Dynamic Analysis Report |
Classification: Ransomware |
2.exe
Created at 2019-06-03T16:07:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
Image Base | 0x400000 |
Entry Point | 0x428420 |
Size Of Code | 0x27a00 |
Size Of Initialized Data | 0x7200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-05-17 13:16:54+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x26bd4 | 0x26c00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.66 |
.itext | 0x428000 | 0xc80 | 0xe00 | 0x27000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.98 |
.data | 0x429000 | 0x19e8 | 0x1a00 | 0x27e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.19 |
.bss | 0x42b000 | 0x529c | 0x0 | 0x29800 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x431000 | 0x164c | 0x1800 | 0x29800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.84 |
.tls | 0x433000 | 0xc | 0x0 | 0x2b000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x434000 | 0x18 | 0x200 | 0x2b000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.21 |
.reloc | 0x435000 | 0x27b4 | 0x2800 | 0x2b200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.65 |
.rsrc | 0x438000 | 0x1600 | 0x1600 | 0x2da00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.73 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x4314ac | 0x31154 | 0x29954 | 0x0 |
SysReAllocStringLen | 0x0 | 0x4314b0 | 0x31158 | 0x29958 | 0x0 |
SysAllocStringLen | 0x0 | 0x4314b4 | 0x3115c | 0x2995c | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExA | 0x0 | 0x4314bc | 0x31164 | 0x29964 | 0x0 |
RegOpenKeyExA | 0x0 | 0x4314c0 | 0x31168 | 0x29968 | 0x0 |
RegCloseKey | 0x0 | 0x4314c4 | 0x3116c | 0x2996c | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetKeyboardType | 0x0 | 0x4314cc | 0x31174 | 0x29974 | 0x0 |
DestroyWindow | 0x0 | 0x4314d0 | 0x31178 | 0x29978 | 0x0 |
LoadStringA | 0x0 | 0x4314d4 | 0x3117c | 0x2997c | 0x0 |
MessageBoxA | 0x0 | 0x4314d8 | 0x31180 | 0x29980 | 0x0 |
CharNextA | 0x0 | 0x4314dc | 0x31184 | 0x29984 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetACP | 0x0 | 0x4314e4 | 0x3118c | 0x2998c | 0x0 |
Sleep | 0x0 | 0x4314e8 | 0x31190 | 0x29990 | 0x0 |
VirtualFree | 0x0 | 0x4314ec | 0x31194 | 0x29994 | 0x0 |
VirtualAlloc | 0x0 | 0x4314f0 | 0x31198 | 0x29998 | 0x0 |
GetTickCount | 0x0 | 0x4314f4 | 0x3119c | 0x2999c | 0x0 |
QueryPerformanceCounter | 0x0 | 0x4314f8 | 0x311a0 | 0x299a0 | 0x0 |
GetCurrentThreadId | 0x0 | 0x4314fc | 0x311a4 | 0x299a4 | 0x0 |
InterlockedDecrement | 0x0 | 0x431500 | 0x311a8 | 0x299a8 | 0x0 |
InterlockedIncrement | 0x0 | 0x431504 | 0x311ac | 0x299ac | 0x0 |
VirtualQuery | 0x0 | 0x431508 | 0x311b0 | 0x299b0 | 0x0 |
WideCharToMultiByte | 0x0 | 0x43150c | 0x311b4 | 0x299b4 | 0x0 |
MultiByteToWideChar | 0x0 | 0x431510 | 0x311b8 | 0x299b8 | 0x0 |
lstrlenA | 0x0 | 0x431514 | 0x311bc | 0x299bc | 0x0 |
lstrcpynA | 0x0 | 0x431518 | 0x311c0 | 0x299c0 | 0x0 |
LoadLibraryExA | 0x0 | 0x43151c | 0x311c4 | 0x299c4 | 0x0 |
GetThreadLocale | 0x0 | 0x431520 | 0x311c8 | 0x299c8 | 0x0 |
GetStartupInfoA | 0x0 | 0x431524 | 0x311cc | 0x299cc | 0x0 |
GetProcAddress | 0x0 | 0x431528 | 0x311d0 | 0x299d0 | 0x0 |
GetModuleHandleA | 0x0 | 0x43152c | 0x311d4 | 0x299d4 | 0x0 |
GetModuleFileNameA | 0x0 | 0x431530 | 0x311d8 | 0x299d8 | 0x0 |
GetLocaleInfoA | 0x0 | 0x431534 | 0x311dc | 0x299dc | 0x0 |
GetCommandLineA | 0x0 | 0x431538 | 0x311e0 | 0x299e0 | 0x0 |
FreeLibrary | 0x0 | 0x43153c | 0x311e4 | 0x299e4 | 0x0 |
FindFirstFileA | 0x0 | 0x431540 | 0x311e8 | 0x299e8 | 0x0 |
FindClose | 0x0 | 0x431544 | 0x311ec | 0x299ec | 0x0 |
ExitProcess | 0x0 | 0x431548 | 0x311f0 | 0x299f0 | 0x0 |
ExitThread | 0x0 | 0x43154c | 0x311f4 | 0x299f4 | 0x0 |
CreateThread | 0x0 | 0x431550 | 0x311f8 | 0x299f8 | 0x0 |
WriteFile | 0x0 | 0x431554 | 0x311fc | 0x299fc | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x431558 | 0x31200 | 0x29a00 | 0x0 |
RtlUnwind | 0x0 | 0x43155c | 0x31204 | 0x29a04 | 0x0 |
RaiseException | 0x0 | 0x431560 | 0x31208 | 0x29a08 | 0x0 |
GetStdHandle | 0x0 | 0x431564 | 0x3120c | 0x29a0c | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TlsSetValue | 0x0 | 0x43156c | 0x31214 | 0x29a14 | 0x0 |
TlsGetValue | 0x0 | 0x431570 | 0x31218 | 0x29a18 | 0x0 |
LocalAlloc | 0x0 | 0x431574 | 0x3121c | 0x29a1c | 0x0 |
GetModuleHandleA | 0x0 | 0x431578 | 0x31220 | 0x29a20 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TranslateMessage | 0x0 | 0x431580 | 0x31228 | 0x29a28 | 0x0 |
ReleaseDC | 0x0 | 0x431584 | 0x3122c | 0x29a2c | 0x0 |
PeekMessageA | 0x0 | 0x431588 | 0x31230 | 0x29a30 | 0x0 |
MsgWaitForMultipleObjects | 0x0 | 0x43158c | 0x31234 | 0x29a34 | 0x0 |
MessageBoxA | 0x0 | 0x431590 | 0x31238 | 0x29a38 | 0x0 |
LoadStringA | 0x0 | 0x431594 | 0x3123c | 0x29a3c | 0x0 |
LoadIconA | 0x0 | 0x431598 | 0x31240 | 0x29a40 | 0x0 |
GetSystemMetrics | 0x0 | 0x43159c | 0x31244 | 0x29a44 | 0x0 |
GetSysColor | 0x0 | 0x4315a0 | 0x31248 | 0x29a48 | 0x0 |
GetDC | 0x0 | 0x4315a4 | 0x3124c | 0x29a4c | 0x0 |
FillRect | 0x0 | 0x4315a8 | 0x31250 | 0x29a50 | 0x0 |
DispatchMessageA | 0x0 | 0x4315ac | 0x31254 | 0x29a54 | 0x0 |
CharNextW | 0x0 | 0x4315b0 | 0x31258 | 0x29a58 | 0x0 |
CharLowerBuffW | 0x0 | 0x4315b4 | 0x3125c | 0x29a5c | 0x0 |
CharNextA | 0x0 | 0x4315b8 | 0x31260 | 0x29a60 | 0x0 |
CharLowerBuffA | 0x0 | 0x4315bc | 0x31264 | 0x29a64 | 0x0 |
CharToOemA | 0x0 | 0x4315c0 | 0x31268 | 0x29a68 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
UnrealizeObject | 0x0 | 0x4315c8 | 0x31270 | 0x29a70 | 0x0 |
StretchBlt | 0x0 | 0x4315cc | 0x31274 | 0x29a74 | 0x0 |
SetTextColor | 0x0 | 0x4315d0 | 0x31278 | 0x29a78 | 0x0 |
SetStretchBltMode | 0x0 | 0x4315d4 | 0x3127c | 0x29a7c | 0x0 |
SetROP2 | 0x0 | 0x4315d8 | 0x31280 | 0x29a80 | 0x0 |
SetDIBColorTable | 0x0 | 0x4315dc | 0x31284 | 0x29a84 | 0x0 |
SetBrushOrgEx | 0x0 | 0x4315e0 | 0x31288 | 0x29a88 | 0x0 |
SetBkMode | 0x0 | 0x4315e4 | 0x3128c | 0x29a8c | 0x0 |
SetBkColor | 0x0 | 0x4315e8 | 0x31290 | 0x29a90 | 0x0 |
SelectPalette | 0x0 | 0x4315ec | 0x31294 | 0x29a94 | 0x0 |
SelectObject | 0x0 | 0x4315f0 | 0x31298 | 0x29a98 | 0x0 |
RealizePalette | 0x0 | 0x4315f4 | 0x3129c | 0x29a9c | 0x0 |
PatBlt | 0x0 | 0x4315f8 | 0x312a0 | 0x29aa0 | 0x0 |
MoveToEx | 0x0 | 0x4315fc | 0x312a4 | 0x29aa4 | 0x0 |
MaskBlt | 0x0 | 0x431600 | 0x312a8 | 0x29aa8 | 0x0 |
GetTextMetricsA | 0x0 | 0x431604 | 0x312ac | 0x29aac | 0x0 |
GetSystemPaletteEntries | 0x0 | 0x431608 | 0x312b0 | 0x29ab0 | 0x0 |
GetStockObject | 0x0 | 0x43160c | 0x312b4 | 0x29ab4 | 0x0 |
GetPixel | 0x0 | 0x431610 | 0x312b8 | 0x29ab8 | 0x0 |
GetPaletteEntries | 0x0 | 0x431614 | 0x312bc | 0x29abc | 0x0 |
GetObjectA | 0x0 | 0x431618 | 0x312c0 | 0x29ac0 | 0x0 |
GetDeviceCaps | 0x0 | 0x43161c | 0x312c4 | 0x29ac4 | 0x0 |
GetDIBits | 0x0 | 0x431620 | 0x312c8 | 0x29ac8 | 0x0 |
GetDIBColorTable | 0x0 | 0x431624 | 0x312cc | 0x29acc | 0x0 |
GetCurrentPositionEx | 0x0 | 0x431628 | 0x312d0 | 0x29ad0 | 0x0 |
GetBrushOrgEx | 0x0 | 0x43162c | 0x312d4 | 0x29ad4 | 0x0 |
DeleteObject | 0x0 | 0x431630 | 0x312d8 | 0x29ad8 | 0x0 |
DeleteDC | 0x0 | 0x431634 | 0x312dc | 0x29adc | 0x0 |
CreatePenIndirect | 0x0 | 0x431638 | 0x312e0 | 0x29ae0 | 0x0 |
CreatePalette | 0x0 | 0x43163c | 0x312e4 | 0x29ae4 | 0x0 |
CreateHalftonePalette | 0x0 | 0x431640 | 0x312e8 | 0x29ae8 | 0x0 |
CreateFontIndirectA | 0x0 | 0x431644 | 0x312ec | 0x29aec | 0x0 |
CreateDIBitmap | 0x0 | 0x431648 | 0x312f0 | 0x29af0 | 0x0 |
CreateDIBSection | 0x0 | 0x43164c | 0x312f4 | 0x29af4 | 0x0 |
CreateCompatibleDC | 0x0 | 0x431650 | 0x312f8 | 0x29af8 | 0x0 |
CreateCompatibleBitmap | 0x0 | 0x431654 | 0x312fc | 0x29afc | 0x0 |
CreateBrushIndirect | 0x0 | 0x431658 | 0x31300 | 0x29b00 | 0x0 |
CreateBitmap | 0x0 | 0x43165c | 0x31304 | 0x29b04 | 0x0 |
BitBlt | 0x0 | 0x431660 | 0x31308 | 0x29b08 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetOpenEnumA | 0x0 | 0x431668 | 0x31310 | 0x29b10 | 0x0 |
WNetEnumResourceA | 0x0 | 0x43166c | 0x31314 | 0x29b14 | 0x0 |
WNetCloseEnum | 0x0 | 0x431670 | 0x31318 | 0x29b18 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteFile | 0x0 | 0x431678 | 0x31320 | 0x29b20 | 0x0 |
WaitForSingleObject | 0x0 | 0x43167c | 0x31324 | 0x29b24 | 0x0 |
VirtualQuery | 0x0 | 0x431680 | 0x31328 | 0x29b28 | 0x0 |
SetFilePointer | 0x0 | 0x431684 | 0x3132c | 0x29b2c | 0x0 |
SetFileAttributesW | 0x0 | 0x431688 | 0x31330 | 0x29b30 | 0x0 |
SetEvent | 0x0 | 0x43168c | 0x31334 | 0x29b34 | 0x0 |
SetEndOfFile | 0x0 | 0x431690 | 0x31338 | 0x29b38 | 0x0 |
ResumeThread | 0x0 | 0x431694 | 0x3133c | 0x29b3c | 0x0 |
ResetEvent | 0x0 | 0x431698 | 0x31340 | 0x29b40 | 0x0 |
ReadFile | 0x0 | 0x43169c | 0x31344 | 0x29b44 | 0x0 |
MulDiv | 0x0 | 0x4316a0 | 0x31348 | 0x29b48 | 0x0 |
MoveFileW | 0x0 | 0x4316a4 | 0x3134c | 0x29b4c | 0x0 |
LeaveCriticalSection | 0x0 | 0x4316a8 | 0x31350 | 0x29b50 | 0x0 |
InitializeCriticalSection | 0x0 | 0x4316ac | 0x31354 | 0x29b54 | 0x0 |
GlobalUnlock | 0x0 | 0x4316b0 | 0x31358 | 0x29b58 | 0x0 |
GlobalReAlloc | 0x0 | 0x4316b4 | 0x3135c | 0x29b5c | 0x0 |
GlobalHandle | 0x0 | 0x4316b8 | 0x31360 | 0x29b60 | 0x0 |
GlobalLock | 0x0 | 0x4316bc | 0x31364 | 0x29b64 | 0x0 |
GlobalFree | 0x0 | 0x4316c0 | 0x31368 | 0x29b68 | 0x0 |
GlobalAlloc | 0x0 | 0x4316c4 | 0x3136c | 0x29b6c | 0x0 |
GetVersionExA | 0x0 | 0x4316c8 | 0x31370 | 0x29b70 | 0x0 |
GetThreadLocale | 0x0 | 0x4316cc | 0x31374 | 0x29b74 | 0x0 |
GetStdHandle | 0x0 | 0x4316d0 | 0x31378 | 0x29b78 | 0x0 |
GetProcAddress | 0x0 | 0x4316d4 | 0x3137c | 0x29b7c | 0x0 |
GetModuleHandleA | 0x0 | 0x4316d8 | 0x31380 | 0x29b80 | 0x0 |
GetModuleFileNameW | 0x0 | 0x4316dc | 0x31384 | 0x29b84 | 0x0 |
GetModuleFileNameA | 0x0 | 0x4316e0 | 0x31388 | 0x29b88 | 0x0 |
GetLocaleInfoA | 0x0 | 0x4316e4 | 0x3138c | 0x29b8c | 0x0 |
GetLocalTime | 0x0 | 0x4316e8 | 0x31390 | 0x29b90 | 0x0 |
GetLastError | 0x0 | 0x4316ec | 0x31394 | 0x29b94 | 0x0 |
GetFullPathNameA | 0x0 | 0x4316f0 | 0x31398 | 0x29b98 | 0x0 |
GetExitCodeThread | 0x0 | 0x4316f4 | 0x3139c | 0x29b9c | 0x0 |
GetEnvironmentVariableW | 0x0 | 0x4316f8 | 0x313a0 | 0x29ba0 | 0x0 |
GetEnvironmentVariableA | 0x0 | 0x4316fc | 0x313a4 | 0x29ba4 | 0x0 |
GetDriveTypeA | 0x0 | 0x431700 | 0x313a8 | 0x29ba8 | 0x0 |
GetDiskFreeSpaceA | 0x0 | 0x431704 | 0x313ac | 0x29bac | 0x0 |
GetDateFormatA | 0x0 | 0x431708 | 0x313b0 | 0x29bb0 | 0x0 |
GetCurrentThreadId | 0x0 | 0x43170c | 0x313b4 | 0x29bb4 | 0x0 |
GetCurrentProcess | 0x0 | 0x431710 | 0x313b8 | 0x29bb8 | 0x0 |
GetCommandLineW | 0x0 | 0x431714 | 0x313bc | 0x29bbc | 0x0 |
GetCPInfo | 0x0 | 0x431718 | 0x313c0 | 0x29bc0 | 0x0 |
InterlockedIncrement | 0x0 | 0x43171c | 0x313c4 | 0x29bc4 | 0x0 |
InterlockedExchange | 0x0 | 0x431720 | 0x313c8 | 0x29bc8 | 0x0 |
InterlockedDecrement | 0x0 | 0x431724 | 0x313cc | 0x29bcc | 0x0 |
FreeLibrary | 0x0 | 0x431728 | 0x313d0 | 0x29bd0 | 0x0 |
FormatMessageA | 0x0 | 0x43172c | 0x313d4 | 0x29bd4 | 0x0 |
FindNextFileW | 0x0 | 0x431730 | 0x313d8 | 0x29bd8 | 0x0 |
FindFirstFileW | 0x0 | 0x431734 | 0x313dc | 0x29bdc | 0x0 |
FindClose | 0x0 | 0x431738 | 0x313e0 | 0x29be0 | 0x0 |
FileTimeToLocalFileTime | 0x0 | 0x43173c | 0x313e4 | 0x29be4 | 0x0 |
FileTimeToDosDateTime | 0x0 | 0x431740 | 0x313e8 | 0x29be8 | 0x0 |
ExitProcess | 0x0 | 0x431744 | 0x313ec | 0x29bec | 0x0 |
EnumCalendarInfoA | 0x0 | 0x431748 | 0x313f0 | 0x29bf0 | 0x0 |
EnterCriticalSection | 0x0 | 0x43174c | 0x313f4 | 0x29bf4 | 0x0 |
DeleteFileW | 0x0 | 0x431750 | 0x313f8 | 0x29bf8 | 0x0 |
DeleteCriticalSection | 0x0 | 0x431754 | 0x313fc | 0x29bfc | 0x0 |
CreateProcessW | 0x0 | 0x431758 | 0x31400 | 0x29c00 | 0x0 |
CreateFileW | 0x0 | 0x43175c | 0x31404 | 0x29c04 | 0x0 |
CreateFileA | 0x0 | 0x431760 | 0x31408 | 0x29c08 | 0x0 |
CreateEventA | 0x0 | 0x431764 | 0x3140c | 0x29c0c | 0x0 |
CompareStringA | 0x0 | 0x431768 | 0x31410 | 0x29c10 | 0x0 |
CloseHandle | 0x0 | 0x43176c | 0x31414 | 0x29c14 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegSetValueExA | 0x0 | 0x431774 | 0x3141c | 0x29c1c | 0x0 |
RegQueryValueExA | 0x0 | 0x431778 | 0x31420 | 0x29c20 | 0x0 |
RegOpenKeyExA | 0x0 | 0x43177c | 0x31424 | 0x29c24 | 0x0 |
RegFlushKey | 0x0 | 0x431780 | 0x31428 | 0x29c28 | 0x0 |
RegCreateKeyExA | 0x0 | 0x431784 | 0x3142c | 0x29c2c | 0x0 |
RegCloseKey | 0x0 | 0x431788 | 0x31430 | 0x29c30 | 0x0 |
OpenProcessToken | 0x0 | 0x43178c | 0x31434 | 0x29c34 | 0x0 |
LookupPrivilegeValueA | 0x0 | 0x431790 | 0x31438 | 0x29c38 | 0x0 |
AdjustTokenPrivileges | 0x0 | 0x431794 | 0x3143c | 0x29c3c | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x43179c | 0x31444 | 0x29c44 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x4317a4 | 0x3144c | 0x29c4c | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SafeArrayPtrOfIndex | 0x0 | 0x4317ac | 0x31454 | 0x29c54 | 0x0 |
SafeArrayGetUBound | 0x0 | 0x4317b0 | 0x31458 | 0x29c58 | 0x0 |
SafeArrayGetLBound | 0x0 | 0x4317b4 | 0x3145c | 0x29c5c | 0x0 |
SafeArrayCreate | 0x0 | 0x4317b8 | 0x31460 | 0x29c60 | 0x0 |
VariantChangeType | 0x0 | 0x4317bc | 0x31464 | 0x29c64 | 0x0 |
VariantCopy | 0x0 | 0x4317c0 | 0x31468 | 0x29c68 | 0x0 |
VariantClear | 0x0 | 0x4317c4 | 0x3146c | 0x29c6c | 0x0 |
VariantInit | 0x0 | 0x4317c8 | 0x31470 | 0x29c70 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InternetReadFile | 0x0 | 0x4317d0 | 0x31478 | 0x29c78 | 0x0 |
InternetOpenA | 0x0 | 0x4317d4 | 0x3147c | 0x29c7c | 0x0 |
InternetConnectA | 0x0 | 0x4317d8 | 0x31480 | 0x29c80 | 0x0 |
InternetCloseHandle | 0x0 | 0x4317dc | 0x31484 | 0x29c84 | 0x0 |
HttpSendRequestA | 0x0 | 0x4317e0 | 0x31488 | 0x29c88 | 0x0 |
HttpOpenRequestA | 0x0 | 0x4317e4 | 0x3148c | 0x29c8c | 0x0 |
HttpAddRequestHeadersA | 0x0 | 0x4317e8 | 0x31490 | 0x29c90 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderLocation | 0x0 | 0x4317f0 | 0x31498 | 0x29c98 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetPathFromIDListW | 0x0 | 0x4317f8 | 0x314a0 | 0x29ca0 | 0x0 |
SHGetMalloc | 0x0 | 0x4317fc | 0x314a4 | 0x29ca4 | 0x0 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
2.exe | 1 | 0x00400000 | 0x00439FFF | Relevant Image | - | 32-bit | - |
...
|
||
2.exe | 1 | 0x00400000 | 0x00439FFF | Process Termination | - | 32-bit | - |
...
|
Threat Name | Severity |
---|---|
Gen:Win32.Malware.lKW@aOXq@A |
Malicious
|
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Text |
Unknown
|
...
|
MICROSOFT MICROSOFT .NET FRAMEWORK 4 WINDOWS MICROSOFT MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE WINDOWS MICROSOFT Microsoft Corporation ( ) . Microsoft Windows ( ) ( "") . . . . . . . . . 1. f0 . Microsoft www.support.microsoft.com/common/international.aspx . 2. f0 MICROSOFT .NET FRAMEWORK . . NET Framework ( " NET ."). . go.microsoft.com/fwlink/?LinkID=66406 . Microsoft Microsoft NET . go.microsoft.com/fwlink/?LinkID=66406 . |
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Text |
Unknown
|
...
|
TILLG TIL LICENSVILKR FOR MICROSOFT-SOFTWARE MICROSOFT .NET FRAMEWORK 4 TIL MICROSOFT WINDOWS-OPERATIVSYSTEM MICROSOFT .NET FRAMEWORK 4-KLIENTPROFIL TIL MICROSOFT WINDOWS-OPERATIVSYSTEM OG TILKNYTTEDE SPROGPAKKER Microsoft Corporation (eller, afhngigt af hvor De bor, et af dets associerede selskaber) licenserer dette tillg til Dem. Hvis De har licens til at bruge Microsoft Windows-operativsystemsoftware (som dette tillg glder for) ("softwaren"), m De anvende dette tillg. De m ikke bruge dette tillg, hvis De ikke har licens til softwaren. De m bruge en kopi af dette tillg sammen med hver gyldigt licenseret kopi af softwaren. De flgende licensvilkr beskriver yderligere vilkr for dette tillg. Disse vilkr og licensvilkrene for softwaren glder for brug af dette tillg. Hvis der er konflikt mellem disse, er det licensvilkrene til tillgget, der er gldende. Ved at tage tillgget i brug accepterer De disse vilkr. Sfremt De ikke kan acceptere vilkrene, har De ikke ret til at brug ... |
C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Text |
Unknown
|
...
|
ERGNZENDE LIZENZBESTIMMUNGEN FR MICROSOFT-SOFTWARE MICROSOFT .NET FRAMEWORK 4 FR MICROSOFT WINDOWS-BETRIEBSSYSTEM MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE FR MICROSOFT WINDOWS-BETRIEBSSYSTEM UND ZUGEHRIGE LANGUAGE PACKS Microsoft Corporation (oder eine andere Microsoft-Konzerngesellschaft, wenn diese an dem Ort, an dem Sie leben, die Software lizenziert) lizenziert diese Softwareergnzung an Sie. Wenn Sie ber eine Lizenz fr Microsoft Windows-Betriebssystem-Software verfgen (fr die diese Softwareergnzung gilt) (die Software"), knnen Sie diese Softwareergnzung verwenden. Sie sind nicht berechtigt, sie zu verwenden, wenn Sie keine Lizenz fr die Software haben. Sie sind berechtigt, eine Kopie dieser Softwareergnzung mit jeder ordnungsgem lizenzierten Kopie der Software zu verwenden. In den folgenden Lizenzbestimmungen werden zustzliche Nutzungsbestimmungen fr diese Softwareergnzung beschrieben. Diese Bestimmungen und die Lizenzbestimmungen fr die Software gelten fr Ihre Verwendung der ... |
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
MICROSOFT MICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWS - MICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWS Microsoft Corporation ( , ) . Microsoft Windows ( ) ( ""), . . . . . , . , . , . , . 1. lang1032 . Microsoft , www.support.microsoft.com/common/international.aspx . 2. lang1032 MICROSOFT .NET FRAMEWORK. .NET Framework ( .NET). .~ , http://go.microsoft.com/fwlink/?LinkID=66406 . Microsoft, , Microsoft .NET, http://go.microsoft.com/fwlink/?LinkID=66406 . |
C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406&clcid=0x409 | - | - | - |
Unknown
|
Not Queried
|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
http://www.support.microsoft.com/common/international.aspx | - | - | - |
Unknown
|
Not Queried
|
MICROSOFT SOFTWARE SUPPLEMENTAL LICENSE TERMS MICROSOFT .NET FRAMEWORK 4 FOR MICROSOFT WINDOWS OPERATING SYSTEM MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE FOR MICROSOFT WINDOWS OPERATING SYSTEM AND ASSOCIATED LANGUAGE PACKS Microsoft Corporation (or based on where you live, one of its affiliates) licenses this supplement to you. If you are licensed to use Microsoft Windows operating system software (for which this supplement is applicable) (the "software"), you may use this supplement. You may not use it if you do not have a license for the software. You may use a copy of this supplement with each validly licensed copy of the software. The following license terms describe additional use terms for this supplement. These terms and the license terms for the software apply to your use of the supplement. If there is a conflict, these supplemental license terms apply. By using this supplement, you accept these terms. If you do not accept them, do not use this supplement. If yo ... |
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Text |
Unknown
|
...
|
MICROSOFT-OHJELMISTON TYDENNYSOSAN KYTTOIKEUSSOPIMUKSEN EHDOT MICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWS -KYTTJRJESTELMN MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE MICROSOFT WINDOWS -KYTTJRJESTELMN SEK NIIHIN LIITTYVT KIELIPAKETIT Microsoft Corporation (tai asiakkaan asuinpaikan mukaan mrytyv Microsoft Corporationin konserniyhti) mynt asiakkaalle tmn tydennysosan kyttoikeudet. Jos asiakkaalla on Microsoft Windows -kyttjrjestelmohjelmiston ("ohjelmisto") (jota tm tydennysosa tydent) kyttoikeudet, asiakas saa kytt tt tydennysosaa. Asiakas ei saa kytt tydennysosaa, jos asiakkaalla ei ole ohjelmiston kyttoikeutta. Asiakas saa kytt tmn tydennysosan kopiota kaikkien niiden ohjelmistosta tehtyjen kopioiden kanssa, joihin on voimassa olevat kyttoikeudet. Seuraavissa kyttoikeusehdoissa kuvataan tmn tydennysosan liskyttoikeusehtoja. Tydennysosan kyttn sovelletaan nit ehtoja ja ohjelmiston kyttoikeusehtoja. Jos ehdot ovat keskenn ristiriidassa, sovelletaan tydennysosan kyttoikeus ... |
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Text |
Unknown
|
...
|
TERMES DE CONTRAT DE LICENCE D'UN SUPPLMENT MICROSOFT MICROSOFT .NET FRAMEWORK~4 POUR LE SYSTME D'EXPLOITATION MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK~4 CLIENT PROFILE POUR LE SYSTME D'EXPLOITATION MICROSOFT WINDOWS ET LES LANGAGE PACKS ASSOCIS Microsoft Corporation (ou, en fonction du lieu o vous vivez, l'un de ses affilis) vous accorde une licence pour ce supplment. Si vous tes titulaire d'une licence d'utilisation du logiciel de systme d'exploitation Microsoft Windows (auquel s'applique le prsent supplment) (le ~logiciel~), vous tes autoris utiliser ce supplment. Vous n''eates pas autoris utiliser ce supplment si vous n''eates pas titulaire d'une licence pour le logiciel. Vous pouvez utiliser une copie de ce supplment avec chaque copie concde sous licence du logiciel. Les termes du contrat de licence suivants dcrivent les conditions d'utilisation supplmentaires pour le supplment. Les prsents termes et les termes du contrat de licence du logiciel s'appliquent l'uti ... |
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
MICROSOFT MICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWS Microsoft Corporation ( , ) . Microsoft Windows ( ) (""), . . . . . , . , . , . , . 1. f0 . Microsoft , www.support.microsoft.com/common/international.aspx . 2. f0 MICROSOFT .NET FRAMEWORK . .NET Framework ( .NET ). .~ .NET , http://go.microsoft.com/fwlink/?LinkID=66406 . Microsoft , , - Microsoft NET . , http://go.microsoft.com/fwlink/?LinkID=66406 . |
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406&clcid=0x409 | - | - | - |
Unknown
|
Not Queried
|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
KIEGSZT LICENCFELTTELEK MICROSOFT SZOFTVERHEZ MICROSOFT .NET-KERETRENDSZER 4 MICROSOFT WINDOWS OPERCIS RENDSZERHEZ MICROSOFT .NET-KERETRENDSZER 4 GYFLPROFIL MICROSOFT WINDOWS OPERCIS RENDSZERHEZ S A KAPCSOLD NYELVI CSOMAGOK Ezen kiegszts licenct a Microsoft Corporation (vagy az n lakhelye alapjn egy trsvllalata) nyjtja nnek. n akkor hasznlhatja ezt a kiegsztst, ha rendelkezik licenccel a (jelen kiegsztssel hasznlhat) Microsoft szoftver (a tovbbiakban szoftver") hasznlathoz. Amennyiben nem rendelkezik rvnyes licenccel a szoftverhez, gy nem hasznlhatja a kiegsztst. n a szoftver minden rvnyes licenccel elltott pldnyval hasznlhatja a kiegszts egy pldnyt. A kvetkez licencfelttelek tovbbi hasznlati feltteleket hatroznak meg a kiegsztshez. A kiegszts hasznlatra a szoftverre vonatkoz licencfelttelek s ezek a felttelek rvnyesek. Egymsnak ellentmond felttelek esetn ezen kiegszt licencfelttelek alkalmazandk. A kiegszts hasznlatval n elfogadja a jelen feltteleket. Amennyiben nem fo ... |
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
http://www.support.microsoft.com/common/international.aspx | - | - | - |
Unknown
|
Not Queried
|
CONDIZIONI DI LICENZA SOFTWARE MICROSOFT SUPPLEMENTARI MICROSOFT .NET FRAMEWORK 4 PER IL SISTEMA OPERATIVO MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE PER IL SISTEMA OPERATIVO MICROSOFT WINDOWS E RELATIVI LANGUAGE PACK Microsoft Corporation (o, in base al luogo di residenza del licenziatario, una delle sue consociate) concede in licenza al licenziatario il presente supplemento. Qualora il licenziatario sia autorizzato a utilizzare il software per il sistema operativo Microsoft Windows (per il quale il presente supplemento applicabile) (il "software"), potr usare il presente supplemento. Il licenziatario non potr utilizzarlo qualora non disponga di una licenza per il software. Il licenziatario potr utilizzare una copia del presente supplemento con ciascuna copia del software validamente concessa in licenza. Nelle condizioni di licenza che seguono sono descritte le condizioni di utilizzo aggiuntive relative al presente supplemento. Tali condizioni e le cond ... |
C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE LANGUAGE PACK Microsoft Corporation ( ) Microsoft Windows ( ) ( ) 1 1. lang1041 www.support.microsoft.com/common/international.aspx 2. f1 MICROSOFT .NET FRAMEWORK .NET Framework ( .NET ) 1 http://go.microsoft.com/fwlink/?LinkID=66406 go.microsoft.com/fwlink/?LinkID=66406 .NET |
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406&clcid=0x409 | - | - | - |
Unknown
|
Not Queried
|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
MICROSOFT MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE Microsoft Corporation( ) . Microsoft Windows (" ") . . . . . . . . . 1. lang1042 . Microsoft www.support.microsoft.com/common/international.aspx . 2. MICROSOFT .NET FRAMEWORK . .NET Framework (.NET ) . . http://go.microsoft.com/fwlink/?LinkID=66406 . , Microsoft Microsoft http://go.microsoft.com/fwlink/?LinkID=66406 .NET . |
C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Text |
Unknown
|
...
|
TILLEGGSLISENSVILKR FOR MICROSOFT-PROGRAMVARE MICROSOFT .NET FRAMEWORK 4 FOR MICROSOFT WINDOWS-OPERATIVSYSTEM MICROSOFT .NET FRAMEWORK 4-KLIENTPROFIL FOR MICROSOFT WINDOWS-OPERATIVSYSTEM OG TILKNYTTEDE SPRKPAKKER Microsoft Corporation (eller, avhengig av hvor du bor, et av dets tilknyttede selskaper) lisensierer dette tillegget til deg. Hvis du er lisensiert til bruke Microsoft Windows-operativsystemprogramvare (som dette tillegget gjelder for) ("programvaren"), har du rett til bruke dette tillegget. Du har ikke tillatelse til bruke det hvis du ikke har lisens for programvaren. Du kan bruke et eksemplar av dette tillegget sammen med hvert enkelt gyldig lisensierte eksemplar av programvaren. Flgende lisensvilkr beskriver ekstra brukervilkr for dette tillegget. Disse vilkrene og lisensvilkrene for programvaren gjelder din bruk av dette tillegget. Ved en eventuell konflikt er det disse tilleggsvilkrene som gjelder. Ved ta i bruk dette tillegget godtar du disse vilkrene ... |
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Text |
Unknown
|
...
|
UZUPENIAJCE POSTANOWIENIA LICENCYJNE DOTYCZCE OPROGRAMOWANIA MICROSOFT MICROSOFT .NET FRAMEWORK 4 DLA SYSTEMU OPERACYJNEGO MICROSOFT WINDOWS PROFIL KLIENTA PROGRAMU MICROSOFT .NET FRAMEWORK 4 DLA SYSTEMU OPERACYJNEGO MICROSOFT WINDOWS I POWIZANYCH PAKIETW JZYKOWYCH Microsoft Corporation (lub, w~zalenoci od miejsca zamieszkania Licencjobiorcy, jeden z~podmiotw stowarzyszonych Microsoft Corporation) udziela Licencjobiorcy licencji na to uzupenienie. Licencjobiorca moe z~niego korzysta, pod warunkiem e uzyska licencj na system operacyjny Microsoft Windows (oprogramowanie"). Licencjobiorca nie moe korzysta z~uzupenienia, jeli nie posiada licencji na to oprogramowanie. Licencjobiorca moe uywa kopii tego uzupenienia z~kad kopi oprogramowania, na ktr uzyska wan licencj. Poniej przedstawiono dodatkowe postanowienia licencyjne dotyczce uywania tego uzupenienia. Korzystanie z~uzupenienia podlega niniejszym uzupeniajcym postanowieniom licencyjnym oraz postanowieniom licencyjnym dot ... |
C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Text |
Unknown
|
...
|
Creator | karenor |
Revision | 2 |
Create Time | 2010-03-05 10:46:00+00:00 |
Modify Time | 2010-03-05 10:46:00+00:00 |
App Version | 32771 |
Company | Microsoft |
Page Count | 1 |
Word Count | 291 |
Character Count | 2340 |
Chars With Spaces | 2626 |
operator | karenor |
MICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE MICROSOFT WINDOWS ( LANGUAGE PACKS ) Microsoft ( , , ). , , ( ), Microsoft Windows. , . . . . , . , . , . , . 1. . Microsoft , www . support . microsoft . com / common / international . aspx ... |
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406&clcid=0x409 | - | - | - |
Unknown
|
Not Queried
|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
TILLGGSLICENSVILLKOR FR PROGRAMVARA FRN MICROSOFT MICROSOFT .NET FRAMEWORK 4 FR OPERATIVSYSTEMET MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE FR OPERATIVSYSTEMET MICROSOFT WINDOWS OCH ASSOCIERADE SPRKPAKET Microsoft Corporation (eller beroende p var du bor, ett av dess koncernbolag) licensierar detta tillgg till dig. Om du innehar licens fr programvara fr operativsystemet Microsoft Windows (som detta tillgg gller fr) ("programvaran") har du rtt att anvnda detta tillgg. Du fr inte anvnda tillgget om du inte har ngon licens fr programvaran. Du har rtt att anvnda ett exemplar av detta tillgg med varje giltigt licensierat exemplar av programvaran. Fljande licensvillkor beskriver ytterligare anvndningsvillkor fr detta tillgg. De hr villkoren och licensvillkoren fr programvaran gller fr din anvndning av tillgget. Om de str i konflikt med varandra gller dessa tillggslicensvillkor. Genom att anvnda detta tillgg accepterar du dessa villkor. Om du inte accepterar d ... |
C:\588bce7c90097ed212\1055\eula.rtf | Modified File | Text |
Unknown
|
...
|
MICROSOFT YAZILIM EK LSANS KOULLARI MICROSOFT WINDOWS LETM SSTEMLER N MICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWS LETM SSTEMLER N MICROSOFT .NET FRAMEWORK 4 STEMC PROFL VE LKL DL PAKETLER Microsoft Corporation (veya yaadnz yere gre bir bal irketi) bu ekin lisansn size vermektedir. Bu ekin geerli olduu Microsoft Windows iletim sistemi yazlmn ("yazlm") kullanma lisansnz varsa bu eki kullanabilirsiniz. Yazlm iin lisansnz yoksa bu eki kullanamazsnz. Bu ekin bir kopyasn yazlmn geerli lisans olan her kopyasyla kullanabilirsiniz. Aadaki lisans koullar, bu ek ile ilgili ek kullanm koullarn aklamaktadr. Eki kullanmnz, bu koullara ve yazlmn lisans koullarna tabidir. Bir ihtilaf olmas durumunda, bu ek lisans koullar geerlidir. Bu eki kullanmanz bu koullar kabul ettiiniz anlamna geli r. Bu koullar kabul etmiyorsanz, bu eki kullanmayn. Bu lisans koullarna uyduunuz takdirde aadaki haklara sahip olursunuz. 1. lang1055 EK N DESTEK HZMETLER. Microso ft, bu yazlm iin www.suppor ... |
C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Text |
Unknown
|
...
|
MICROSOFT MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE Microsoft Corporation Microsoft Corporation Microsoft Windows "lang2052"lang2052 1. lang2052 Microsoft www.support.microsoft.com/common/international.aspx 2. f0 MICROSOFT .NET FRAMEWORK .NET Framework ".NET "f1 go.microsoft.com/fwlink/?LinkID=66406 Microsoft Microsoft .NET go.microsoft.com/fwlink/?LinkID=66406 |
C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406&clcid=0x409 | - | - | - |
Unknown
|
Not Queried
|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
TERMOS DE LICENCIAMENTO SUPLEMENTARES PARA SOFTWARE MICROSOFT MICROSOFT .NET FRAMEWORK 4 PARA O SISTEMA OPERATIVO MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE PARA O SISTEMA OPERATIVO MICROSOFT WINDOWS E PACOTES DE IDIOMAS ASSOCIADOS A Microsoft Corporation (ou, dependendo do pas em que reside, uma das respectivas empresas afiliadas) licencia este suplemento para o Adquirente. Se o Adquirente estiver licenciado para utilizar software do sistema operativo Microsoft Windows (ao qual este suplemento se aplica)) (o "software"), poder utilizar este suplemento. O Adquirente no poder utiliz-lo se no tiver uma licena para o software. Poder utilizar uma cpia deste suplemento com cada cpia do software licenciada de modo vlido. Os seguintes termos de licena descrevem termos adicionais de utilizao deste suplemento. Estes termos e os termos de licenciamento para o software aplicam-se utilizao deste suplemento por parte do Adquirente. Caso se verifique um conflito, apl ... |
C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://go.microsoft.com/fwlink/?LinkID=66406 | - | - | - |
Unknown
|
Not Queried
|
MICROSOFT MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 Microsoft ( ) Microsoft Windows ( ) ( ) 1. lang1028 Microsoft www.support.microsoft.com/common/international.aspx 2. f0 MICROSOFT .NET FRAMEWORK .NET Framework (.NET ) http://go.microsoft.com/fwlink/?LinkID=66406 Microsoft http://go.microsoft.com/fwlink/?LinkID=66406 Microsoft .NET |
C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Text |
Unknown
|
...
|
TRMINOS DE LICENCIA COMPLEMENTARIOS DEL SOFTWARE DE MICROSOFT MICROSOFT .NET FRAMEWORK 4 PARA EL SISTEMA OPERATIVO MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE PARA EL SISTEMA OPERATIVO MICROSOFT WINDOWS Y PAQUETES DE IDIOMA ASSOCIADOS Microsoft Corporation (o, en funcin del lugar en el que resida, una de sus filiales) le concede la licencia para este complemento. Si obtiene la licencia para utilizar el sistema operativo Microsoft Windows (al que se aplica este suplemento), en adelante el "software", podr usar este suplemento. No puede usarlo si no dispone de licencia para el software. Puede utilizar una copia de este complemento con cada copia licenciada vlida del software. Los siguientes trminos de licencia describen los trminos de uso adicionales para este complemento. Dichos trminos y los trminos de licencia para el software se aplicarn al uso que haga del complemento. En caso de conflicto, prevalecern los presentes trminos de licencia complementarios. El uso d ... |
C:\Users\FD1HVy\Desktop\-IU8WGmE.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\-IU8WGmE.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\0 HFSllE7M55ZM.flv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\0 HFSllE7M55ZM.flv | Modified File | Stream |
Not Queried
|
...
|
c:\users\fd1hvy\appdata\local\virtualstore\bootnxt | Modified File | Stream |
Not Queried
|
...
|
C:\BOOTNXT.E5A57CBB-C8F5-8ECD-FBE7-0F42DE6C2FE2 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\0Vo-ly6biRdbFh.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\0Vo-ly6biRdbFh.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\1nAU21n.gif | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\1nAU21n.gif | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\1y GAOepHjz_GGuAnfUs.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\1y GAOepHjz_GGuAnfUs.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\2o0RvoNQH3Pnt6RW4e9V.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\2o0RvoNQH3Pnt6RW4e9V.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Text |
Not Queried
|
...
|
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\2TxEwTCTxw7fCarfd9s.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\2TxEwTCTxw7fCarfd9s.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\4tYgLFbf4vLGutZ Yr.xls | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\4tYgLFbf4vLGutZ Yr.xls | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\7AWcMCYzrmcSj02AOd.ods | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\7AWcMCYzrmcSj02AOd.ods | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\header.bmp | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\AL2c1H0uH2V75ObWn2WC.ots | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\AL2c1H0uH2V75ObWn2WC.ots | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Unknown |
Not Queried
|
...
|
C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\bIlOji97MBhWI.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\bIlOji97MBhWI.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Unknown |
Not Queried
|
...
|
C:\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\bvjvPicqNbxCUAF0jjb.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\bvjvPicqNbxCUAF0jjb.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Unknown |
Not Queried
|
...
|
C:\588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\BvpCYYHpcrUGg.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\BvpCYYHpcrUGg.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Unknown |
Not Queried
|
...
|
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\c88P_1gwS3beXz__x0G.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\c88P_1gwS3beXz__x0G.avi | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\netfx_Extended_x64.msi | Modified File | Unknown |
Not Queried
|
...
|
C:\588bce7c90097ed212\netfx_Extended_x64.msi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\Cc1dWs.flv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\Cc1dWs.flv | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Unknown |
Not Queried
|
...
|
C:\588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\CQt7uZQveV9 d-32SC.gif | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\CQt7uZQveV9 d-32SC.gif | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\czEq2jPbtoc-alsL.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\czEq2jPbtoc-alsL.avi | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Unknown |
Not Queried
|
...
|
C:\588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\dxaVbKx3o LR.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\dxaVbKx3o LR.png | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Unknown |
Not Queried
|
...
|
C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\Eezf.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\Eezf.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\f11Y6vzrSnRuG6gXdJyI.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\f11Y6vzrSnRuG6gXdJyI.wav | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\he_DSG.swf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\he_DSG.swf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Strings.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\IdcfNSdAI6EpKkJpB.doc | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\IdcfNSdAI6EpKkJpB.doc | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\K2N8lD.swf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\K2N8lD.swf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\watermark.bmp | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Unknown |
Not Queried
|
...
|
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\N5glZ_ot2BPg.swf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\N5glZ_ot2BPg.swf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Unknown |
Not Queried
|
...
|
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\NVChGlevkoRjEh-4.ppt | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\NVChGlevkoRjEh-4.ppt | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Unknown |
Not Queried
|
...
|
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\QsFi7A0Ff-4Zif40.flv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\QsFi7A0Ff-4Zif40.flv | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Unknown |
Not Queried
|
...
|
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\rqNverwPZv42JV.flv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\rqNverwPZv42JV.flv | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\SGkLqISAYkg22NMe.swf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\SGkLqISAYkg22NMe.swf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\T8ss-NNC6a.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\T8ss-NNC6a.png | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Text |
Not Queried
|
...
|
DODATKOV LICENN PODMNKY PRO SOFTWARE SPOLENOSTI MICROSOFT MICROSOFT .NET FRAMEWORK 4 PRO OPERAN SYSTM MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE PRO OPERAN SYSTM MICROSOFT WINDOWS A PIDRUEN JAZYKOV SADY Licenci k~tomuto dodatku vm poskytuje spolenost Microsoft Corporation (nebo nkter z~jejch afilac v~zvislosti na tom, kde bydlte). Mte-li licenci k uit operanho systmu Microsoft Windows (pro nj je tento dodatek uren) (software"), smte tento dodatek uvat. Tento dodatek nesmte uvat, pokud licenci k~softwaru nemte. Kopii tohoto dodatku smte uvat s~kadou platn licencovanou kopi softwaru. Nsledujc licenn podmnky popisuj dal podmnky uvn pro tento dodatek. Na vae uvn tohoto dodatku se vztahuj tyto podmnky a~li cenn podmnky pro software. V~ppad konfliktu plat tyto dodatkov licenn podmnky. Pouitm dodatku pijmte tyto podmnky. Pokud je nepijmte, dodatek nepouvejte. Dodrte-li tyto licenn podmnky, mte nsledujc prva. 1. f0 SLUBY TECHNICK PODPORY PRO DODATEK. Spo ... |
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\tps2Xi4Z_o.flv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\tps2Xi4Z_o.flv | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\Um03CTlTx2.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\Um03CTlTx2.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\UWyo BXoBgCXp.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\UWyo BXoBgCXp.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\vPNd5r.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\vPNd5r.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\WngvlI9HhGNFIHt.doc | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\WngvlI9HhGNFIHt.doc | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\XLMOBIDgt-65GJKBZs.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\XLMOBIDgt-65GJKBZs.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\yBv.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\yBv.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\za7tguGWEH8Un6nT2.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\za7tguGWEH8Un6nT2.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\LEC y1M\1XiaHqRLQcN.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\LEC y1M\1XiaHqRLQcN.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\LEC y1M\2t6b1Wgb.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\LEC y1M\2t6b1Wgb.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\LEC y1M\aHlckfoF9Df PJtrnP.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\LEC y1M\aHlckfoF9Df PJtrnP.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\LEC y1M\Br2U44.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\LEC y1M\Br2U44.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\LEC y1M\GQFmK U7yfly.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\LEC y1M\GQFmK U7yfly.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\LEC y1M\OOE5fKcEdsHQz8B4.ods | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\LEC y1M\OOE5fKcEdsHQz8B4.ods | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Text |
Not Queried
|
...
|
AANVULLENDE LICENTIEVOORWAARDEN VOOR MICROSOFT-SOFTWARE MICROSOFT .NET FRAMEWORK 4 VOOR HET BESTURINGSSYSTEEM MICROSOFT WINDOWS MICROSOFT .NET FRAMEWORK 4 CLIENT PROFILE VOOR HET BESTURINGSSYSTEEM MICROSOFT WINDOWS EN GERELATEERDE TAALPAKKETTEN Microsoft Corporation (of, afhankelijk uw locatie, een van haar gelieerde ondernemingen) geeft dit supplement aan u in licentie. Als u een licentie hebt voor het gebruik van Microsoft Windows-besturingssysteemsoftware (waarop dit supplement van toepassing is) (de 'software'), mag u dit supplement gebruiken. U mag dit supplement niet gebruiken als u niet over een licentie voor de software beschikt. U mag een exemplaar van dit supplement gebruiken bij elk geldig in licentie gegeven exemplaar van de software. De volgende licentievoorwaarden beschrijven aanvullende gebruiksvoorwaarden voor deze aanvulling. Deze voorwaarden zijn samen met de licentievoorwaarden voor de software van toepassing op uw gebruik van dit supplement. Als deze ... |
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\LEC y1M\se4L.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\LEC y1M\se4L.png | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Text |
Not Queried
|
...
|
TERMOS DE LICENA COMPLEMENTARES PARA SOFTWARE DA MICROSOFT MICROSOFT .NET FRAMEWORK 4 PARA SISTEMA OPERACIONAL MICROSOFT WINDOWS PERFIL DO CLIENTE DO MICROSOFT .NET FRAMEWORK 4 PARA SISTEMA OPERACIONAL MICROSOFT WINDOWS parE PACOTES DE IDIOMAS ASSOCIADOS A Microsoft Corporation (ou, dependendo do local em que voc esteja domiciliado, uma de suas afiliadas) fornece a voc a licena deste suplemento. Se voc possui a licena de uso do software do sistema operacional Microsoft Windows (ao qual este suplemento se aplica) (o "software"), pode usar este suplemento. Voc no poder us-lo se no possuir a licena para o software. Voc poder usar uma cpia deste suplemento com cada cpia licenciada vlida do software. Os termos de licena a seguir descrevem termos adicionais de uso deste suplemento. Estes termos e os termos da licena do software se aplicam ao uso do suplemento. Em caso de conflito, aplicar-se-o os termos de licena deste suplemento. O uso deste suplemento representa sua aceita ... |
C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1055\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\3076\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Text |
Not Queried
|
...
|
C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Print.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Print.ico | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate2.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate2.ico | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate4.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate4.ico | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate7.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate7.ico | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Save.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\warn.ico | Modified File | Image |
Not Queried
|
...
|
C:\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\HardwareEvents.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Internet Explorer.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\HardwareEvents.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\AppData\Local\Temp\800DA69A.buran | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\!!! YOUR FILES ARE ENCRYPTED !!!.TXT | Dropped File | Text |
Not Queried
|
...
|
WHOIS Domain Information
Domain Name | |
WHOIS Response |
This feature requires an online-connection to the VMRay backend.
An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".
Before
This feature requires an online-connection to the VMRay backend.
An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".
After
This feature requires an online-connection to the VMRay backend.
An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".