VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: | - |
Threat Names: |
Generic.Ransom.Ragnar.3E490C33
Generic.Ransom.Ragnar.9CB61097
|
iljueb.exe
Windows Exe (x86-32)
Created at 2020-04-23T12:57:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\iljueb.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402df0 |
Size Of Code | 0x6e00 |
Size Of Initialized Data | 0x5000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-04-06 19:57:20+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x6daf | 0x6e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.55 |
.rdata | 0x408000 | 0x14aa | 0x1600 | 0x7200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.31 |
.data | 0x40a000 | 0x35c | 0x0 | 0x0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.keys | 0x40b000 | 0x2e70 | 0x3000 | 0x8800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.55 |
.rsrc | 0x40e000 | 0x1e0 | 0x200 | 0xb800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.7 |
.reloc | 0x40f000 | 0x320 | 0x400 | 0xba00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.74 |
Imports (6)
»
KERNEL32.dll (70)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetFilePointerEx | 0x0 | 0x408068 | 0x8be8 | 0x7de8 | 0x467 |
FindClose | 0x0 | 0x40806c | 0x8bec | 0x7dec | 0x12e |
CloseHandle | 0x0 | 0x408070 | 0x8bf0 | 0x7df0 | 0x52 |
GetNativeSystemInfo | 0x0 | 0x408074 | 0x8bf4 | 0x7df4 | 0x225 |
GetTickCount | 0x0 | 0x408078 | 0x8bf8 | 0x7df8 | 0x293 |
MapViewOfFile | 0x0 | 0x40807c | 0x8bfc | 0x7dfc | 0x357 |
UnmapViewOfFile | 0x0 | 0x408080 | 0x8c00 | 0x7e00 | 0x4d6 |
lstrcmpiW | 0x0 | 0x408084 | 0x8c04 | 0x7e04 | 0x545 |
lstrcpyA | 0x0 | 0x408088 | 0x8c08 | 0x7e08 | 0x547 |
lstrcpyW | 0x0 | 0x40808c | 0x8c0c | 0x7e0c | 0x548 |
lstrcatW | 0x0 | 0x408090 | 0x8c10 | 0x7e10 | 0x53f |
lstrlenA | 0x0 | 0x408094 | 0x8c14 | 0x7e14 | 0x54d |
lstrlenW | 0x0 | 0x408098 | 0x8c18 | 0x7e18 | 0x54e |
CreateEventW | 0x0 | 0x40809c | 0x8c1c | 0x7e1c | 0x85 |
CreateFileMappingW | 0x0 | 0x4080a0 | 0x8c20 | 0x7e20 | 0x8c |
LoadLibraryW | 0x0 | 0x4080a4 | 0x8c24 | 0x7e24 | 0x33f |
CreateProcessW | 0x0 | 0x4080a8 | 0x8c28 | 0x7e28 | 0xa8 |
GetStartupInfoW | 0x0 | 0x4080ac | 0x8c2c | 0x7e2c | 0x263 |
GetCommandLineW | 0x0 | 0x4080b0 | 0x8c30 | 0x7e30 | 0x187 |
GetDriveTypeW | 0x0 | 0x4080b4 | 0x8c34 | 0x7e34 | 0x1d3 |
GetSystemDirectoryW | 0x0 | 0x4080b8 | 0x8c38 | 0x7e38 | 0x270 |
GetWindowsDirectoryW | 0x0 | 0x4080bc | 0x8c3c | 0x7e3c | 0x2af |
ReadFile | 0x0 | 0x4080c0 | 0x8c40 | 0x7e40 | 0x3c0 |
CreateFileW | 0x0 | 0x4080c4 | 0x8c44 | 0x7e44 | 0x8f |
SetFileAttributesW | 0x0 | 0x4080c8 | 0x8c48 | 0x7e48 | 0x461 |
GetFileAttributesW | 0x0 | 0x4080cc | 0x8c4c | 0x7e4c | 0x1ea |
FindFirstFileW | 0x0 | 0x4080d0 | 0x8c50 | 0x7e50 | 0x139 |
FindNextFileW | 0x0 | 0x4080d4 | 0x8c54 | 0x7e54 | 0x145 |
CopyFileW | 0x0 | 0x4080d8 | 0x8c58 | 0x7e58 | 0x75 |
MoveFileExW | 0x0 | 0x4080dc | 0x8c5c | 0x7e5c | 0x360 |
GetVolumeInformationA | 0x0 | 0x4080e0 | 0x8c60 | 0x7e60 | 0x2a5 |
GetVolumeInformationW | 0x0 | 0x4080e4 | 0x8c64 | 0x7e64 | 0x2a7 |
GetComputerNameW | 0x0 | 0x4080e8 | 0x8c68 | 0x7e68 | 0x18f |
FindFirstVolumeA | 0x0 | 0x4080ec | 0x8c6c | 0x7e6c | 0x13c |
FindNextVolumeA | 0x0 | 0x4080f0 | 0x8c70 | 0x7e70 | 0x147 |
FindVolumeClose | 0x0 | 0x4080f4 | 0x8c74 | 0x7e74 | 0x150 |
SetVolumeMountPointA | 0x0 | 0x4080f8 | 0x8c78 | 0x7e78 | 0x4aa |
GetVolumePathNamesForVolumeNameA | 0x0 | 0x4080fc | 0x8c7c | 0x7e7c | 0x2ac |
WTSGetActiveConsoleSessionId | 0x0 | 0x408100 | 0x8c80 | 0x7e80 | 0x4f4 |
MultiByteToWideChar | 0x0 | 0x408104 | 0x8c84 | 0x7e84 | 0x367 |
WideCharToMultiByte | 0x0 | 0x408108 | 0x8c88 | 0x7e88 | 0x511 |
GetLocaleInfoW | 0x0 | 0x40810c | 0x8c8c | 0x7e8c | 0x206 |
CreateToolhelp32Snapshot | 0x0 | 0x408110 | 0x8c90 | 0x7e90 | 0xbe |
Process32FirstW | 0x0 | 0x408114 | 0x8c94 | 0x7e94 | 0x396 |
Process32NextW | 0x0 | 0x408118 | 0x8c98 | 0x7e98 | 0x398 |
DeviceIoControl | 0x0 | 0x40811c | 0x8c9c | 0x7e9c | 0xdd |
WriteFile | 0x0 | 0x408120 | 0x8ca0 | 0x7ea0 | 0x525 |
GetFileSize | 0x0 | 0x408124 | 0x8ca4 | 0x7ea4 | 0x1f0 |
GetFileSizeEx | 0x0 | 0x408128 | 0x8ca8 | 0x7ea8 | 0x1f1 |
UnlockFile | 0x0 | 0x40812c | 0x8cac | 0x7eac | 0x4d4 |
LockFile | 0x0 | 0x408130 | 0x8cb0 | 0x7eb0 | 0x352 |
GetLogicalDrives | 0x0 | 0x408134 | 0x8cb4 | 0x7eb4 | 0x209 |
Sleep | 0x0 | 0x408138 | 0x8cb8 | 0x7eb8 | 0x4b2 |
WaitForMultipleObjects | 0x0 | 0x40813c | 0x8cbc | 0x7ebc | 0x4f7 |
WaitForSingleObject | 0x0 | 0x408140 | 0x8cc0 | 0x7ec0 | 0x4f9 |
GetLastError | 0x0 | 0x408144 | 0x8cc4 | 0x7ec4 | 0x202 |
CreateThread | 0x0 | 0x408148 | 0x8cc8 | 0x7ec8 | 0xb5 |
TerminateProcess | 0x0 | 0x40814c | 0x8ccc | 0x7ecc | 0x4c0 |
ExitProcess | 0x0 | 0x408150 | 0x8cd0 | 0x7ed0 | 0x119 |
GetCurrentProcess | 0x0 | 0x408154 | 0x8cd4 | 0x7ed4 | 0x1c0 |
OpenProcess | 0x0 | 0x408158 | 0x8cd8 | 0x7ed8 | 0x380 |
GetProcessHeap | 0x0 | 0x40815c | 0x8cdc | 0x7edc | 0x24a |
HeapFree | 0x0 | 0x408160 | 0x8ce0 | 0x7ee0 | 0x2cf |
HeapAlloc | 0x0 | 0x408164 | 0x8ce4 | 0x7ee4 | 0x2cb |
VirtualFree | 0x0 | 0x408168 | 0x8ce8 | 0x7ee8 | 0x4ec |
VirtualAlloc | 0x0 | 0x40816c | 0x8cec | 0x7eec | 0x4e9 |
LocalFree | 0x0 | 0x408170 | 0x8cf0 | 0x7ef0 | 0x348 |
LocalAlloc | 0x0 | 0x408174 | 0x8cf4 | 0x7ef4 | 0x344 |
GetFullPathNameW | 0x0 | 0x408178 | 0x8cf8 | 0x7ef8 | 0x1fb |
GetProcAddress | 0x0 | 0x40817c | 0x8cfc | 0x7efc | 0x245 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfA | 0x0 | 0x4081a0 | 0x8d20 | 0x7f20 | 0x332 |
wsprintfW | 0x0 | 0x4081a4 | 0x8d24 | 0x7f24 | 0x333 |
ADVAPI32.dll (20)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptGenRandom | 0x0 | 0x408000 | 0x8b80 | 0x7d80 | 0xc1 |
CryptReleaseContext | 0x0 | 0x408004 | 0x8b84 | 0x7d84 | 0xcb |
QueryServiceStatusEx | 0x0 | 0x408008 | 0x8b88 | 0x7d88 | 0x229 |
OpenServiceA | 0x0 | 0x40800c | 0x8b8c | 0x7d8c | 0x1fa |
OpenSCManagerA | 0x0 | 0x408010 | 0x8b90 | 0x7d90 | 0x1f8 |
EnumServicesStatusA | 0x0 | 0x408014 | 0x8b94 | 0x7d94 | 0xff |
EnumDependentServicesA | 0x0 | 0x408018 | 0x8b98 | 0x7d98 | 0xfc |
ControlService | 0x0 | 0x40801c | 0x8b9c | 0x7d9c | 0x5c |
CloseServiceHandle | 0x0 | 0x408020 | 0x8ba0 | 0x7da0 | 0x57 |
CryptEncrypt | 0x0 | 0x408024 | 0x8ba4 | 0x7da4 | 0xba |
CryptDestroyKey | 0x0 | 0x408028 | 0x8ba8 | 0x7da8 | 0xb7 |
CryptAcquireContextW | 0x0 | 0x40802c | 0x8bac | 0x7dac | 0xb1 |
RegQueryValueExW | 0x0 | 0x408030 | 0x8bb0 | 0x7db0 | 0x26e |
RegOpenKeyExW | 0x0 | 0x408034 | 0x8bb4 | 0x7db4 | 0x261 |
RegCloseKey | 0x0 | 0x408038 | 0x8bb8 | 0x7db8 | 0x230 |
DuplicateTokenEx | 0x0 | 0x40803c | 0x8bbc | 0x7dbc | 0xdf |
CreateProcessAsUserW | 0x0 | 0x408040 | 0x8bc0 | 0x7dc0 | 0x7c |
GetUserNameW | 0x0 | 0x408044 | 0x8bc4 | 0x7dc4 | 0x165 |
SetTokenInformation | 0x0 | 0x408048 | 0x8bc8 | 0x7dc8 | 0x2c2 |
OpenProcessToken | 0x0 | 0x40804c | 0x8bcc | 0x7dcc | 0x1f7 |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathW | 0x0 | 0x408184 | 0x8d04 | 0x7f04 | 0xe1 |
CommandLineToArgvW | 0x0 | 0x408188 | 0x8d08 | 0x7f08 | 0x6 |
SHLWAPI.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StrStrIA | 0x0 | 0x408190 | 0x8d10 | 0x7f10 | 0x144 |
PathFindExtensionW | 0x0 | 0x408194 | 0x8d14 | 0x7f14 | 0x47 |
StrToIntA | 0x0 | 0x408198 | 0x8d18 | 0x7f18 | 0x14b |
CRYPT32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptDecodeObjectEx | 0x0 | 0x408054 | 0x8bd4 | 0x7dd4 | 0x83 |
CryptStringToBinaryW | 0x0 | 0x408058 | 0x8bd8 | 0x7dd8 | 0xd9 |
CryptBinaryToStringA | 0x0 | 0x40805c | 0x8bdc | 0x7ddc | 0x7c |
CryptImportPublicKeyInfo | 0x0 | 0x408060 | 0x8be0 | 0x7de0 | 0xa4 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
iljueb.exe | 1 | 0x00C20000 | 0x00C2FFFF | First Execution | 32-bit | 0x00C22DF0 |
...
|
|||
iljueb.exe | 1 | 0x00C20000 | 0x00C2FFFF | Content Changed | 32-bit | 0x00C23403 |
...
|
|||
iljueb.exe | 1 | 0x00C20000 | 0x00C2FFFF | Content Changed | 32-bit | 0x00C21000 |
...
|
|||
iljueb.exe | 1 | 0x00C20000 | 0x00C2FFFF | Final Dump | 32-bit | 0x00C27D20 |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.Ragnar.3E490C33 |
Malicious
|
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.CNT.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.HLP | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\MTEXTRA.TTF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.CFG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\GIFIMP32.FLT | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\EPSIMP32.FLT | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\PNG32.FLT | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.WPG | Modified File | Binary |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG | Modified File | Binary |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.CGM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\JPEGIM32.FLT.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.FLT | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.FNT.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\MSOINTL.DLL.IDX_DLL | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\README.HTM | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\MSOINTL.REST.IDX_DLL | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\ADO210.CHM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUI.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUISet.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\ExcelMUI.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\GrooveMUI.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\InfoPathMUI.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\BRANDING.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OCT.CHM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUI.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.CHM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10R.CHM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\Office32MUI.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.WW\Office32WW.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\OneNoteMUI.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\OutlookMUI.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\ProjectMUI.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.en\Proof.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.es\Proof.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.fr\Proof.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\Proofing.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\PublisherMUI.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\VisioMUI.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\pkeyconfig-office.xrm-ms.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppobjs-spp-plugin-manifest-signed.xrm-ms.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPWMI.MOF.ragnar_FD7BD9FC | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_FR.LEX | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_ES.LEX.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\MCABOUT.HTM | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\STINTL.DLL.IDX_DLL | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\DATES.XML.ragnar_FD7BD9FC | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\PHONE.XML.ragnar_FD7BD9FC | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.DAT.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\TIME.XML.ragnar_FD7BD9FC | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\BASMLA.XSL | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT.ragnar_FD7BD9FC | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\RECOVR32.CNV | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\Wks9Pxy.cnv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\WPFT632.CNV | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\WPFT532.CNV.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\AFTRNOON.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\AFTRNOON.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\ARCTIC.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\ARCTIC.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\AXIS.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\AXIS.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\BLENDS.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\BLENDS.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\BLUECALM.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\BLUECALM.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\BLUEPRNT.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\BLUEPRNT.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\BOLDSTRI.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\BREEZE.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\BREEZE.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\CANYON.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\CANYON.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\CAPSULES.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\CAPSULES.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\CASCADE.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\CASCADE.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\COMPASS.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\COMPASS.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\CONCRETE.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\DEEPBLUE.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\DEEPBLUE.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\ECHO.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\ECHO.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\ECLIPSE.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\EDGE.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\EDGE.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\EVRGREEN.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\EVRGREEN.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\EXPEDITN.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\EXPEDITN.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\ICE.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\INDUST.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\INDUST.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\IRIS.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\RGNR_FD7BD9FC.txt | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\eqnedt32.exe.manifest.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\WPGIMP32.FLT.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\PICTIM32.FLT | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10O.CHM.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSCONFIG.CHM.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUISet.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\SETUP.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\PowerPointMUI.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\PrjProrWW.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\SETUP.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\ProPlusrWW.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\VisiorWW.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\WordMUI.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MUAUTH.CAB.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_EN.LEX | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\MSTAG.TLB.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\BOLDSTRI.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\CONCRETE.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\ECLIPSE.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\PREVIEW.GIF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\ICE.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\IRIS.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\JOURNAL.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»