Injector Spyware Ransomware
-
Created on 2022-04-23T04:16:00
a4fb180f23ce8454febb54cea71c28dedecb09823bee87b65aec3e144c7ad844.exe
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file Reputation Analysis requests per analysis (150) was exceeded.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\kEecfMwgj\Desktop\a4fb180f23ce8454febb54cea71c28dedecb09823bee87b65aec3e144c7ad844.exe | Sample File | Binary |
malicious
|
...
|
Verdict |
malicious
|
Image Base | 0x400000 |
Entry Point | 0x40ae1e |
Size Of Code | 0x9000 |
Size Of Initialized Data | 0xe000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-09-05 02:49:41+00:00 |
FileDescription | |
FileVersion | 0.0.0.0 |
InternalName | aqv33d4b.exe |
LegalCopyright | |
OriginalFilename | aqv33d4b.exe |
ProductVersion | 0.0.0.0 |
Assembly Version | 0.0.0.0 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x8e24 | 0x9000 | 0x1000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.51 |
.sdata | 0x40c000 | 0x6d | 0x1000 | 0xa000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.26 |
.rsrc | 0x40e000 | 0xb85c | 0xc000 | 0xb000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.72 |
.reloc | 0x41a000 | 0xc | 0x1000 | 0x17000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.01 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | - | 0x402000 | 0xadf4 | 0x9df4 | 0x0 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
a4fb180f23ce8454febb54cea71c28dedecb09823bee87b65aec3e144c7ad844.exe | 1 | 0x001D0000 | 0x001EBFFF | Relevant Image |
![]() |
32-bit | - |
![]() |
...
|
c:\programdata\microsoft\assistance\client\1.0\en-us\help_cvalidator.h1d.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\assistance\client\1.0\en-us\help_mkwd_assetid.h1w.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\assistance\client\1.0\en-us\help_mkwd_bestbet.h1w.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\assistance\client\1.0\en-us\help_mtoc_help.h1h.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\assistance\client\1.0\en-us\help_mvalidator.h1d.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\assistance\client\1.0\en-us\help_mvalidator.lck.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\assistance\client\1.0\en-us\help{9daa54e8-cd95-4107-8e7f-ba3f24732d95}.h1q.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\deploymentconfig.0.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\deploymentconfig.2.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\e728f99d-05d1-4020-9ece-6de2ec414166\en-us.16\masterdescriptor.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\e728f99d-05d1-4020-9ece-6de2ec414166\en-us.16\s321033.hash.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\e728f99d-05d1-4020-9ece-6de2ec414166\en-us.16\stream.x86.en-us.man.dat.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\e728f99d-05d1-4020-9ece-6de2ec414166\x-none.16\masterdescriptor.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\e728f99d-05d1-4020-9ece-6de2ec414166\x-none.16\s320.hash.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\e728f99d-05d1-4020-9ece-6de2ec414166\x-none.16\stream.x86.x-none.man.dat.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\deploymentconfiguration.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\manifest.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\userdeploymentconfiguration.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\usermanifest.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\airspace.etw.man.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.access.access.x-none.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.accessmui.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.accessmuiset.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.dcf.dcf.x-none.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.dcfmui.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.excel.excel.x-none.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.excelmui.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.groove.groove.x-none.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.groovemui.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.lync.lync.x-none.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.lyncmui.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.office64mui.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.office64muiset.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.office64ww.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.officemui.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.officemuiset.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.onenote.onenote.x-none.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.onenotemui.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osm.osm.x-none.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osmmui.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osmux.osmux.x-none.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osmuxmui.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.outlook.outlook.x-none.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.outlookmui.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.powerpivot.powerpivot.x-none.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.powerpoint.powerpoint.x-none.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.powerpointmui.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proof.culture.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proof.culture.msi.16.es-es.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proof.culture.msi.16.fr-fr.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proofing.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.publisher.publisher.x-none.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.publishermui.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.shared.office.x-none.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.word.word.x-none.msi.16.x-none.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.wordmui.msi.16.en-us.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\integrator.exe.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\microsoft_office_officetelemetryagentfallback2016.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\microsoft_office_officetelemetryagentlogon2016.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\msoutilstat.etw.man.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\wordetw.man.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-us\resource.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\folder.ico.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\netfol.ico.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pictures.ico.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\ringtones.ico.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\settings.ico.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\sync.ico.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\wmp.ico.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-us\resource.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\folder.ico.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_pref.ico.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_property.ico.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_queue.ico.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_.ico.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_property.ico.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_settings.ico.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\identitycrl\ppcrlconfig.dll.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\identitycrl\ppcrlui.dll.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\mf\active.grl.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\mf\pending.grl.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\officesoftwareprotectionplatform\cache\cache.dat.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\officesoftwareprotectionplatform\tokens.dat.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\gatherlogs\systemindex\systemindex.1.crwl.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\gatherlogs\systemindex\systemindex.1.gthr.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\mss.chk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\mss.log.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\mssres00001.jrs.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\mssres00002.jrs.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciab0001.000.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciab0001.001.ozq0 | Dropped File | Text |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciab0001.002.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciab0002.000.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciab0002.001.ozq0 | Dropped File | Text |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciab0002.002.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciad0001.000.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciad0001.001.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\ciad0001.002.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\index.000.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\index.001.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\index.002.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\indexer\cifiles\settings.dia.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\propmap\cipt0000.000.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\propmap\cipt0000.001.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\propmap\cipt0000.002.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\secstore\cist0000.000.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\secstore\cist0000.001.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\projects\systemindex\secstore\cist0000.002.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\search\data\applications\windows\windows.edb.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile10.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile11.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile12.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile13.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile14.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile15.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile16.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile17.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile18.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile19.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile20.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile21.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile22.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile23.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile24.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile25.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile26.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile27.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile28.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile29.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile30.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile31.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile32.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile33.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile34.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile35.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile36.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile37.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile38.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile39.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile40.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile41.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile42.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile43.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\default pictures\usertile44.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\guest.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\user account pictures\keecfmwgj.dat.ozq0 | Dropped File | Text |
clean
|
...
|
c:\programdata\microsoft\user account pictures\user.bmp.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\caches\cversions.2.db.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\caches\{228385d3-b646-481b-b0de-f0c3a58f5423}.2.ver0x0000000000000001.db.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\caches\{2f368d22-02bf-4413-97d1-c886cb140911}.2.ver0x0000000000000001.db.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\caches\{40fc8d7d-05ed-4feb-b03b-6c100659ef5c}.2.ver0x0000000000000001.db.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\caches\{4e4260a4-7e39-442e-bc22-7ff751d1c161}.2.ver0x0000000000000002.db.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\caches\{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x000000000000000a.db.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\caches\{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x000000000000000e.db.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\caches\{87178f01-581a-45f0-9991-3f918faa83f1}.2.ver0x0000000000000001.db.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\caches\{c353f91e-d25f-48f0-a2cd-9f60b2681e9a}.2.ver0x0000000000000001.db.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\caches\{ddf571f2-be98-426d-8288-1a9a39c3fda2}.2.ver0x0000000000000002.db.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\devicemetadatastore\en-us\34e548a8-3268-4dde-bedf-c40f9b6c814a.devicemetadata-ms.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\devicemetadatastore\en-us\63921eef-8415-4368-9201-f0df4af5778f.devicemetadata-ms.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\ringtones\desktop.ini.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\ringtones\ringtone 01.wma.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\ringtones\ringtone 02.wma.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\ringtones\ringtone 03.wma.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\ringtones\ringtone 04.wma.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\ringtones\ringtone 05.wma.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\ringtones\ringtone 06.wma.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\ringtones\ringtone 07.wma.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\ringtones\ringtone 08.wma.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\ringtones\ringtone 09.wma.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\ringtones\ringtone 10.wma.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\default programs.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\desktop.ini.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\access 2016.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\accessibility\desktop.ini.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\accessibility\speech recognition.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\calculator.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\desktop.ini.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\displayswitch.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\math input panel.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\mobility center.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\networkprojection.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\paint.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\remote desktop connection.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\snipping tool.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\sound recorder.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\sticky notes.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\sync center.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\system tools\character map.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\system tools\desktop.ini.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\system tools\dfrgui.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\system tools\disk cleanup.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\system tools\resource monitor.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\system tools\system information.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\system tools\system restore.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\system tools\task scheduler.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\system tools\windows easy transfer reports.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\system tools\windows easy transfer.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\tablet pc\desktop.ini.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\tablet pc\shapecollector.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\tablet pc\tabtip.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\tablet pc\windows journal.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\welcome center.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\windows powershell\desktop.ini.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\windows powershell\windows powershell (x86).lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\windows powershell\windows powershell ise (x86).lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\windows powershell\windows powershell ise.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\windows powershell\windows powershell.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\wordpad.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\administrative tools\component services.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\administrative tools\computer management.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\administrative tools\data sources (odbc).lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\administrative tools\desktop.ini.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\administrative tools\event viewer.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\administrative tools\iscsi initiator.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\administrative tools\memory diagnostics tool.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\administrative tools\performance monitor.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\administrative tools\print management.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\administrative tools\security configuration management.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\administrative tools\services.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\administrative tools\system configuration.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\administrative tools\task scheduler.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\administrative tools\windows firewall with advanced security.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\desktop.ini.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\excel 2016.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\games\desktop.ini.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\games\gameexplorer.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\maintenance\backup and restore center.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\maintenance\create recovery disc.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\maintenance\desktop.ini.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\maintenance\remote assistance.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\media center.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\database compare 2016.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\office 2016 language preferences.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\office 2016 upload center.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\skype for business recording manager.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\spreadsheet compare 2016.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\telemetry dashboard for office 2016.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2016 tools\telemetry log for office 2016.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\onedrive for business.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\onenote 2016.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\outlook 2016.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\powerpoint 2016.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\publisher 2016.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\sidebar.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\skype for business 2016.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\startup\desktop.ini.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\windows anytime upgrade.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\windows dvd maker.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\windows fax and scan.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\windows media player.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\word 2016.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\programs\xps viewer.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\start menu\windows update.lnk.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\wer\reportqueue\noncritical_x64_14581a24ae3cd03160d66be822236893de867_cab_07347da7\report.wer.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\wer\reportqueue\noncritical_x64_6924e027c982b3b48a48ab43378a2d3de936f9f1_cab_06ecd400\report.wer.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\wer\reportqueue\noncritical_x64_7ee33023ce28264d2338f4816fb96f7bae61c6a_cab_065c73f6\dmi73a8.tmp.log.xml.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\wer\reportqueue\noncritical_x64_7ee33023ce28264d2338f4816fb96f7bae61c6a_cab_065c73f6\report.wer.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows\wer\reportqueue\noncritical_x64_b26fb5ddb583b426ae5e125aec3cdbd84fab752_cab_0724ca6f\report.wer.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows defender\definition updates\{d2b0b133-42ed-44d3-809a-46ebb62ba863}\mpasbase.vdm.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows defender\definition updates\{d2b0b133-42ed-44d3-809a-46ebb62ba863}\mpasdlta.vdm.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows defender\definition updates\{d2b0b133-42ed-44d3-809a-46ebb62ba863}\mpengine.dll.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows defender\support\mplog-07132009-221054.log.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows nt\msfax\common coverpages\en-us\confident.cov.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows nt\msfax\common coverpages\en-us\fyi.cov.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows nt\msfax\common coverpages\en-us\generic.cov.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows nt\msfax\common coverpages\en-us\urgent.cov.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows nt\msfax\virtualinbox\en-us\welcomefax.tif.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\microsoft\windows nt\msscan\welcomescan.jpg.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\42d5bec7ddfbd49e76467529cbc2868987bf8460\packages\patch\x64\windows6.1-kb2999226-x64.msu.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\54050a5f8ae7f0c56e553f0090146c17a1d2bf8d\packages\patch\x64\windows6.1-kb2999226-x64.msu.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{0fa68574-690b-4b00-89aa-b28946231449}v14.25.28508\packages\vcruntimeadditional_x86\cab1.cab.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{0fa68574-690b-4b00-89aa-b28946231449}v14.25.28508\packages\vcruntimeadditional_x86\vc_runtimeadditional_x86.msi.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{13a4ee12-23ea-3371-91ee-efb36ddfff3e}v12.0.21005\packages\vcruntimeminimum_x86\cab1.cab.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{13a4ee12-23ea-3371-91ee-efb36ddfff3e}v12.0.21005\packages\vcruntimeminimum_x86\vc_runtimeminimum_x86.msi.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{2bc3bd4d-faba-4394-93c7-9ac82a263fe2}v14.25.28508\packages\vcruntimeminimum_x86\cab1.cab.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{2bc3bd4d-faba-4394-93c7-9ac82a263fe2}v14.25.28508\packages\vcruntimeminimum_x86\vc_runtimeminimum_x86.msi.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{37b8f9c7-03fb-3253-8781-2517c99d7c00}v11.0.61030\packages\vcruntimeadditional_amd64\cab1.cab.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{37b8f9c7-03fb-3253-8781-2517c99d7c00}v11.0.61030\packages\vcruntimeadditional_amd64\vc_runtimeadditional_x64.msi.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{3c3aafc8-d898-43ec-998f-965ffdae065a}\state.rsm.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{3c3aafc8-d898-43ec-998f-965ffdae065a}\vcredist_x64.exe.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{65e650ff-30be-469d-b63a-418d71ea1765}\state.rsm.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{65e650ff-30be-469d-b63a-418d71ea1765}\vc_redist.x86.exe.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{6913e92a-b64e-41c9-a5e6-cef39207fe89}\state.rsm.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{6913e92a-b64e-41c9-a5e6-cef39207fe89}\vc_redist.x64.exe.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{7d0b74c2-c3f8-4af1-940f-cd79ab4b2dce}v14.25.28508\packages\vcruntimeadditional_amd64\cab1.cab.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{7d0b74c2-c3f8-4af1-940f-cd79ab4b2dce}v14.25.28508\packages\vcruntimeadditional_amd64\vc_runtimeadditional_x64.msi.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{929fbd26-9020-399b-9a7a-751d61f0b942}v12.0.21005\packages\vcruntimeadditional_amd64\cab1.cab.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{929fbd26-9020-399b-9a7a-751d61f0b942}v12.0.21005\packages\vcruntimeadditional_amd64\vc_runtimeadditional_x64.msi.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{a749d8e6-b613-3be3-8f5f-045c84eba29b}v12.0.21005\packages\vcruntimeminimum_amd64\cab1.cab.ozq0 | Dropped File | Compressed |
clean
|
...
|
c:\programdata\package cache\{a749d8e6-b613-3be3-8f5f-045c84eba29b}v12.0.21005\packages\vcruntimeminimum_amd64\vc_runtimeminimum_x64.msi.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{b175520c-86a2-35a7-8619-86dc379688b9}v11.0.61030\packages\vcruntimeadditional_x86\cab1.cab.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{b175520c-86a2-35a7-8619-86dc379688b9}v11.0.61030\packages\vcruntimeadditional_x86\vc_runtimeadditional_x86.msi.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{bd95a8cd-1d9f-35ad-981a-3e7925026ebb}v11.0.61030\packages\vcruntimeminimum_x86\cab1.cab.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{bd95a8cd-1d9f-35ad-981a-3e7925026ebb}v11.0.61030\packages\vcruntimeminimum_x86\vc_runtimeminimum_x86.msi.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{cf2bea3c-26ea-32f8-aa9b-331f7e34ba97}v11.0.61030\packages\vcruntimeminimum_amd64\cab1.cab.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{cf2bea3c-26ea-32f8-aa9b-331f7e34ba97}v11.0.61030\packages\vcruntimeminimum_amd64\vc_runtimeminimum_x64.msi.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{e6e75766-da0f-4ba2-9788-6ea593ce702d}\state.rsm.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{e6e75766-da0f-4ba2-9788-6ea593ce702d}\vcredist_x86.exe.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{eea66967-97e2-4561-a999-5c22e3cde428}v14.25.28508\packages\vcruntimeminimum_amd64\cab1.cab.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{eea66967-97e2-4561-a999-5c22e3cde428}v14.25.28508\packages\vcruntimeminimum_amd64\vc_runtimeminimum_x64.msi.ozq0 | Dropped File | Stream |
clean
|
...
|
c:\programdata\package cache\{f8cfeb22-a2e7-3971-9eda-4b11edefc185}v12.0.21005\packages\vcruntimeadditional_x86\cab1.cab.ozq0 | Dropped File | Stream |
clean
|
...
|
C:\Users\kEecfMwgj\AppData\Roaming\Microsoft\Windows\Recent\ZUlgRx Jta9i.lnk.ozq0 | Dropped File | Unknown |
clean
|
...
|