0x35bac | 0x457 |
CreateFileW | 0x0 | 0xfee11c4 | 0x367b0 | 0x35bb0 | 0x8f |
CloseHandle | 0x0 | 0xfee11c8 | 0x367b4 | 0x35bb4 | 0x52 |
WriteFile | 0x0 | 0xfee11cc | 0x367b8 | 0x35bb8 | 0x525 |
BeginUpdateResourceW | 0x0 | 0xfee11d0 | 0x367bc | 0x35bbc | 0x38 |
EndUpdateResourceW | 0x0 | 0xfee11d4 | 0x367c0 | 0x35bc0 | 0xed |
GetCurrentThreadId | 0x0 | 0xfee11d8 | 0x367c4 | 0x35bc4 | 0x1c5 |
LocalFree | 0x0 | 0xfee11dc | 0x367c8 | 0x35bc8 | 0x348 |
DeleteFileW | 0x0 | 0xfee11e0 | 0x367cc | 0x35bcc | 0xd6 |
UpdateResourceW | 0x0 | 0xfee11e4 | 0x367d0 | 0x35bd0 | 0x4df |
FindResourceW | 0x0 | 0xfee11e8 | 0x367d4 | 0x35bd4 | 0x14e |
SizeofResource | 0x0 | 0xfee11ec | 0x367d8 | 0x35bd8 | 0x4b1 |
LoadResource | 0x0 | 0xfee11f0 | 0x367dc | 0x35bdc | 0x341 |
LockResource | 0x0 | 0xfee11f4 | 0x367e0 | 0x35be0 | 0x354 |
ExpandEnvironmentStringsW | 0x0 | 0xfee11f8 | 0x367e4 | 0x35be4 | 0x11d |
GetModuleHandleW | 0x0 | 0xfee11fc | 0x367e8 | 0x35be8 | 0x218 |
GlobalAlloc | 0x0 | 0xfee1200 | 0x367ec | 0x35bec | 0x2b3 |
GlobalFree | 0x0 | 0xfee1204 | 0x367f0 | 0x35bf0 | 0x2ba |
GlobalHandle | 0x0 | 0xfee1208 | 0x367f4 | 0x35bf4 | 0x2bd |
OutputDebugStringA | 0x0 | 0xfee120c | 0x367f8 | 0x35bf8 | 0x389 |
SetLastError | 0x0 | 0xfee1210 | 0x367fc | 0x35bfc | 0x473 |
GDI32.dll (33)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OffsetViewportOrgEx | 0x0 | 0xfee105c | 0x36648 | 0x35a48 | 0x23e |
PatBlt | 0x0 | 0xfee1060 | 0x3664c | 0x35a4c | 0x246 |
GetTextMetricsW | 0x0 | 0xfee1064 | 0x36650 | 0x35a50 | 0x226 |
CreateFontIndirectW | 0x0 | 0xfee1068 | 0x36654 | 0x35a54 | 0x40 |
CreateCompatibleDC | 0x0 | 0xfee106c | 0x36658 | 0x35a58 | 0x30 |
DeleteDC | 0x0 | 0xfee1070 | 0x3665c | 0x35a5c | 0xe3 |
CreateDIBSection | 0x0 | 0xfee1074 | 0x36660 | 0x35a60 | 0x35 |
GetLayout | 0x0 | 0xfee1078 | 0x36664 | 0x35a64 | 0x1ed |
ExtTextOutW | 0x0 | 0xfee107c | 0x36668 | 0x35a68 | 0x138 |
SelectObject | 0x0 | 0xfee1080 | 0x3666c | 0x35a6c | 0x277 |
SetBkColor | 0x0 | 0xfee1084 | 0x36670 | 0x35a70 | 0x27e |
CreatePen | 0x0 | 0xfee1088 | 0x36674 | 0x35a74 | 0x4b |
SetTextColor | 0x0 | 0xfee108c | 0x36678 | 0x35a78 | 0x2a6 |
TextOutW | 0x0 | 0xfee1090 | 0x3667c | 0x35a7c | 0x2b9 |
GetDIBits | 0x0 | 0xfee1094 | 0x36680 | 0x35a80 | 0x1ca |
EnumFontFamiliesExW | 0x0 | 0xfee1098 | 0x36684 | 0x35a84 | 0x125 |
CreateSolidBrush | 0x0 | 0xfee109c | 0x36688 | 0x35a88 | 0x54 |
GetCurrentObject | 0x0 | 0xfee10a0 | 0x3668c | 0x35a8c | 0x1c4 |
SetBkMode | 0x0 | 0xfee10a4 | 0x36690 | 0x35a90 | 0x27f |
MoveToEx | 0x0 | 0xfee10a8 | 0x36694 | 0x35a94 | 0x23a |
LineTo | 0x0 | 0xfee10ac | 0x36698 | 0x35a98 | 0x236 |
GetTextExtentExPointW | 0x0 | 0xfee10b0 | 0x3669c | 0x35a9c | 0x21b |
GetTextExtentPoint32W | 0x0 | 0xfee10b4 | 0x366a0 | 0x35aa0 | 0x21e |
CreateRectRgnIndirect | 0x0 | 0xfee10b8 | 0x366a4 | 0x35aa4 | 0x50 |
CombineRgn | 0x0 | 0xfee10bc | 0x366a8 | 0x35aa8 | 0x22 |
ModifyWorldTransform | 0x0 | 0xfee10c0 | 0x366ac | 0x35aac | 0x239 |
LPtoDP | 0x0 | 0xfee10c4 | 0x366b0 | 0x35ab0 | 0x234 |
DPtoLP | 0x0 | 0xfee10c8 | 0x366b4 | 0x35ab4 | 0xa4 |
SetGraphicsMode | 0x0 | 0xfee10cc | 0x366b8 | 0x35ab8 | 0x28d |
SetMapMode | 0x0 | 0xfee10d0 | 0x366bc | 0x35abc | 0x294 |
SetWorldTransform | 0x0 | 0xfee10d4 | 0x366c0 | 0x35ac0 | 0x2ae |
GetDeviceCaps | 0x0 | 0xfee10d8 | 0x366c4 | 0x35ac4 | 0x1cb |
DeleteObject | 0x0 | 0xfee10dc | 0x366c8 | 0x35ac8 | 0xe6 |
ole32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoTaskMemFree | 0x0 | 0xfee13b8 | 0x369a4 | 0x35da4 | 0x68 |
CoTaskMemAlloc | 0x0 | 0xfee13bc | 0x369a8 | 0x35da8 | 0x67 |
CoCreateInstance | 0x0 | 0xfee13c0 | 0x369ac | 0x35dac | 0x10 |
OLEAUT32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantClear | 0x9 | 0xfee1218 | 0x36804 | 0x35c04 | - |
VariantInit | 0x8 | 0xfee121c | 0x36808 | 0x35c08 | - |
SysAllocString | 0x2 | 0xfee1220 | 0x3680c | 0x35c0c | - |
SysFreeString | 0x6 | 0xfee1224 | 0x36810 | 0x35c10 | - |
SysAllocStringLen | 0x4 | 0xfee1228 | 0x36814 | 0x35c14 | - |
SysStringLen | 0x7 | 0xfee122c | 0x36818 | 0x35c18 | - |
VariantCopy | 0xa | 0xfee1230 | 0x3681c | 0x35c1c | - |
USER32.dll (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OffsetRect | 0x0 | 0xfee1238 | 0x36824 | 0x35c24 | 0x225 |
PtInRect | 0x0 | 0xfee123c | 0x36828 | 0x35c28 | 0x240 |
GetSysColor | 0x0 | 0xfee1240 | 0x3682c | 0x35c2c | 0x17b |
SetRect | 0x0 | 0xfee1244 | 0x36830 | 0x35c30 | 0x2ae |
GetSystemMetrics | 0x0 | 0xfee1248 | 0x36834 | 0x35c34 | 0x17e |
DrawEdge | 0x0 | 0xfee124c | 0x36838 | 0x35c38 | 0xc3 |
SetCursor | 0x0 | 0xfee1250 | 0x3683c | 0x35c3c | 0x288 |
LoadCursorW | 0x0 | 0xfee1254 | 0x36840 | 0x35c40 | 0x1eb |
ScreenToClient | 0x0 | 0xfee1258 | 0x36844 | 0x35c44 | 0x26d |
ClientToScreen | 0x0 | 0xfee125c | 0x36848 | 0x35c48 | 0x47 |
GetWindowRect | 0x0 | 0xfee1260 | 0x3684c | 0x35c4c | 0x19c |
DestroyIcon | 0x0 | 0xfee1264 | 0x36850 | 0x35c50 | 0xa3 |
CopyIcon | 0x0 | 0xfee1268 | 0x36854 | 0x35c54 | 0x53 |
GetIconInfo | 0x0 | 0xfee126c | 0x36858 | 0x35c58 | 0x133 |
LoadImageW | 0x0 | 0xfee1270 | 0x3685c | 0x35c5c | 0x1ef |
GetClassNameW | 0x0 | 0xfee1274 | 0x36860 | 0x35c60 | 0x112 |
GetForegroundWindow | 0x0 | 0xfee1278 | 0x36864 | 0x35c64 | 0x12d |
ReleaseCapture | 0x0 | 0xfee127c | 0x36868 | 0x35c68 | 0x264 |
SetCapture | 0x0 | 0xfee1280 | 0x3686c | 0x35c6c | 0x280 |
GetCapture | 0x0 | 0xfee1284 | 0x36870 | 0x35c70 | 0x108 |
EqualRect | 0x0 | 0xfee1288 | 0x36874 | 0x35c74 | 0xf3 |
EndPaint | 0x0 | 0xfee128c | 0x36878 | 0x35c78 | 0xdc |
BeginPaint | 0x0 | 0xfee1290 | 0x3687c | 0x35c7c | 0xe |
GetUpdateRect | 0x0 | 0xfee1294 | 0x36880 | 0x35c80 | 0x187 |
GetCursorPos | 0x0 | 0xfee1298 | 0x36884 | 0x35c84 | 0x120 |
DefWindowProcW | 0x0 | 0xfee129c | 0x36888 | 0x35c88 | 0x9c |
RegisterClassExW | 0x0 | 0xfee12a0 | 0x3688c | 0x35c8c | 0x24d |
GetClassInfoExW | 0x0 | 0xfee12a4 | 0x36890 | 0x35c90 | 0x10d |
UnregisterClassW | 0x0 | 0xfee12a8 | 0x36894 | 0x35c94 | 0x306 |
SetWindowLongW | 0x0 | 0xfee12ac | 0x36898 | 0x35c98 | 0x2c4 |
IsWindow | 0x0 | 0xfee12b0 | 0x3689c | 0x35c9c | 0x1db |
CreateWindowExW | 0x0 | 0xfee12b4 | 0x368a0 | 0x35ca0 | 0x6e |
PostMessageW | 0x0 | 0xfee12b8 | 0x368a4 | 0x35ca4 | 0x236 |
SendMessageW | 0x0 | 0xfee12bc | 0x368a8 | 0x35ca8 | 0x27c |
GetWindow | 0x0 | 0xfee12c0 | 0x368ac | 0x35cac | 0x18e |
RegisterWindowMessageW | 0x0 | 0xfee12c4 | 0x368b0 | 0x35cb0 | 0x263 |
SetWindowPos | 0x0 | 0xfee12c8 | 0x368b4 | 0x35cb4 | 0x2c6 |
GetMonitorInfoW | 0x0 | 0xfee12cc | 0x368b8 | 0x35cb8 | 0x15f |
MonitorFromPoint | 0x0 | 0xfee12d0 | 0x368bc | 0x35cbc | 0x218 |
MonitorFromWindow | 0x0 | 0xfee12d4 | 0x368c0 | 0x35cc0 | 0x21a |
InvertRect | 0x0 | 0xfee12d8 | 0x368c4 | 0x35cc4 | 0x1c0 |
IsRectEmpty | 0x0 | 0xfee12dc | 0x368c8 | 0x35cc8 | 0x1d4 |
SetWindowRgn | 0x0 | 0xfee12e0 | 0x368cc | 0x35ccc | 0x2c7 |
FillRect | 0x0 | 0xfee12e4 | 0x368d0 | 0x35cd0 | 0xf6 |
ToUnicode | 0x0 | 0xfee12e8 | 0x368d4 | 0x35cd4 | 0x2f3 |
GetKeyboardState | 0x0 | 0xfee12ec | 0x368d8 | 0x35cd8 | 0x142 |
SetCaretPos | 0x0 | 0xfee12f0 | 0x368dc | 0x35cdc | 0x282 |
GetCaretPos | 0x0 | 0xfee12f4 | 0x368e0 | 0x35ce0 | 0x10a |
DestroyWindow | 0x0 | 0xfee12f8 | 0x368e4 | 0x35ce4 | 0xa6 |
IntersectRect | 0x0 | 0xfee12fc | 0x368e8 | 0x35ce8 | 0x1bd |
GetPropW | 0x0 | 0xfee1300 | 0x368ec | 0x35cec | 0x16b |
RemovePropW | 0x0 | 0xfee1304 | 0x368f0 | 0x35cf0 | 0x269 |
UpdateWindow | 0x0 | 0xfee1308 | 0x368f4 | 0x35cf4 | 0x311 |
RedrawWindow | 0x0 | 0xfee130c | 0x368f8 | 0x35cf8 | 0x24a |
CallWindowProcW | 0x0 | 0xfee1310 | 0x368fc | 0x35cfc | 0x1e |
SetPropW | 0x0 | 0xfee1314 | 0x36900 | 0x35d00 | 0x2ad |
GetDC | 0x0 | 0xfee1318 | 0x36904 | 0x35d04 | 0x121 |
ReleaseDC | 0x0 | 0xfee131c | 0x36908 | 0x35d08 | 0x265 |
keybd_event | 0x0 | 0xfee1320 | 0x3690c | 0x35d0c | 0x330 |
MapVirtualKeyW | 0x0 | 0xfee1324 | 0x36910 | 0x35d10 | 0x208 |
GetClientRect | 0x0 | 0xfee1328 | 0x36914 | 0x35d14 | 0x114 |
GetWindowThreadProcessId | 0x0 | 0xfee132c | 0x36918 | 0x35d18 | 0x1a4 |
KillTimer | 0x0 | 0xfee1330 | 0x3691c | 0x35d1c | 0x1e3 |
SetTimer | 0x0 | 0xfee1334 | 0x36920 | 0x35d20 | 0x2bb |
SystemParametersInfoW | 0x0 | 0xfee1338 | 0x36924 | 0x35d24 | 0x2ec |
GetFocus | 0x0 | 0xfee133c | 0x36928 | 0x35d28 | 0x12c |
GetWindowLongW | 0x0 | 0xfee1340 | 0x3692c | 0x35d2c | 0x196 |
IMM32.dll (13)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImmGetCompositionFontW | 0x0 | 0xfee10e4 | 0x366d0 | 0x35ad0 | 0x34 |
ImmGetHotKey | 0x0 | 0xfee10e8 | 0x366d4 | 0x35ad4 | 0x41 |
ImmGetOpenStatus | 0x0 | 0xfee10ec | 0x366d8 | 0x35ad8 | 0x4a |
ImmSetOpenStatus | 0x0 | 0xfee10f0 | 0x366dc | 0x35adc | 0x77 |
ImmGetContext | 0x0 | 0xfee10f4 | 0x366e0 | 0x35ae0 | 0x38 |
ImmGetConversionStatus | 0x0 | 0xfee10f8 | 0x366e4 | 0x35ae4 | 0x3b |
ImmLockIMC | 0x0 | 0xfee10fc | 0x366e8 | 0x35ae8 | 0x5e |
ImmUnlockIMC | 0x0 | 0xfee1100 | 0x366ec | 0x35aec | 0x7e |
ImmSetConversionStatus | 0x0 | 0xfee1104 | 0x366f0 | 0x35af0 | 0x75 |
ImmLockIMCC | 0x0 | 0xfee1108 | 0x366f4 | 0x35af4 | 0x5f |
ImmUnlockIMCC | 0x0 | 0xfee110c | 0x366f8 | 0x35af8 | 0x7f |
ImmGetIMCCSize | 0x0 | 0xfee1110 | 0x366fc | 0x35afc | 0x43 |
ImmRequestMessageW | 0x0 | 0xfee1114 | 0x36700 | 0x35b00 | 0x6a |
COMDLG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetOpenFileNameW | 0x0 | 0xfee1054 | 0x36640 | 0x35a40 | 0xc |
Exports (5)
»
Api name | EAT Address | Ordinal |
---|---|---|
uiImeConfigure | 0x12f12 | 0x1 |
uiImeGetImeMenuItems | 0x12f6f | 0x2 |
uiImeWindowProc | 0x1302b | 0x3 |
uiInitialize | 0x12fb4 | 0x4 |
uiUninitialize | 0x12f79 | 0x5 |
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.garminwasted | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
c:\users\5p5nrg~1\appdata\local\temp\armui.ini | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
c:\windows\system32\logfiles\scm\5f5a18eb-dc73-4e45-a11c-b59043598412 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\2470470f-2634-478e-b181-571e98a789bb | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\4c8b01a2-11ff-4c41-848f-508ef4f00cf7 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\7afcc0ca-7121-422a-ab45-b0e8d599ff08 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_idx.db | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_96.db | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_256.db | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\b2945f6a-2378-4a2d-a700-f64d33f40fe5 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\2470470f-2634-478e-b181-571e98a789bb | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\b2945f6a-2378-4a2d-a700-f64d33f40fe5 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\4c8b01a2-11ff-4c41-848f-508ef4f00cf7 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\9435f817-fed2-454e-88cd-7f78fda62c48 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrg~1\appdata\local\temp\adobearm.log | Modified File | Text |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\system.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\application.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\security.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-kernel-whea%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-grouppolicy%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-user profile service%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-offlinefiles%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-branchcachesmb%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-terminalservices-localsessionmanager%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-dhcpv6-client%4admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\explorerstartuplog_runonce.etl | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\BOOTSECT.BAK.garminwasted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\BOOTSECT.BAK.garminwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.garminwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.garminwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.garminwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.garminwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.garminwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.garminwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.garminwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.garminwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.garminwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.garminwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.garminwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.garminwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.garminwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.garminwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.garminwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.garminwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.garminwasted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.garminwasted_info | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.garminwasted_info | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows\serviceprofiles\localservice\appdata\local\lastalive0.dat | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows\serviceprofiles\localservice\appdata\local\lastalive1.dat | Dropped File | Stream |
Unknown
|
...
|
»