Dynamic Analysis Report |
Classification: Ransomware |
C_932.NLS.exe
Created at 2019-06-19T16:00:00
Remarks (2/2)
(0x200000e): The overall sleep time of all monitored processes was truncated from "1 minute, 30 seconds" to "30 seconds" to reveal dormant functionality.
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\C_932.NLS.exe | Sample File | Binary |
Malicious
|
...
|
Image Base | 0x400000 |
Entry Point | 0x401000 |
Size Of Code | 0x1000 |
Size Of Initialized Data | 0x2000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-03-20 07:33:07+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xfe8 | 0x1000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.54 |
.rdata | 0x402000 | 0x72c | 0x800 | 0x1400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.data | 0x403000 | 0x1740 | 0x1200 | 0x1c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.79 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleFileNameA | 0x0 | 0x402044 | 0x21c8 | 0x15c8 | 0x132 |
GetSystemTimeAsFileTime | 0x0 | 0x402048 | 0x21cc | 0x15cc | 0x179 |
GlobalAlloc | 0x0 | 0x40204c | 0x21d0 | 0x15d0 | 0x1a5 |
GlobalFree | 0x0 | 0x402050 | 0x21d4 | 0x15d4 | 0x1ac |
GlobalMemoryStatus | 0x0 | 0x402054 | 0x21d8 | 0x15d8 | 0x1b1 |
MapViewOfFile | 0x0 | 0x402058 | 0x21dc | 0x15dc | 0x200 |
MoveFileW | 0x0 | 0x40205c | 0x21e0 | 0x15e0 | 0x207 |
MultiByteToWideChar | 0x0 | 0x402060 | 0x21e4 | 0x15e4 | 0x20b |
OpenProcess | 0x0 | 0x402064 | 0x21e8 | 0x15e8 | 0x216 |
Process32FirstW | 0x0 | 0x402068 | 0x21ec | 0x15ec | 0x223 |
Process32NextW | 0x0 | 0x40206c | 0x21f0 | 0x15f0 | 0x224 |
RtlZeroMemory | 0x0 | 0x402070 | 0x21f4 | 0x15f4 | 0x258 |
SetErrorMode | 0x0 | 0x402074 | 0x21f8 | 0x15f8 | 0x27f |
GetLogicalDrives | 0x0 | 0x402078 | 0x21fc | 0x15fc | 0x12e |
SetFilePointerEx | 0x0 | 0x40207c | 0x2200 | 0x1600 | 0x286 |
Sleep | 0x0 | 0x402080 | 0x2204 | 0x1604 | 0x2b7 |
TerminateProcess | 0x0 | 0x402084 | 0x2208 | 0x1608 | 0x2bf |
UnmapViewOfFile | 0x0 | 0x402088 | 0x220c | 0x160c | 0x2cf |
WriteFile | 0x0 | 0x40208c | 0x2210 | 0x1610 | 0x2f7 |
lstrcatA | 0x0 | 0x402090 | 0x2214 | 0x1614 | 0x30f |
lstrcatW | 0x0 | 0x402094 | 0x2218 | 0x1618 | 0x310 |
lstrcmpW | 0x0 | 0x402098 | 0x221c | 0x161c | 0x312 |
lstrcmpiA | 0x0 | 0x40209c | 0x2220 | 0x1620 | 0x313 |
lstrcmpiW | 0x0 | 0x4020a0 | 0x2224 | 0x1624 | 0x314 |
lstrcpyW | 0x0 | 0x4020a4 | 0x2228 | 0x1628 | 0x316 |
lstrlenA | 0x0 | 0x4020a8 | 0x222c | 0x162c | 0x319 |
lstrlenW | 0x0 | 0x4020ac | 0x2230 | 0x1630 | 0x31a |
GetLastError | 0x0 | 0x4020b0 | 0x2234 | 0x1634 | 0x128 |
GetFileAttributesW | 0x0 | 0x4020b4 | 0x2238 | 0x1638 | 0x11a |
GetEnvironmentVariableA | 0x0 | 0x4020b8 | 0x223c | 0x163c | 0x113 |
GetDateFormatA | 0x0 | 0x4020bc | 0x2240 | 0x1640 | 0x104 |
GetCurrentProcessId | 0x0 | 0x4020c0 | 0x2244 | 0x1644 | 0x101 |
FindNextFileW | 0x0 | 0x4020c4 | 0x2248 | 0x1648 | 0xbb |
FindFirstFileW | 0x0 | 0x4020c8 | 0x224c | 0x164c | 0xb4 |
FindClose | 0x0 | 0x4020cc | 0x2250 | 0x1650 | 0xad |
FileTimeToSystemTime | 0x0 | 0x4020d0 | 0x2254 | 0x1654 | 0xa4 |
CreateToolhelp32Snapshot | 0x0 | 0x4020d4 | 0x2258 | 0x1658 | 0x59 |
CreateThread | 0x0 | 0x4020d8 | 0x225c | 0x165c | 0x56 |
CreateFileW | 0x0 | 0x4020dc | 0x2260 | 0x1660 | 0x40 |
CreateFileMappingA | 0x0 | 0x4020e0 | 0x2264 | 0x1664 | 0x3e |
CreateFileA | 0x0 | 0x4020e4 | 0x2268 | 0x1668 | 0x3d |
CopyFileA | 0x0 | 0x4020e8 | 0x226c | 0x166c | 0x2e |
SetFileAttributesW | 0x0 | 0x4020ec | 0x2270 | 0x1670 | 0x284 |
CloseHandle | 0x0 | 0x4020f0 | 0x2274 | 0x1674 | 0x23 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHChangeNotify | 0x0 | 0x402108 | 0x228c | 0x168c | 0x60 |
ShellExecuteA | 0x0 | 0x40210c | 0x2290 | 0x1690 | 0xd9 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyExA | 0x0 | 0x402000 | 0x2184 | 0x1584 | 0x1d0 |
RegCloseKey | 0x0 | 0x402004 | 0x2188 | 0x1588 | 0x1b7 |
OpenProcessToken | 0x0 | 0x402008 | 0x218c | 0x158c | 0x198 |
LookupPrivilegeValueA | 0x0 | 0x40200c | 0x2190 | 0x1590 | 0x141 |
CryptReleaseContext | 0x0 | 0x402010 | 0x2194 | 0x1594 | 0x98 |
CryptImportKey | 0x0 | 0x402014 | 0x2198 | 0x1598 | 0x97 |
CryptGenKey | 0x0 | 0x402018 | 0x219c | 0x159c | 0x8d |
CryptExportKey | 0x0 | 0x40201c | 0x21a0 | 0x15a0 | 0x8c |
CryptEncrypt | 0x0 | 0x402020 | 0x21a4 | 0x15a4 | 0x87 |
CryptDestroyKey | 0x0 | 0x402024 | 0x21a8 | 0x15a8 | 0x84 |
CryptDecrypt | 0x0 | 0x402028 | 0x21ac | 0x15ac | 0x81 |
CryptAcquireContextA | 0x0 | 0x40202c | 0x21b0 | 0x15b0 | 0x7d |
AdjustTokenPrivileges | 0x0 | 0x402030 | 0x21b4 | 0x15b4 | 0x19 |
RegQueryValueExA | 0x0 | 0x402034 | 0x21b8 | 0x15b8 | 0x1da |
RegSetValueExA | 0x0 | 0x402038 | 0x21bc | 0x15bc | 0x1e7 |
RegCreateKeyA | 0x0 | 0x40203c | 0x21c0 | 0x15c0 | 0x1ba |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetOpenEnumA | 0x0 | 0x4020f8 | 0x227c | 0x167c | 0x25 |
WNetEnumResourceA | 0x0 | 0x4020fc | 0x2280 | 0x1680 | 0x13 |
WNetCloseEnum | 0x0 | 0x402100 | 0x2284 | 0x1684 | 0xc |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
c_932.nls.exe | 1 | 0x00400000 | 0x00404FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Gen:Win32.AV-Killer.cmZ@aifp3fh |
Malicious
|
\\?\C:\ProgramData\Microsoft Help\MS.GROOVE.14.1033.hxn.[ID]g9uZrLhJaygpwRm1[ID] | Modified File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Microsoft\MF\Pending.GRL.[ID]g9uZrLhJaygpwRm1[ID] | Modified File | Stream |
Unknown
|
...
|
\\?\C:\BOOTSECT.BAK.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Boot\BOOTSTAT.DAT.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Microsoft Office\bannedhard.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Mozilla Firefox\AccessibleMarshal.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Reference Assemblies\sections.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Windows Journal\gold substantially.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Uninstall Information\especially-ccd-facilitate.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Reference Assemblies\mediawiki.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Windows Portable Devices\liverevilusage.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Windows Photo Viewer\suffernorwegianfifteen.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Windows Defender\treaty_olive.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Java\jre7\COPYRIGHT.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Java\jre7\LICENSE.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Java\jre7\README.txt.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\Office14\BCSLaunch.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\Office14\DGRMLNCH.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Adobe\ARM\Reader_10.0.0\AdbeRdrSecUpd10111.msp.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Microsoft Office\Document Themes 14\Adjacency.thmx.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\Default\Links\Downloads.lnk.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Microsoft Office\Document Themes 14\Angles.thmx.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\Office14\1033\BHOINTL.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Microsoft Synchronization Services\ADO.NET\v1.0\Microsoft.Synchronization.Data.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\Office14\1033\DL_RES.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Microsoft Synchronization Services\ADO.NET\v1.0\Microsoft.Synchronization.Data.Server.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Saved Games\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Searches\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Searches\Everywhere.search-ms.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\0Q8doMuQ.swf.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\CIrdEedWE6.mkv.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DiD_6nqj9.avi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Microsoft\User Account Pictures\user.bmp.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Package Cache\{e6e75766-da0f-4ba2-9788-6ea593ce702d}\state.rsm.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Adobe\Reader 10.0\Benioku.htm.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Adobe\Reader 10.0\Berime.htm.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0kzI-M-c1vXcd0Bacx.mp3.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2IEj-Bprh3fH12Sk7.odt.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\8i8Xn UZ7.jpg.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\dHCMntg.rtf.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Frdn5-oMFGap_Wjgfuj2.ods.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\9O_Z3mXUixLyl.csv.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\cH9GNVMjD8ZOg2ghJZgJ.xlsx.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\gY9c9qHwmstPknB2E15Y.m4a.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fyqw5W.mp3.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\skaxmF9z-Qgjk.mp4.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Package Cache\{e6e75766-da0f-4ba2-9788-6ea593ce702d}\vcredist_x86.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\FBIBLIO.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Microsoft Office\Document Themes 14\Apothecary.thmx.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\Stationery\Desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Package Cache\{e52a6842-b0ac-476e-b48f-378a97a67346}\VC_redist.x64.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\RECOVR32.CNV.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Microsoft SQL Server Compact Edition\v3.5\sqlceca35.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\PROOF\MSLID.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\Default\Downloads\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\VC\msdia100.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Microsoft Office\Office14\ACCDDS.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\I1fpTZ.m4a.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\FDATE.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\System\Ole DB\xmlrw.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.msi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.msi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\MCABOUT.HTM.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\STINTL.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\STINTL.DLL.IDX_DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Binary |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Hg1aq.jpg.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\hmhr.wav.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\jAtLio6.doc.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\Downloads.lnk.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\RecentPlaces.lnk.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\EURO\MSOEURO.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Java\jre7\THIRDPARTYLICENSEREADME.txt.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\ACEINTL.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\5_ZUjzjcPnH3.mp4.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Java\jre7\Welcome.html.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\9lk rzIJKnabURE1.png.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\Filters\msgfilt.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Java\jre7\lib\accessibility.properties.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\U9nNDtOagrcsbbNXoq7.avi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\uZ8yb2pzJzSAO1.mp4.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Microsoft Synchronization Services\ADO.NET\v1.0\Microsoft.Synchronization.Data.SqlServerCe.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Microsoft Help\MS.INFOPATHEDITOR.14.1033.hxn.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Common Files\Java\Java Update\jaucheck.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Microsoft Help\MS.MSACCESS.14.1033.hxn.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Microsoft Help\MS.INFOPATH.14.1033.hxn.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\MSB1AR.LEX.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1ZpD.gif.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2m0jDWJRbuSJx.bmp.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\4HVv8.jpg.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\9Ji7in8ccV.bmp.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\Public\Documents\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\Public\Pictures\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\Public\Videos\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Microsoft.NET\Primary Interop Assemblies\adodb.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Binary |
Unknown
|
...
|
\\?\C:\Users\Public\Recorded TV\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\Public\Libraries\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Adobe\ARM\Reader_10.0.0\AdbeRdrUpd10110_MUI.msp.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\Default\Desktop\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Mozilla Firefox\crashreporter.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\dbfmOx0DNUNPSie\c-JKdua8N5.ots.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Binary |
Unknown
|
...
|
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.msi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\Filters\odffilt.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\Public\Desktop\Adobe Reader X.lnk.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Java\jre7\lib\alt-rt.jar.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\w-u--0v1t59p.avi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\IconCache.db.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\ACEODBCI.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\Default\NTUSER.DAT.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.CNT.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Microsoft Office\Document Themes 14\Aspect.thmx.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Common Files\System\Ole DB\xmlrw.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Microsoft\OFFICE\AssetLibrary.ico.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\msmdlocal.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\Default\Documents\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveLR.cab.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Microsoft\MF\Active.GRL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\MSClientDataMgr\MSCDM.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\Default\AppData\Local\IconCache.db.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.msi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.msi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\Default\Music\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\Default\Favorites\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Microsoft\IdentityCRL\ppcrlui.dll.[ID]g9uZrLhJaygpwRm1[ID] | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\OFFICE\DocumentRepository.ico.[ID]g9uZrLhJaygpwRm1[ID] | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Adobe\determine matthew.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\DVD Maker\maximize.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Google\shoes perception.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Java\teachers.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft Help\Hx.hxn.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft Help\MS.EXCEL.14.1033.hxn.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft Help\MS.EXCEL.DEV.14.1033.hxn.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Firefox\application.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Firefox\breakpadinjector.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Windows Sidebar\agentssee.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Windows NT\seemed.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Windows Mail\diy.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\MSBuild\Microsoft.Office.InfoPath.targets.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Windows Sidebar\settings.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Maintenance Service\updater.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\Office14\AUTHZAX.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft Help\MS.GRAPH.14.1033.hxn.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Default\Contacts\Administrator.contact.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{3c3aafc8-d898-43ec-998f-965ffdae065a}\state.rsm.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Default\Links\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Default\Links\Desktop.lnk.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Default\Links\RecentPlaces.lnk.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Searches\Indexed Locations.search-ms.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{3c3aafc8-d898-43ec-998f-965ffdae065a}\vcredist_x64.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Sun\Java\Java Update\jaureglist.xml.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\User Account Pictures\guest.bmp.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{f325f05b-f963-4640-a43b-c8a494cdda0f}\state.rsm.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{e52a6842-b0ac-476e-b48f-378a97a67346}\state.rsm.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Internet Explorer\SIGNUP\install.ins.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Internet Explorer\SIGNUP\install.ins.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Adobe\Reader 10.0\IrakHau.htm.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Java\jre7\release.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\54a SlEUM.m4a.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\4no91 QuYYqmyLqH-.pptx.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\adEBzQ.avi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Java\jre7\THIRDPARTYLICENSEREADME-JAVAFX.txt.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Downloads\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5e_mBx7SjCEJ-.pptx.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\CRK9 Rh7.xlsx.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\HDGHAY1I-BXzP_H.m4a.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\OfficeSoftwareProtectionPlatform\tokens.dat.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Compressed |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Office\Document Themes 14\Apex.thmx.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{f325f05b-f963-4640-a43b-c8a494cdda0f}\VC_redist.x86.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Default\Contacts\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\microsoft shared\VSTO\ActionsPane3.xsd.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\MSCONV97.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\ACECORE.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Adobe\Reader 10.0\Leame.htm.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\hTefMhnvMK.flv.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\IE2sk29TIgjPvTzVKz.pptx.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ISB48ey.pptx.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\1033\EEINTL.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Adobe\Reader 10.0\LeesMij.htm.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\Desktop.lnk.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Adobe\Reader 10.0\Leggimi.htm.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\System\Ole DB\xmlrwbin.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\7e4F4WEY32qCdiSWyG3P.mkv.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\AdARbZbRdZlVmzpJhU8h.mkv.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPC.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\GDIPFONTCACHEV1.DAT.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\VQQ6Kzula.avi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft Help\MS.MSACCESS.DEV.14.1033.hxn.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AcrobatUpdater.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.msi.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\DW\DBGHELP.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Mozilla\logs\maintenanceservice-install.log.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Downloads\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Microsoft.NET\RedistList\AssemblyList_4_client.xml.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\DESIGNER\MSADDNDR.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Firefox\browser\blocklist.xml.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Java\jre7\bin\awt.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\microsoft shared\VC\amd64\msdia80.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\IdentityCRL\ppcrlconfig.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Adobe\Reader 10.0\LeiaMe.htm.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\microsoft shared\VSTO\vstoee.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Music\desktop.ini.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Microsoft Analysis Services\AS OLEDB\10\msmdlocal.dll.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPCEXT.DLL.[ID]g9uZrLhJaygpwRm1[ID] | Dropped File | Stream |
Not Queried
|
...
|