VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
gfvrib.exe
Windows Exe (x86-32)
Created at 2019-09-02T23:39:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gfvrib.exe | Sample File | Binary |
Blacklisted
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-08-31 18:16 (UTC+2) |
Last Seen | 2019-09-02 22:08 (UTC+2) |
Names | Win32.Trojan.Zenpak |
Families | Zenpak |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x401bc6 |
Size Of Code | 0x19a00 |
Size Of Initialized Data | 0x2ec9400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-12-04 11:00:39+00:00 |
Version Information (4)
»
FileVersionStart | 1.0.5.4 |
InternalName | fiubsiyfv.isi |
LegalCopyright | Copyright (C) 2019, fdgudfgv |
ProductVersion | 1.9.1 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x19957 | 0x19a00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.72 |
.rdata | 0x41b000 | 0x1d5ae | 0x1d600 | 0x19e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.54 |
.data | 0x439000 | 0x2ea64b0 | 0xc00 | 0x37400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.32 |
.gfids | 0x32e0000 | 0x111c | 0x400 | 0x38000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.19 |
.rsrc | 0x32e2000 | 0x3fb8 | 0x4000 | 0x38400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.16 |
.reloc | 0x32e6000 | 0x13e0 | 0x1400 | 0x3c400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.56 |
Imports (2)
»
KERNEL32.dll (80)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
lstrlenA | 0x0 | 0x41b010 | 0x37e60 | 0x36c60 | 0x54d |
DuplicateHandle | 0x0 | 0x41b014 | 0x37e64 | 0x36c64 | 0xe8 |
lstrcatA | 0x0 | 0x41b018 | 0x37e68 | 0x36c68 | 0x53e |
GetModuleHandleA | 0x0 | 0x41b01c | 0x37e6c | 0x36c6c | 0x215 |
ProcessIdToSessionId | 0x0 | 0x41b020 | 0x37e70 | 0x36c70 | 0x399 |
GetLastError | 0x0 | 0x41b024 | 0x37e74 | 0x36c74 | 0x202 |
CreateMutexW | 0x0 | 0x41b028 | 0x37e78 | 0x36c78 | 0x9e |
CloseHandle | 0x0 | 0x41b02c | 0x37e7c | 0x36c7c | 0x52 |
GetProcAddress | 0x0 | 0x41b030 | 0x37e80 | 0x36c80 | 0x245 |
lstrcpyW | 0x0 | 0x41b034 | 0x37e84 | 0x36c84 | 0x548 |
FormatMessageA | 0x0 | 0x41b038 | 0x37e88 | 0x36c88 | 0x15d |
GetTickCount | 0x0 | 0x41b03c | 0x37e8c | 0x36c8c | 0x293 |
GetCurrencyFormatA | 0x0 | 0x41b040 | 0x37e90 | 0x36c90 | 0x1b8 |
FlushFileBuffers | 0x0 | 0x41b044 | 0x37e94 | 0x36c94 | 0x157 |
PeekConsoleInputA | 0x0 | 0x41b048 | 0x37e98 | 0x36c98 | 0x38b |
GetSystemTimes | 0x0 | 0x41b04c | 0x37e9c | 0x36c9c | 0x27a |
GlobalAlloc | 0x0 | 0x41b050 | 0x37ea0 | 0x36ca0 | 0x2b3 |
GetHandleInformation | 0x0 | 0x41b054 | 0x37ea4 | 0x36ca4 | 0x1ff |
UnhandledExceptionFilter | 0x0 | 0x41b058 | 0x37ea8 | 0x36ca8 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x41b05c | 0x37eac | 0x36cac | 0x4a5 |
GetCurrentProcess | 0x0 | 0x41b060 | 0x37eb0 | 0x36cb0 | 0x1c0 |
TerminateProcess | 0x0 | 0x41b064 | 0x37eb4 | 0x36cb4 | 0x4c0 |
IsProcessorFeaturePresent | 0x0 | 0x41b068 | 0x37eb8 | 0x36cb8 | 0x304 |
QueryPerformanceCounter | 0x0 | 0x41b06c | 0x37ebc | 0x36cbc | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x41b070 | 0x37ec0 | 0x36cc0 | 0x1c1 |
GetCurrentThreadId | 0x0 | 0x41b074 | 0x37ec4 | 0x36cc4 | 0x1c5 |
GetSystemTimeAsFileTime | 0x0 | 0x41b078 | 0x37ec8 | 0x36cc8 | 0x279 |
InitializeSListHead | 0x0 | 0x41b07c | 0x37ecc | 0x36ccc | 0x2e7 |
IsDebuggerPresent | 0x0 | 0x41b080 | 0x37ed0 | 0x36cd0 | 0x300 |
GetStartupInfoW | 0x0 | 0x41b084 | 0x37ed4 | 0x36cd4 | 0x263 |
GetModuleHandleW | 0x0 | 0x41b088 | 0x37ed8 | 0x36cd8 | 0x218 |
EncodePointer | 0x0 | 0x41b08c | 0x37edc | 0x36cdc | 0xea |
RaiseException | 0x0 | 0x41b090 | 0x37ee0 | 0x36ce0 | 0x3b1 |
SetLastError | 0x0 | 0x41b094 | 0x37ee4 | 0x36ce4 | 0x473 |
RtlUnwind | 0x0 | 0x41b098 | 0x37ee8 | 0x36ce8 | 0x418 |
EnterCriticalSection | 0x0 | 0x41b09c | 0x37eec | 0x36cec | 0xee |
LeaveCriticalSection | 0x0 | 0x41b0a0 | 0x37ef0 | 0x36cf0 | 0x339 |
DeleteCriticalSection | 0x0 | 0x41b0a4 | 0x37ef4 | 0x36cf4 | 0xd1 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41b0a8 | 0x37ef8 | 0x36cf8 | 0x2e3 |
TlsAlloc | 0x0 | 0x41b0ac | 0x37efc | 0x36cfc | 0x4c5 |
TlsGetValue | 0x0 | 0x41b0b0 | 0x37f00 | 0x36d00 | 0x4c7 |
TlsSetValue | 0x0 | 0x41b0b4 | 0x37f04 | 0x36d04 | 0x4c8 |
TlsFree | 0x0 | 0x41b0b8 | 0x37f08 | 0x36d08 | 0x4c6 |
FreeLibrary | 0x0 | 0x41b0bc | 0x37f0c | 0x36d0c | 0x162 |
LoadLibraryExW | 0x0 | 0x41b0c0 | 0x37f10 | 0x36d10 | 0x33e |
GetStdHandle | 0x0 | 0x41b0c4 | 0x37f14 | 0x36d14 | 0x264 |
WriteFile | 0x0 | 0x41b0c8 | 0x37f18 | 0x36d18 | 0x525 |
GetModuleFileNameW | 0x0 | 0x41b0cc | 0x37f1c | 0x36d1c | 0x214 |
MultiByteToWideChar | 0x0 | 0x41b0d0 | 0x37f20 | 0x36d20 | 0x367 |
WideCharToMultiByte | 0x0 | 0x41b0d4 | 0x37f24 | 0x36d24 | 0x511 |
ExitProcess | 0x0 | 0x41b0d8 | 0x37f28 | 0x36d28 | 0x119 |
GetModuleHandleExW | 0x0 | 0x41b0dc | 0x37f2c | 0x36d2c | 0x217 |
GetACP | 0x0 | 0x41b0e0 | 0x37f30 | 0x36d30 | 0x168 |
HeapFree | 0x0 | 0x41b0e4 | 0x37f34 | 0x36d34 | 0x2cf |
HeapAlloc | 0x0 | 0x41b0e8 | 0x37f38 | 0x36d38 | 0x2cb |
LCMapStringW | 0x0 | 0x41b0ec | 0x37f3c | 0x36d3c | 0x32d |
GetFileType | 0x0 | 0x41b0f0 | 0x37f40 | 0x36d40 | 0x1f3 |
GetConsoleCP | 0x0 | 0x41b0f4 | 0x37f44 | 0x36d44 | 0x19a |
GetConsoleMode | 0x0 | 0x41b0f8 | 0x37f48 | 0x36d48 | 0x1ac |
ReadFile | 0x0 | 0x41b0fc | 0x37f4c | 0x36d4c | 0x3c0 |
SetFilePointerEx | 0x0 | 0x41b100 | 0x37f50 | 0x36d50 | 0x467 |
GetStringTypeW | 0x0 | 0x41b104 | 0x37f54 | 0x36d54 | 0x269 |
ReadConsoleW | 0x0 | 0x41b108 | 0x37f58 | 0x36d58 | 0x3be |
FindClose | 0x0 | 0x41b10c | 0x37f5c | 0x36d5c | 0x12e |
FindFirstFileExW | 0x0 | 0x41b110 | 0x37f60 | 0x36d60 | 0x134 |
FindNextFileW | 0x0 | 0x41b114 | 0x37f64 | 0x36d64 | 0x145 |
IsValidCodePage | 0x0 | 0x41b118 | 0x37f68 | 0x36d68 | 0x30a |
GetOEMCP | 0x0 | 0x41b11c | 0x37f6c | 0x36d6c | 0x237 |
GetCPInfo | 0x0 | 0x41b120 | 0x37f70 | 0x36d70 | 0x172 |
GetCommandLineA | 0x0 | 0x41b124 | 0x37f74 | 0x36d74 | 0x186 |
GetCommandLineW | 0x0 | 0x41b128 | 0x37f78 | 0x36d78 | 0x187 |
GetEnvironmentStringsW | 0x0 | 0x41b12c | 0x37f7c | 0x36d7c | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x41b130 | 0x37f80 | 0x36d80 | 0x161 |
SetStdHandle | 0x0 | 0x41b134 | 0x37f84 | 0x36d84 | 0x487 |
GetProcessHeap | 0x0 | 0x41b138 | 0x37f88 | 0x36d88 | 0x24a |
DecodePointer | 0x0 | 0x41b13c | 0x37f8c | 0x36d8c | 0xca |
WriteConsoleW | 0x0 | 0x41b140 | 0x37f90 | 0x36d90 | 0x524 |
HeapSize | 0x0 | 0x41b144 | 0x37f94 | 0x36d94 | 0x2d4 |
HeapReAlloc | 0x0 | 0x41b148 | 0x37f98 | 0x36d98 | 0x2d2 |
CreateFileW | 0x0 | 0x41b14c | 0x37f9c | 0x36d9c | 0x8f |
ADVAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DeleteService | 0x0 | 0x41b000 | 0x37e50 | 0x36c50 | 0xda |
StartServiceCtrlDispatcherW | 0x0 | 0x41b004 | 0x37e54 | 0x36c54 | 0x2c8 |
SetTokenInformation | 0x0 | 0x41b008 | 0x37e58 | 0x36c58 | 0x2c2 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x033E7578 | 0x033FA857 | Marked Executable | - | 32-bit | 0x033E7CBF |
![]() |
![]() |
...
|
buffer | 1 | 0x00020000 | 0x00036FFF | First Execution | - | 32-bit | 0x00020000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00020000 | 0x00036FFF | Content Changed | - | 32-bit | 0x000204F6 |
![]() |
![]() |
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3388679973-3930757225-3770151564-1000\fda992c8d564f97e48410a19a2e459f6_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.msi._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.msi._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.msi._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.msi._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\ShellUI.MST._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.msi._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.msi._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.msi._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.msi._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.msi._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.msi._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer\SIGNUP\install.ins | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Benioku.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Berime.htm._NEMTY_kGOBjgD_ | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\IrakHau.htm._NEMTY_kGOBjgD_ | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Leame.htm._NEMTY_kGOBjgD_ | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\LeesMij.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Leggimi.htm._NEMTY_kGOBjgD_ | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\LeiaMe.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Liesmich.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Lisezmoi.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Llegiu-me.htm._NEMTY_kGOBjgD_ | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\LueMinut.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Adobe.Reader.Dependencies.manifest._NEMTY_kGOBjgD_ | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\5p5nrgjn0js_halpmcxz@db-ip[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\_NEMTY_kGOBjgD_-DECRYPT.txt | Dropped File | Text |
Unknown
|
...
|
»