Malicious
Classifications
Ransomware
Threat Names
Mal/Generic-S Mal/HTMLGen-A Gen:Variant.Razy.326200
Dynamic Analysis Report
Created on 2021-04-18T17:44:00
CUsersGrujaDesktopca5751036a12d0.exe
Windows Exe (x86-32)
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\CUsersGrujaDesktopca5751036a12d0.exe | Sample File | Binary |
malicious
|
...
|
»
File Reputation Information
»
Verdict |
malicious
|
Names | Mal/Generic-S |
AV Matches (1)
»
Threat Name | Verdict |
---|---|
Gen:Variant.Razy.326200 |
malicious
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x409940 |
Size Of Code | 0xb800 |
Size Of Initialized Data | 0x6400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-09-18 01:33:32+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xb788 | 0xb800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.48 |
.rdata | 0x40d000 | 0x1b9c | 0x1c00 | 0xbc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.85 |
.data | 0x40f000 | 0x4174 | 0x3e00 | 0xd800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.94 |
.reloc | 0x414000 | 0x484 | 0x600 | 0x11600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.53 |
Imports (10)
»
Secur32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetUserNameExA | - | 0x40d150 | 0xe428 | 0xd028 | 0x1d |
WININET.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
HttpAddRequestHeadersA | - | 0x40d160 | 0xe438 | 0xd038 | 0x52 |
HttpSendRequestA | - | 0x40d164 | 0xe43c | 0xd03c | 0x5b |
InternetCloseHandle | - | 0x40d168 | 0xe440 | 0xd040 | 0x6b |
InternetOpenA | - | 0x40d16c | 0xe444 | 0xd044 | 0x97 |
HttpQueryInfoA | - | 0x40d170 | 0xe448 | 0xd048 | 0x59 |
InternetConnectA | - | 0x40d174 | 0xe44c | 0xd04c | 0x71 |
HttpOpenRequestA | - | 0x40d178 | 0xe450 | 0xd050 | 0x57 |
InternetCrackUrlA | - | 0x40d17c | 0xe454 | 0xd054 | 0x73 |
InternetReadFile | - | 0x40d180 | 0xe458 | 0xd058 | 0x9f |
SHLWAPI.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wnsprintfW | - | 0x40d13c | 0xe414 | 0xd014 | 0x16e |
StrStrIW | - | 0x40d140 | 0xe418 | 0xd018 | 0x145 |
PathFindExtensionW | - | 0x40d144 | 0xe41c | 0xd01c | 0x47 |
wnsprintfA | - | 0x40d148 | 0xe420 | 0xd020 | 0x16d |
MPR.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetCloseEnum | - | 0x40d110 | 0xe3e8 | 0xcfe8 | 0x10 |
WNetEnumResourceW | - | 0x40d114 | 0xe3ec | 0xcfec | 0x1c |
WNetOpenEnumW | - | 0x40d118 | 0xe3f0 | 0xcff0 | 0x3d |
WNetGetConnectionW | - | 0x40d11c | 0xe3f4 | 0xcff4 | 0x24 |
WNetAddConnection2W | - | 0x40d120 | 0xe3f8 | 0xcff8 | 0x6 |
KERNEL32.dll (58)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetVersionExW | - | 0x40d024 | 0xe2fc | 0xcefc | 0x2a4 |
CreateThread | - | 0x40d028 | 0xe300 | 0xcf00 | 0xb5 |
GetComputerNameExA | - | 0x40d02c | 0xe304 | 0xcf04 | 0x18d |
GetCommandLineW | - | 0x40d030 | 0xe308 | 0xcf08 | 0x187 |
GetVolumePathNamesForVolumeNameW | - | 0x40d034 | 0xe30c | 0xcf0c | 0x2ad |
SetVolumeMountPointW | - | 0x40d038 | 0xe310 | 0xcf10 | 0x4ab |
FindVolumeClose | - | 0x40d03c | 0xe314 | 0xcf14 | 0x150 |
FindNextVolumeW | - | 0x40d040 | 0xe318 | 0xcf18 | 0x14a |
GetModuleHandleA | - | 0x40d044 | 0xe31c | 0xcf1c | 0x215 |
GetModuleFileNameW | - | 0x40d048 | 0xe320 | 0xcf20 | 0x214 |
CreateMutexA | - | 0x40d04c | 0xe324 | 0xcf24 | 0x9b |
GetSystemInfo | - | 0x40d050 | 0xe328 | 0xcf28 | 0x273 |
GetLastError | - | 0x40d054 | 0xe32c | 0xcf2c | 0x202 |
GetCurrentThread | - | 0x40d058 | 0xe330 | 0xcf30 | 0x1c4 |
InterlockedIncrement | - | 0x40d05c | 0xe334 | 0xcf34 | 0x2ef |
InterlockedCompareExchange64 | - | 0x40d060 | 0xe338 | 0xcf38 | 0x2ea |
HeapAlloc | - | 0x40d064 | 0xe33c | 0xcf3c | 0x2cb |
HeapFree | - | 0x40d068 | 0xe340 | 0xcf40 | 0x2cf |
GetProcessHeap | - | 0x40d06c | 0xe344 | 0xcf44 | 0x24a |
GetQueuedCompletionStatus | - | 0x40d070 | 0xe348 | 0xcf48 | 0x25e |
Sleep | - | 0x40d074 | 0xe34c | 0xcf4c | 0x4b2 |
WriteFile | - | 0x40d078 | 0xe350 | 0xcf50 | 0x525 |
ReadFile | - | 0x40d07c | 0xe354 | 0xcf54 | 0x3c0 |
CloseHandle | - | 0x40d080 | 0xe358 | 0xcf58 | 0x52 |
lstrcatW | - | 0x40d084 | 0xe35c | 0xcf5c | 0x53f |
GetProcAddress | - | 0x40d088 | 0xe360 | 0xcf60 | 0x245 |
GetFileType | - | 0x40d08c | 0xe364 | 0xcf64 | 0x1f3 |
GetStdHandle | - | 0x40d090 | 0xe368 | 0xcf68 | 0x264 |
LoadLibraryA | - | 0x40d094 | 0xe36c | 0xcf6c | 0x33c |
MultiByteToWideChar | - | 0x40d098 | 0xe370 | 0xcf70 | 0x367 |
WideCharToMultiByte | - | 0x40d09c | 0xe374 | 0xcf74 | 0x511 |
FillConsoleOutputCharacterA | - | 0x40d0a0 | 0xe378 | 0xcf78 | 0x127 |
FillConsoleOutputAttribute | - | 0x40d0a4 | 0xe37c | 0xcf7c | 0x126 |
GetConsoleMode | - | 0x40d0a8 | 0xe380 | 0xcf80 | 0x1ac |
GetConsoleScreenBufferInfo | - | 0x40d0ac | 0xe384 | 0xcf84 | 0x1b2 |
SetConsoleScreenBufferSize | - | 0x40d0b0 | 0xe388 | 0xcf88 | 0x445 |
SetConsoleCursorPosition | - | 0x40d0b4 | 0xe38c | 0xcf8c | 0x431 |
SetConsoleTextAttribute | - | 0x40d0b8 | 0xe390 | 0xcf90 | 0x446 |
AllocConsole | - | 0x40d0bc | 0xe394 | 0xcf94 | 0x10 |
AttachConsole | - | 0x40d0c0 | 0xe398 | 0xcf98 | 0x17 |
WriteConsoleW | - | 0x40d0c4 | 0xe39c | 0xcf9c | 0x524 |
GetConsoleOutputCP | - | 0x40d0c8 | 0xe3a0 | 0xcfa0 | 0x1b0 |
ExitProcess | - | 0x40d0cc | 0xe3a4 | 0xcfa4 | 0x119 |
CreateIoCompletionPort | - | 0x40d0d0 | 0xe3a8 | 0xcfa8 | 0x94 |
PostQueuedCompletionStatus | - | 0x40d0d4 | 0xe3ac | 0xcfac | 0x38e |
GetLogicalDrives | - | 0x40d0d8 | 0xe3b0 | 0xcfb0 | 0x209 |
GetFileSizeEx | - | 0x40d0dc | 0xe3b4 | 0xcfb4 | 0x1f1 |
FindClose | - | 0x40d0e0 | 0xe3b8 | 0xcfb8 | 0x12e |
lstrcpyW | - | 0x40d0e4 | 0xe3bc | 0xcfbc | 0x548 |
lstrlenW | - | 0x40d0e8 | 0xe3c0 | 0xcfc0 | 0x54e |
GetDriveTypeW | - | 0x40d0ec | 0xe3c4 | 0xcfc4 | 0x1d3 |
CreateFileW | - | 0x40d0f0 | 0xe3c8 | 0xcfc8 | 0x8f |
FindFirstFileW | - | 0x40d0f4 | 0xe3cc | 0xcfcc | 0x139 |
FindNextFileW | - | 0x40d0f8 | 0xe3d0 | 0xcfd0 | 0x145 |
LocalFree | - | 0x40d0fc | 0xe3d4 | 0xcfd4 | 0x348 |
VirtualProtect | - | 0x40d100 | 0xe3d8 | 0xcfd8 | 0x4ef |
GetCurrentProcess | - | 0x40d104 | 0xe3dc | 0xcfdc | 0x1c0 |
FindFirstVolumeW | - | 0x40d108 | 0xe3e0 | 0xcfe0 | 0x13f |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfW | - | 0x40d158 | 0xe430 | 0xd030 | 0x333 |
ADVAPI32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OpenSCManagerW | - | 0x40d000 | 0xe2d8 | 0xced8 | 0x1f9 |
CloseServiceHandle | - | 0x40d004 | 0xe2dc | 0xcedc | 0x57 |
ControlService | - | 0x40d008 | 0xe2e0 | 0xcee0 | 0x5c |
EnumDependentServicesW | - | 0x40d00c | 0xe2e4 | 0xcee4 | 0xfd |
QueryServiceConfigW | - | 0x40d010 | 0xe2e8 | 0xcee8 | 0x224 |
OpenServiceW | - | 0x40d014 | 0xe2ec | 0xceec | 0x1fb |
GetUserNameA | - | 0x40d018 | 0xe2f0 | 0xcef0 | 0x164 |
EnumServicesStatusW | - | 0x40d01c | 0xe2f4 | 0xcef4 | 0x102 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CommandLineToArgvW | - | 0x40d134 | 0xe40c | 0xd00c | 0x6 |
ole32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoInitialize | - | 0x40d188 | 0xe460 | 0xd060 | 0x3e |
CoCreateInstance | - | 0x40d18c | 0xe464 | 0xd064 | 0x10 |
CoSetProxyBlanket | - | 0x40d190 | 0xe468 | 0xd068 | 0x63 |
OLEAUT32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantClear | 0x9 | 0x40d128 | 0xe400 | 0xd000 | - |
VariantInit | 0x8 | 0x40d12c | 0xe404 | 0xd004 | - |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
cusersgrujadesktopca5751036a12d0.exe | 1 | 0x008D0000 | 0x008E4FFF | Relevant Image |
![]() |
32-bit | 0x008DB9D0 |
![]() |
![]() |
...
|
cusersgrujadesktopca5751036a12d0.exe | 1 | 0x008D0000 | 0x008E4FFF | Content Changed |
![]() |
32-bit | 0x008D8000 |
![]() |
![]() |
...
|
cusersgrujadesktopca5751036a12d0.exe | 1 | 0x008D0000 | 0x008E4FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
\\?\C:\$Recycle.Bin\S-1-5-18\YOUR_FILES_ARE_ENCRYPTED.HTML | Dropped File | HTML |
suspicious
|
...
|
»
Extracted URLs (2)
»
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
http://nbzzb6sa6xuura2z.onion |
Not Queried
|
N/A
|
- |
...
|
http://ebwexiymbsib4rmw.onion |
Not Queried
|
N/A
|
- |
...
|
Extracted JavaScripts (1)
»
JavaScript #1
»
let text = {
en: `<h2> Whats Happen? </h2>
We got your documents and files encrypted and you cannot access them. To make sure we�re not bluffing just check out your files. Want to recover them? Just do what we instruct you to. If you fail to follow our recommendations, you will never see your files again. During each attack, we copy valuable commercial data. If the user doesn’t pay to us, we will either send those data to rivals, or publish them. GDPR. Don’t want to pay to us, pay 10x more to the government.
<h2> What Guarantees? </h2>
We’re doing our own business and never care about what you do. All we need is to earn. Should we be unfair guys, no one would work with us. So if you drop our offer we won’t take any offense but you’ll lose all of your data and files. How much time would it take to recover losses? You only may guess.
<h2> How do I access the website? </h2>
<ul>
<li><a href="https://torproject.org" target="_blank">Get TOR browser here</a></li>
<li><a href="http://ebwexiymbsib4rmw.onion/chat.html?32566078ed-daf6e535f2-16e53e7753-808865ae5d-81d764b11e-3f7615c15b-f694f39ad2-420bff9fd7">Go to our website</a></li>
</ul>`,
de: `<h2> Was ist gerade passiert? </h2>
Wir haben Ihre Dokumente und Dateien verschlüsselt und Sie können nicht mehr darauf zugreifen. Jeder Angriff wird von einer Kopie der kommerziellen Informationen begleitet. Um sicherzustellen, dass wir es ernst meinen, prüfen Sie einfach Ihre Dateien und Sie werden sehen. Möchten Sie sie wiederherstellen? Halten Sie sich einfach an unsere Anweisungen, um uns zu bezahlen. Tuen Sie dies nicht, werden Sie Ihre Dateien niemals wiedersehen. Im Falle einer Zahlungsverweigerung werden die Daten entweder an Wettbewerber verkauft oder in offenen Quellen bereitgestellt. GDPR. Wenn Sie uns nicht bezahlen möchten, zahlen Sie das Zehnfache an der Regierung.
<h2> Wie sollten Sie uns trauen ? </h2>
Wir machen unsere eigenen Geschäfte und kümmern uns nicht darum was Sie tunen. Wir müssen nur verdienen. Sollten wir einfach nur bluffen, würde niemand an uns zahlen. Wenn Sie unser Angebot ablehnen, werden Sie alle Ihre Daten für immer verlieren. Wie viel Zeit werden Sie brauchen um ihre Daten selber zu ersetzen ? Sie können es sich schon denken.
<h2> Unsere Forderungen </h2>
<ul>
<li><a href="https://torproject.org" target="_blank">Holen Sie sich den TOR-Browser hier</a></li>
<li><a href="http://ebwexiymbsib4rmw.onion/chat.html?32566078ed-daf6e535f2-16e53e7753-808865ae5d-81d764b11e-3f7615c15b-f694f39ad2-420bff9fd7">Gehen Sie auf unsere Website</a></li>
</ul>`,
fr: `<h2> Qu'est-ce qui vient de se passer? </h2>
Nous avons crypté vos documents et fichiers et vous ne pouvez pas y accéder. Chaque attaque est accompagnée d'une copie des informations commerciales. Pour vous assurer que nous ne bluffons pas. Voulez-vous les restaurer? Faites juste ce que nous vous demandons, pour nous payer. Si vous ne suivez pas nos recommandations, vous ne verrez plus jamais vos fichiers. En cas de refus de paiement - les données seront soit revendues à des concurrents, soit diffusées dans des sources ouvertes. GDPR. Si vous ne voulez pas nous payer, payez x10 fois le gouvernement.
<h2> Qu'en est-il des garanties? </h2>
Nous faisons nos propres affaires et ne nous soucions jamais de ce que vous faites. Tout ce dont nous avons besoin est de gagner de l'argent. Si nous devions être injustes, personne ne travaillerait avec nous. Donc, si vous abandonnez notre offre, nous ne prendrons aucune infraction, mais vous perdrez toutes vos données et vos fichiers. Combien de temps faudrait-il pour récupérer les pertes? Vous pouvez seulement deviner.
<h2> Comment puis-je accéder au site web? </h2>
<ul>
<li><a href="https://torproject.org" target="_blank">Téléchargez le navigateur TOR ici</a></li>
<li><a href="http://ebwexiymbsib4rmw.onion/chat.html?32566078ed-daf6e535f2-16e53e7753-808865ae5d-81d764b11e-3f7615c15b-f694f39ad2-420bff9fd7">Allez sur notre site web</a></li>
</ul>`,
es: `<h2> ¿Lo que de pasar? </h2>
Ya tenemos sus documentos y archivos encriptados y usted no puede acceder a ellos. Para asegurarse de que no estamos faroleando. ¿Quiere recuperarlos? Sólo haga lo que le indicamos. Si usted no sigue nuestras recomendaciones, usted nunca verá sus archivos. Durante cada ataque, copiamos los datos comerciales valiosos. Si el usuario no nos paga, enviaremos estos datos a sus rivales o los publicaremos. GDPR. No quiere pagarnos, paga 10 veces más al gobierno.
<h2> ¿Qué pasa con las garantías? </h2>
Estamos haciendo nuestro propio negocio y nunca nos importa lo que hace usted. Todo lo que necesitamos es ganar. Hay que ser injustos chicos, nadie trabajaría con nosotros. Entonces, si deja caer nuestras propuestas, no nos ofenderemos pero usted perderá todos sus datos y archivos. ¿Cuánto tiempo se requiere para recuperar las pérdidas? Sólo usted puede adivinar.
<h2> ¿Cómo acceder al sitio web? </h2>
<ul>
<li><a href="https://torproject.org" target="_blank">Obtenga el navegador TOR aquí</a></li>
<li><a href="http://ebwexiymbsib4rmw.onion/chat.html?32566078ed-daf6e535f2-16e53e7753-808865ae5d-81d764b11e-3f7615c15b-f694f39ad2-420bff9fd7">Vaya a nuestro sitio web</a></li>
</ul>`,
jp: `<h2> 何があったのですか? </h2>
ドキュメントとファイルを暗号化しました。 それらにアクセスすることはできません。 ブラフしないようにするには、 ファイルをチェックアウトして、すべてが。 それらを回復したいですか? ただや
る
指示すること。 指示に従わない場合、ファイルは二度と表示されません。 各攻撃中に、貴重な商用データをコピーします。 ユーザーが当社に支払わない場合は、それらのデータをライバルに送信するか、公開します。
<h2> 何が保証されますか ? </h2>
私たちは私たち自身のビジネスを行っており、あなたが何をするかを気にしません。 必要なのは稼ぐことだけです。 私たちが不公平な人である場合、誰も私たちと一緒に働くことはありません。 ですから、あなたが私たちの申し出をやめても、私たちは何の罪も犯しません
すべてのデータとファイルが失われます。 損失を回復するのにどれくらい時間がかかりますか? 推測するだけです。
<h2> Webサイトにアクセスするにはどうすればよいですか? </h2>
<ul>
<li><a href=" https://torproject.org " target="_blank">ここで TORブラウザを入手 </a></li>
<li><a href="http://ebwexiymbsib4rmw.onion/chat.html?32566078ed-daf6e535f2-16e53e7753-808865ae5d-81d764b11e-3f7615c15b-f694f39ad2-420bff9fd7">当社のウェブサイトにアクセス </a></li>
</ul>`
};
function sel_lang(event) {
let active = document.getElementsByClassName('is-active')[0];
active.classList.remove('is-active');
event.target.parentElement.classList.add('is-active');
let lang = event.target.getAttribute('data-lang');
let el = document.getElementById('text');
el.innerHTML = text[lang];
}
document.addEventListener("DOMContentLoaded", ()=>{
let el = document.getElementById('text');
el.innerHTML = text['en'];
});
c:\users\rdhj0cnfevzx\appdata\local\microsoft\windows\inetcache\counters.dat | Modified File | Unknown |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\4bad322a-c043-4ded-a97a-6fe0c4412fbe\en-us.16\stream.x86.en-us.man.dat.b52a6cc8fb7587f444c47df3b494ea273d8cb96d932f5714f89deff12500af29 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\4bad322a-c043-4ded-a97a-6fe0c4412fbe\en-us.16\masterdescriptor.en-us.xml.235cc25993f000e992314636c73d2f41d20d3da3eabd72395d1453bbc11f9e41 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\4bad322a-c043-4ded-a97a-6fe0c4412fbe\x-none.16\masterdescriptor.x-none.xml.dcff3d82d1b1ed9ba78e08c4292caff1e455c7f588d712bcdfc010adfe95300d | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\4bad322a-c043-4ded-a97a-6fe0c4412fbe\x-none.16\stream.x86.x-none.man.dat.6692d2404db80b31af2521527511e37531f5a60515884abcba3b987bd9f4023e | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\deploymentconfiguration.xml.c55c4cc3386d39ca67b7efc99f2afe6a87bb3727d6f6448ec1ee2a52f08af456 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\deploymentconfig.2.xml.23e6e799bc481ccb75186b6f590bcd776071f6f17ea585a13ff58529fdc5181b | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\deploymentconfig.0.xml.c2a50e74cbbce2d28d8fe1595662eb9da2e91d1b214115e0aa3f728475c0b167 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\manifest.xml.f193705816e2ae5cabaef6c93e9ed0bac5d2803827239c4815dae903ec0ce265 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\userdeploymentconfiguration.xml.612c781de413ab05b13d1571d3e4db38b349472b2abe56f096b1d8fcc9a8843b | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\usermanifest.xml.983e3b788a4dd401c68d88d8b1e8a17b56c5d03a4afce882ebb6c8b091a2ff0b | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.access.access.x-none.msi.16.x-none.xml.2a9c2240c096342679b02602a32dece74f3578d36dbb1ae260ce679aa85d0822 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.accessmui.msi.16.en-us.xml.af2903751d41dd605ac38fda596c6df6dd35ec61729dc97d1b1d0214737cea63 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.accessmuiset.msi.16.en-us.xml.4f044cad89a1720c2bbd364bfc640c46283e6f9d419fe0a6503497d594b8981f | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.dcf.dcf.x-none.msi.16.x-none.xml.05abd055f321c1f455a19fcea61c49f0f03b7e9783890e5b8b5984881e3dbc56 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.dcfmui.msi.16.en-us.xml.9c7c59af708a7cf4e2811d636746b9151bfab3f62a1639e894f634e643bbc829 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.excel.excel.x-none.msi.16.x-none.xml.590bafd8023fb2c08b6388cb451778cbfb1efa7ecf92692804b87c1e2bd8700d | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.excelmui.msi.16.en-us.xml.bc8d2d3d21cdf40a5b8e9b04479ba396ee5fdca1dfe0ea74d8d66fe1fc4ed117 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.groove.groove.x-none.msi.16.x-none.xml.91a660c1ba58544296520fa26c66c31679b68677a2bc88692825baaee991b55a | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.groovemui.msi.16.en-us.xml.6989212dcccacf940f0432bcd84f46751cc637bb1dc297fd8ef1cb7450ceaf58 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.lyncmui.msi.16.en-us.xml.6c9c72a264dfe42351ff8bd45dc69b215dc711029d3433452f6c233c2943086b | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.office64mui.msi.16.en-us.xml.4812f047be1161911fab8137a4df6a32bf0ac27ec6fb41974189f0e250f0fd25 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.office64muiset.msi.16.en-us.xml.6476b1f5c9ec68fa29ec3041285cf19575a68249fa9581078af2dfb6826ac864 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.office64ww.msi.16.x-none.xml.0d912e9f3b4b905333fa9c7a2b2595bd4015d2531e6002305bae24a17276280e | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.lync.lync.x-none.msi.16.x-none.xml.16f4e381e48d0162ee67461a5365ebac257148c9ddb30ee640c0b7f823854914 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.officemui.msi.16.en-us.xml.a745d989dd6e2fc25a95ca19f91ab5317830d83792361ab0a827b46a46020b39 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.officemuiset.msi.16.en-us.xml.8d9a543b57f9b91d99262495d368e23f537bcf6f72a149400d163cc63de67b4b | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.onenote.onenote.x-none.msi.16.x-none.xml.ca57fc1d02a891435e52e4b359361a0d9e02a777b7d8828f53ee9e6472155947 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.onenotemui.msi.16.en-us.xml.a8395fba273611b3dbb7295aee8b422cae600be98512484c65e089b79c19033c | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osm.osm.x-none.msi.16.x-none.xml.de14a6f512e6b7d0661c204b0f85acbb4c15376e9ba608b18d470d8772ae602d | Dropped File | Binary |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osmmui.msi.16.en-us.xml.e305005790b2be59e81a8183ace8e67ba5253af8a80207c47f3f014324edb026 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osmux.osmux.x-none.msi.16.x-none.xml.3aa7c3f06c702f5c1ebe88ccbb16a8a3a4dc5979cf70798fca87ba6392d8542d | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osmuxmui.msi.16.en-us.xml.ede9707dd16e2f753267c83192ed6df43086dbf39dcfbbf303747cc7e705236a | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.outlook.outlook.x-none.msi.16.x-none.xml.56538ccb850b5f89a694f1c43c2f98f716ea047b025b9ed24d6a55d0ec90f40f | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.outlookmui.msi.16.en-us.xml.893eb23ccaf9b37c110091634df95e35230584572330b8022eeaad03fad91054 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.powerpivot.powerpivot.x-none.msi.16.x-none.xml.e5889a30dd02959d351cff516a75e662aaed86dfb860c5f8d98972dbf4cc6236 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.powerpoint.powerpoint.x-none.msi.16.x-none.xml.7b83b07f21609a71a3fd4235e905a472d194facebb3a0c15a454b45a3191817e | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.powerpointmui.msi.16.en-us.xml.d3c8529ff6bf133eb9067bb9985d30a31728cf37e0c37803f1991ce4feda6b19 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proof.culture.msi.16.en-us.xml.c20683c0006d2655f4257ab56ba8b0480adb8a138ccf3fd50cd0f3712dc70378 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proof.culture.msi.16.es-es.xml.3ac02768eeea551ace188a88e79694b27effc72b1dd8004ee55dc60f3c5e5439 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proof.culture.msi.16.fr-fr.xml.a3d40fc656f90e65046dfc37d8cadb1300eea7404d69de8b1260ca70bdb23f24 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proofing.msi.16.en-us.xml.8e5e7fdbdeb1019e1f1af327d35157db6b53043004bcb0ee66b08bbda398cd3f | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.publisher.publisher.x-none.msi.16.x-none.xml.e3f9b213894f112b0c01978ccfcdf184d4e01a29bc765ef8f5403d6f08a0087b | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.publishermui.msi.16.en-us.xml.c16446b4e80f2ae98978cf024444cf109316d036d8758840ba3ef6481f259c7b | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.shared.office.x-none.msi.16.x-none.xml.4f944e8e1926bb94c9856018047341d9f95e4edde0201794e12796a3b149ad72 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.word.word.x-none.msi.16.x-none.xml.3934b8b27d27d3fcdb3151ac44d67db926a7b6fbe41be8629ab21c9ecfe2a735 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\microsoft_office_officetelemetryagentlogon2016.xml.fe211bebbdcfbcb19ed6fc1a41ad899e6c78d6e16775cac1d17fa61b0c4a9e74 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\microsoft_office_officetelemetryagentfallback2016.xml.0ffeb1c1b8d79e252d2afb77165ce2747e060017e160d17d37a0d16e33b83205 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.wordmui.msi.16.en-us.xml.91b947d80728256a3e2232cdb309e0088fa5a46db724dbceef51eac0d42f6c16 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\identitycrl\production\ppcrlconfig600.dll.cd14c12384a0f27fad30ccea50ba446ff3b2760079076387e2a1d21f68b72900 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\identitycrl\int\ppcrlconfig600.dll.9b76d51a5e286ab163f5a241f643dfd3efb2a387f1728d50e87158ca69cf1767 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{18dcffd4-37d6-4bc6-87e0-4266fdbb8e49}\customizations.xml.e9452abce27219a7f5efa7067eabeb88371a6626c6558fc4b1a0ed15b0fb8756 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{18dcffd4-37d6-4bc6-87e0-4266fdbb8e49}\prov\runtime.xml.0e7a4551c407f4b9b53a3f7562f5d06c94161d2e52e85cf88476a2b8e71bc71c | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{1e05dd5d-a022-46c5-963c-b20de341170f}\customizations.xml.97868653c4bd6b54e148f197b536bee7f241ed3aeb0dd6e6706a99afa0011038 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{23cb517f-5073-4e96-a202-7fe6122a2271}\customizations.xml.3937f94e11b3568aec37edcbcde859201ba8fa9123d01dc11b499ef133de3f3f | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\customizations.xml.138e6cbcf435fddccd4fcfabfd8fa7f8200e39554849e0aaca98fbf772426a02 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\prov\runtime.xml.e00a73b9f049acdb9c2c2e20048a6ce8795a662ea603cdb17bc7ebf9b03c6372 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{7a30a9be-737f-47a1-a541-6e7b0761ed19}\customizations.xml.29eef47def9fc159363b83176a127fe9d31ff7607f81e6b741670d86d4a68129 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{8fb7d64e-70fc-4f9d-89ee-d486817534df}\customizations.xml.24573de981c0717b812b75a2ceb24250474c6f059bd938193ed15754443d1b21 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{99b095d8-5959-4820-bea7-7448c8427b4e}\customizations.xml.94f5fefb71ade4e241d82cb4057f0ed268b2ec99ea6d0d9918db88393dfc8f2a | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{7a30a9be-737f-47a1-a541-6e7b0761ed19}\prov\runtime.xml.6aa9d8602584e7ee923656f3ff25311fe9171749b03854a8a76c810deeeadf4c | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{9aec5bda-1e87-46b3-bb96-1a01c606555e}\customizations.xml.74702a6d3cc5bfe65e66cb9f9a1d8f1061a30044752fcfd1e43eb8843a3d4f7b | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{9df6a4ed-fc16-48bf-8b24-6e2ad2bfcfea}\customizations.xml.a20e1b14e1aa84c10df5703feb5bdb1146185819bbb9132d109490faab168a7c | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{b0b9123d-7d7f-4c6b-9973-ceced46f2a09}\customizations.xml.5de914bbc4f858ba40e268dbeed7326c1eefb74f7ce073687fb876503a916c48 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{c5dc3753-b6c8-4057-b396-bf13d769311c}\customizations.xml.1a2ffef383cf6c4fa82be7ff8229eb81281cadd0e9878668836f8842302f470f | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{ee4aac98-c174-4941-82b1-d121e493e4fb}\customizations.xml.5a652dcbe919f507e7aa061c376886c457f27af57e0aad12a6af4ede7a11103d | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{f11899f2-71ec-4621-9997-e17ae2f6eb26}\customizations.xml.3c3777e125ae6a2a4cc36296c2a12e42ee436c89853fc88c99b08da8cda2e24e | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\customizations.xml.e817b911cf4e9b462c2f3aa22dc733f3e56499826724160357a4eaefc4ca3535 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\prov\runtime.xml.2bcbe6422fdef6778dc2ab1b655d664513b2ee5e2f1745751dcf7d02c464026a | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\user account pictures\user-192.png.6c1f84d131bf31daee6409a8027eab66dbe635e9a401ee46dfb60fb9a574e425 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\user account pictures\user.bmp.08510f7314c2c923a183d099e21d05c5c32824088aed51ecd59560ba76c32a76 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\user account pictures\guest.bmp.c2f66f9290edaaa108cdcc3b5cb4ed9540f486e1f47c6d3947b7bc92d5f32b62 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\user account pictures\guest.png.011d5b71ce830f11a020752fbb93997dd6b43f9feedc842f34017a6122497219 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\user account pictures\user.png.5704c4fb9a0a8563132c56988d69aa33f75c7e79c3b3b12ee1815ac022258c69 | Dropped File | Binary |
clean
|
...
|
»
c:\programdata\microsoft\windows defender\network inspection system\support\nislog.txt.b824a17ccb8b0cc3265c20d409ead7097419d22024a6ada953ce59e748dd614e | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\windows defender\scans\mpcache-9899dbe4d8bb3d253eb4f285757bebaf1581b50f.bin.3f22c47bd587bda830881836dae47518e8ae9e78dc24686f6632c1daf18e2578 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\windows defender\support\mplog-02112021-121950.log.1a4c5916f0518d555c60199e08b5a97240a621e94ac1fe8b301d6767a405bd1e | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\windows defender\support\mpwpptracing-02112021-121950-00000003-ffffffff.bin.ff89eb2a750463235aca5f84805aa0fd97f8d489e6388faa8cb0f4770fe55e3d | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\windows defender\support\mpwpptracing-02112021-122238-00000003-ffffffff.bin.c97c08c5bda6ca20873d7eb27e5cfed4f374d9dd26c9a5a951d757782ac2c875 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\windows defender\support\mpwpptracing-02112021-124618-00000003-ffffffff.bin.8434dbd73a6948fe33dba00a9ae02277b9ad7a898cb48318541cfc111c5f785f | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\microsoft\windows live\wlive48x48.png.0ba7776161bacf351e19eb9e8bb544cb531eac342681bd97dcc39bab5d6c6d69 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\package cache\{0fa68574-690b-4b00-89aa-b28946231449}v14.25.28508\packages\vcruntimeadditional_x86\cab1.cab.1f7353b686bb3874b7dcf70d397a2d391b0ae5183f7ba5d8c07c2dcdb0caca2f | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\package cache\{13a4ee12-23ea-3371-91ee-efb36ddfff3e}v12.0.21005\packages\vcruntimeminimum_x86\cab1.cab.8396badd3288d9fb15cea45161384fc4d4dfa16042c2b7758a8a04d31cd3ed62 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\package cache\{2bc3bd4d-faba-4394-93c7-9ac82a263fe2}v14.25.28508\packages\vcruntimeminimum_x86\cab1.cab.e01fda55bbdced16bde9f8cf62cbb915e0e79fd1d7f1623e421faed1ffb1d436 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\package cache\{37b8f9c7-03fb-3253-8781-2517c99d7c00}v11.0.61030\packages\vcruntimeadditional_amd64\cab1.cab.f73c8dadc880fd3e1f1e1ef8b3dea54d938bc56f338a80bea0ab60c31fc77243 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\package cache\{7d0b74c2-c3f8-4af1-940f-cd79ab4b2dce}v14.25.28508\packages\vcruntimeadditional_amd64\cab1.cab.70d1f2f7401e527306ec818f9ed326093c55d49b04d4a3c68b5c9fc28a951b03 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\package cache\{929fbd26-9020-399b-9a7a-751d61f0b942}v12.0.21005\packages\vcruntimeadditional_amd64\cab1.cab.99ed2c9fac46b8eb309bbbf1c555ed0250f019498554c787404d841e847a154a | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\package cache\{a749d8e6-b613-3be3-8f5f-045c84eba29b}v12.0.21005\packages\vcruntimeminimum_amd64\cab1.cab.543182c5b310aabcbb8805b614e14164430caa1da63d19b807ceb35ae10de67b | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\package cache\{b175520c-86a2-35a7-8619-86dc379688b9}v11.0.61030\packages\vcruntimeadditional_x86\cab1.cab.e5b0ec829362a8a7929d2e88c163b79fc4e0f0e3f6630f06e2dd2ef16d672146 | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\package cache\{bd95a8cd-1d9f-35ad-981a-3e7925026ebb}v11.0.61030\packages\vcruntimeminimum_x86\cab1.cab.b52d1c80c438b58bbb8d0842a00b13fa192a823d99581f508317b2b31b31257d | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\package cache\{cf2bea3c-26ea-32f8-aa9b-331f7e34ba97}v11.0.61030\packages\vcruntimeminimum_amd64\cab1.cab.40ade269cd14f5566b1db6a7dabe010fc0a121e8df896be75978ed36b4809f0e | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\package cache\{eea66967-97e2-4561-a999-5c22e3cde428}v14.25.28508\packages\vcruntimeminimum_amd64\cab1.cab.8c2cb4e0b6fefac3bb1784c017e1373e18db85bb9214c700dfc97826c9f4e40e | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\package cache\{f8cfeb22-a2e7-3971-9eda-4b11edefc185}v12.0.21005\packages\vcruntimeadditional_x86\cab1.cab.7eebd4de2f6238176bd6035c992fbdd08f9f5ec6f80b25a681125c2706cdcd5d | Dropped File | Stream |
clean
|
...
|
»
c:\programdata\usoprivate\updatestore\updatestore51b519d5-b6f5-4333-8df6-e74d7c9aead4.xml.1a710b472d26ea7721ea0fc24883cb9acc6fd80feb948210dc4390e38861a569 | Dropped File | Stream |
clean
|
...
|
»
c:\recovery\windowsre\reagent.xml.7e9351c75abc89171edcac2661535183a40101c38dbca40e308f06aa72f16b45 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\comms\unistoredb\usstmp.log.1ea48a96286822a552fb4f0bb2e9debc68ea719a037d250e70f634362ccd9d46 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\iconcache.db.6c4ef3f63a79fecf841c1d432bbdd76f26077f23cdecf39cc98b9f6190c4486a | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\clr_v4.0\usagelogs\powershell.exe.log.bc1f46ae79d3d85cce7cdf85cbd0c51375a536c8d6494ba92f54b9a316d4bd53 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\clr_v4.0_32\usagelogs\powershell.exe.log.858648c8c4db1bf3e6244d3c5620f02560cdc706e5ad53fa4bed6acc27c6c15f | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\internet explorer\brndlog.txt.e72c710c8ccad84aa1131a2a0332a4ac2b40040fd04ed6c7e3975781cdc4b94d | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\internet explorer\iecompatdata\iecompatdata.xml.ca74f08f019fdbe2512a43c4ba8ef92d79647233582e5a64a42b9645ac790c7d | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\internet explorer\ie4uinit-userconfig.log.3a08029a2e82788d5f00470e3bb18b94791ee7b24991ad65d0ac0ca4c7963b27 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\internet explorer\versionmanager\versionlist.xml.162099c1f493aa7e611a6d6ae7c1e8ed2addba5492506ab7f40144044f156e3d | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\office\16.0\msaccess.exe_rules.xml.eb24c68320bd147f7abef64f57d9d30c026cad7512037c422b777f8216131f5a | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\office\16.0\officec2rclient.exe_rules.xml.34fcb489563d3dbf4d8b74585ff0ff5d8dd9dea074ce8cf7b0e01022c2d49554 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\office\16.0\officeclicktorun.exe_rules.xml.01a4ff285ba8a6dda6129dddeb96539d76518e76c396e248a678a68146e89d2f | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\office\16.0\outlook.exe_rules.xml.801fdec0b61644273809f6887baf72a0357525716d4bb5d88d7de268d24bc41a | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\office\16.0\powerpnt.exe_rules.xml.6354c0804f150aaccf920416ed8610fa1015a8456a191da56a57babb60bfe361 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\office\16.0\setup.exe_rules.xml.e90f43c6b7bd6398482744171df3ed365b909aa2d8c7f98fb4c9d32437c17871 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\office\16.0\setup32.exe_rules.xml.666578f634783abeec6a70c047a32bbb0c2c1bcc22bbe7ab27abe7d8fc738822 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\office\16.0\excel.exe_rules.xml.ea75fa454e9fd85c909c1a4202ffe983acd601aa1e8a9dc03557280ecc087e24 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\office\16.0\winword.exe_rules.xml.f00520072be99102d8075d7a127e439599cc485247ae3ec11e890ef8b6702120 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\office\otele\{530fa225-a741-4103-8238-7b3d9de36f28} (0) - 3596 - winword.exe - otelemediumcost.dat.76d8f8b328e0b6b8bce1c39a30f5fe13cb5a64a62d560e2123e5715a56df8975 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\office\otele\{09178d66-ba92-4de3-b96c-2b24754031bf} (0) - 1840 - msaccess.exe - otelemediumcost.dat.e543329e8e30fcbfeb127b29f50e6a0007349f3b67bdb4eebfdc24e11b628101 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\office\otele\{c116fc9a-b698-46de-a139-0bd729ca72f1} (0) - 3756 - excel.exe - otelemediumcost.dat.6afff073814879a89fadc5e0421c75eb91ed56e3d66683af87ccaec51934970f | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\office\otele\{4d44c03c-ceac-41b9-a9f9-31bd04be84b8} (0) - 540 - powerpnt.exe - otelemediumcost.dat.3efd50aab9bd29650e2b4b43f843620348edd4ea65fcf4cc19068ff0633de774 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626\autoplayoptin.gif.19cbb8569e4470519cc469a0c7e1c838650bd5d0c89a3fdc640a062ce8d3ba2d | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626\autoplayoptin.png.ae1f0887ef2a1680493247997eb1f49fb58e53dd5e2b35d389c8c49de3bd072b | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626\autoplaylogo.png.3369bed176cdc0ae2865f952ac52784107d9abd9448f414e613078bb6cf3f32d | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626\collectonedrivelogs.bat.9540d5bd726eed8bd33a6f04eecbf9de248d9584ac335ba23d05aa8f35424821 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626\exclusionlist.xml.a0ad0d3da8f00b4bd56970d29632ac8f6e8ab990cc68e2083c3517d114921e18 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626\filesync.localizedresources.dll.943d6fb3b1e5cfcdde88298dae80fcbf95631cc38f914d48ca5272772bf34d2f | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626\etwlog.dll.a431ae2ea457ebb9cdfd27af385ce2fbb0a3706ffd280e6479bb6ed6a2555577 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626\filesync.resources.dll.d0a9e4bf07e5c2fa4965bf89fdf245ee4b58ca9db052cc8aab0e70c2f5e2012f | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626_1\autoplaylogo.png.7bb716a615a0daf6f7d73a6ba6794fa8ba76523f49b97cb2bc02c63768e45310 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626_1\autoplayoptin.gif.85f618b9046aa721673c61c07952cd7ab74912c0eaca1b5d46963f20292ca20d | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626_1\autoplayoptin.png.767d75c9248d2e28a9820017f73acc430b259fef7044d0d208154456128b3f38 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626_1\collectonedrivelogs.bat.27a1174e79f19ac8efa02aec0a385e70bff87e0556d5b7989d63ee67a3205f42 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626_1\filesync.localizedresources.dll.eccb7093e0b0c3e67b667bebddd7eb89c9de058707b074566bbd29df4d278707 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626_1\etwlog.dll.d4efa973844e6624f8bb8942af8cba161bf4c2a756509a973687397bf5a9a605 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626_1\filesyncapi.dll.e76705295dfe1132012760acb42cc6102f0a9d52744d6336d1a8f52d240f8929 | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626_1\exclusionlist.xml.5c17bc5c69ce29dbd1a6aad2e394398f310beb159ac340f413409a035172bb4d | Dropped File | Stream |
clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\onedrive\17.3.5892.0626_1\filesync.resources.dll.ceb77c26c2a9a4bdff1831afacddd3d7dd1b2da9d60798575ed8d1e113e0e338 | Dropped File | Stream |
clean
|
...
|
»