Malicious
Classifications
Ransomware
Threat Names
Gibberish Mal/Generic-S
Dynamic Analysis Report
Created on 2022-04-25T14:14:00
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe
Windows Exe (x86-32)
Remarks (1/1)
(0x02000046): The maximum binlog size was reached. The analysis was terminated prematurely.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | Sample File | Binary |
malicious
|
...
|
»
File Reputation Information
»
Verdict |
malicious
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x487640 |
Size Of Code | 0x33000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x54000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-07-04 23:27:55+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x54000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x455000 | 0x33000 | 0x32a00 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.92 |
UPX2 | 0x488000 | 0x1000 | 0x400 | 0x32e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.79 |
Imports (9)
»
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptEncrypt | - | 0x4880c8 | 0x880c8 | 0x32ec8 | 0x0 |
KERNEL32.DLL (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | - | 0x4880d0 | 0x880d0 | 0x32ed0 | 0x0 |
ExitProcess | - | 0x4880d4 | 0x880d4 | 0x32ed4 | 0x0 |
GetProcAddress | - | 0x4880d8 | 0x880d8 | 0x32ed8 | 0x0 |
VirtualProtect | - | 0x4880dc | 0x880dc | 0x32edc | 0x0 |
MPR.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetCloseEnum | - | 0x4880e4 | 0x880e4 | 0x32ee4 | 0x0 |
ole32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoInitialize | - | 0x4880ec | 0x880ec | 0x32eec | 0x0 |
OLEAUT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantClear | 0x9 | 0x4880f4 | 0x880f4 | 0x32ef4 | - |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | - | 0x4880fc | 0x880fc | 0x32efc | 0x0 |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StrStrA | - | 0x488104 | 0x88104 | 0x32f04 | 0x0 |
WININET.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InternetOpenW | - | 0x48810c | 0x8810c | 0x32f0c | 0x0 |
WS2_32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
htons | 0x9 | 0x488114 | 0x88114 | 0x32f14 | - |
Memory Dumps (56)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | First Execution |
![]() |
32-bit | 0x00487640 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00452EBA |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00434F89 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0043A5E6 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00455057 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0043F42A |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00405397 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00421170 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00453A70 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0043310A |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00436196 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0045511F |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0040344C |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0041D080 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00421170 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00409C20 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x004083B0 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0042EE9E |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0042521B |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0040B650 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0041D080 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00422000 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00423790 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0040C280 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0040D000 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x004037AC |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0043209E |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0043209E |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x004035F0 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00452FF2 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x004247A0 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x004078E0 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0042EE9E |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x004079F6 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0042EE9E |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0042F92A |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0042EE9E |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00432CC2 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0042F90D |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x004247A0 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0042CA5A |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0043209E |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0042F925 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x004083B0 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x004031E2 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0042EE9E |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0041D080 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x004260A3 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0040313C |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0042EE9E |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0041D080 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00430EBC |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0040D000 |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x00432CFA |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Content Changed |
![]() |
32-bit | 0x0040323C |
![]() |
...
|
d44df8fc28ccfa08c75e9965b3cc145d82111137e70b96946331e113ec6dd0b9.exe | 1 | 0x00400000 | 0x00488FFF | Final Dump |
![]() |
32-bit | - |
![]() |
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF.$$$ | Dropped File | Unknown |
N/A
Not Available because the file was not extracted successfully.
|
...
|
»
Also Known As | \\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF (Dropped File) |
MIME Type | - |
File Size | - |
MD5 | - |
SHA1 | - |
SHA256 | - |
SSDeep | - |
ImpHash | - |
\\?\C:\$Recycle.Bin\S-1-5-18\desktop.ini | Modified File | Stream |
clean
|
...
|
»
\\?\C:\$Recycle.Bin\S-1-5-21-1560258661-3990802383-1811730007-1000\desktop.ini | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Common Files\1iz126n_fyjFdzvpI4k_.jpg | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Common Files\qNyuFiCwjmRo.gif | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Common Files\rdr7ouGNjf0.jpg | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Internet Explorer\SIGNUP\install.ins | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Microsoft Office 15\ClientX64\IntegratedOffice.exe | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\WindowsPowerShell\Modules\PackageManagement\1.0.0.1\PackageManagement.psd1 | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\WindowsPowerShell\Modules\PackageManagement\1.0.0.1\PackageManagement.format.ps1xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\WindowsPowerShell\Modules\PackageManagement\1.0.0.1\PackageProviderFunctions.psm1 | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PSGet.Format.ps1xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PowerShellGet.psd1 | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\en-US\PSGet.Resource.psd1 | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PSGet.Resource.psd1 | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PSModule.psm1 | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\WindowsPowerShell\Modules\PSReadline\1.1\PSReadline.psd1 | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files\WindowsPowerShell\Modules\PSReadline\1.1\PSReadline.psm1 | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Common Files\DESIGNER\MSADDNDR.OLB | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\Stationery\Desktop.ini | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\VSTA\AppInfoDocument\AddIns.store | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\VSTA\VSTOFiles.cat | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\PipelineSegments.store | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\ActionsPane3.xsd | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\vstoee100.tlb | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\vstoee90.tlb | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\desktop.ini | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Internet Explorer\SIGNUP\install.ins | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\AppXManifest.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\FileSystemMetadata.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\Office16\OSPP.HTM | Modified File | Binary |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\Office16\OSPP.VBS | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\Office16\SLERROR.XML | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-0000-0000000FF1CE.xml | Modified File | Binary |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-002A-0000-1000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-002A-0409-1000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0116-0409-1000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.common.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-0000-0000000FF1CE.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AuthoredExtensions.xml | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\client\AppVDllSurrogate64.exe | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\client\AppVDllSurrogate32.exe | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\client\AppVLP.exe | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN00790_.WMF | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\readme.txt | Dropped File | Stream |
clean
|
...
|
»