VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: | - |
Threat Names: |
Gen:Heur.Ransom.REntS.Gen.1
Gen:Variant.Fugrafa.33435
|
oiikyy.exe
Windows Exe (x86-32)
Created at 2020-04-09T03:25:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\oiikyy.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402604 |
Size Of Code | 0x49400 |
Size Of Initialized Data | 0xc3e00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-05-14 16:12:31+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x49358 | 0x49400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.96 |
.rdata | 0x44b000 | 0x2800 | 0x2800 | 0x49800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.04 |
.data | 0x44e000 | 0xad82c | 0x1000 | 0x4c000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.24 |
.tls | 0x4fc000 | 0x9 | 0x200 | 0x4d000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.02 |
.rsrc | 0x4fd000 | 0x12050 | 0x12200 | 0x4d200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.09 |
Imports (3)
»
KERNEL32.dll (102)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_llseek | 0x0 | 0x44b010 | 0x4cdfc | 0x4b5fc | 0x539 |
GetDefaultCommConfigW | 0x0 | 0x44b014 | 0x4ce00 | 0x4b600 | 0x1ca |
BuildCommDCBAndTimeoutsA | 0x0 | 0x44b018 | 0x4ce04 | 0x4b604 | 0x3b |
HeapAlloc | 0x0 | 0x44b01c | 0x4ce08 | 0x4b608 | 0x2cb |
SetConsoleTextAttribute | 0x0 | 0x44b020 | 0x4ce0c | 0x4b60c | 0x446 |
SetConsoleScreenBufferSize | 0x0 | 0x44b024 | 0x4ce10 | 0x4b610 | 0x445 |
SetCommBreak | 0x0 | 0x44b028 | 0x4ce14 | 0x4b614 | 0x422 |
GetModuleHandleW | 0x0 | 0x44b02c | 0x4ce18 | 0x4b618 | 0x218 |
GetTickCount | 0x0 | 0x44b030 | 0x4ce1c | 0x4b61c | 0x293 |
GetWindowsDirectoryA | 0x0 | 0x44b034 | 0x4ce20 | 0x4b620 | 0x2ae |
OpenProcess | 0x0 | 0x44b038 | 0x4ce24 | 0x4b624 | 0x380 |
WideCharToMultiByte | 0x0 | 0x44b03c | 0x4ce28 | 0x4b628 | 0x511 |
Sleep | 0x0 | 0x44b040 | 0x4ce2c | 0x4b62c | 0x4b2 |
SetSystemPowerState | 0x0 | 0x44b044 | 0x4ce30 | 0x4b630 | 0x48a |
GetAtomNameW | 0x0 | 0x44b048 | 0x4ce34 | 0x4b634 | 0x16e |
GetModuleFileNameW | 0x0 | 0x44b04c | 0x4ce38 | 0x4b638 | 0x214 |
GetVolumePathNameA | 0x0 | 0x44b050 | 0x4ce3c | 0x4b63c | 0x2aa |
DisconnectNamedPipe | 0x0 | 0x44b054 | 0x4ce40 | 0x4b640 | 0xe1 |
EnumSystemLocalesA | 0x0 | 0x44b058 | 0x4ce44 | 0x4b644 | 0x10d |
FindFirstFileExA | 0x0 | 0x44b05c | 0x4ce48 | 0x4b648 | 0x133 |
GetConsoleAliasesLengthW | 0x0 | 0x44b060 | 0x4ce4c | 0x4b64c | 0x198 |
GetLongPathNameW | 0x0 | 0x44b064 | 0x4ce50 | 0x4b650 | 0x20f |
GetProcAddress | 0x0 | 0x44b068 | 0x4ce54 | 0x4b654 | 0x245 |
EnumDateFormatsExA | 0x0 | 0x44b06c | 0x4ce58 | 0x4b658 | 0xf5 |
EnumSystemCodePagesW | 0x0 | 0x44b070 | 0x4ce5c | 0x4b65c | 0x108 |
SetFileApisToOEM | 0x0 | 0x44b074 | 0x4ce60 | 0x4b660 | 0x45d |
ProcessIdToSessionId | 0x0 | 0x44b078 | 0x4ce64 | 0x4b664 | 0x399 |
GetProcessWorkingSetSize | 0x0 | 0x44b07c | 0x4ce68 | 0x4b668 | 0x254 |
LocalAlloc | 0x0 | 0x44b080 | 0x4ce6c | 0x4b66c | 0x344 |
IsSystemResumeAutomatic | 0x0 | 0x44b084 | 0x4ce70 | 0x4b670 | 0x305 |
SetConsoleOutputCP | 0x0 | 0x44b088 | 0x4ce74 | 0x4b674 | 0x442 |
GetCommMask | 0x0 | 0x44b08c | 0x4ce78 | 0x4b678 | 0x181 |
FindAtomA | 0x0 | 0x44b090 | 0x4ce7c | 0x4b67c | 0x12c |
FatalAppExitA | 0x0 | 0x44b094 | 0x4ce80 | 0x4b680 | 0x120 |
PeekConsoleInputA | 0x0 | 0x44b098 | 0x4ce84 | 0x4b684 | 0x38b |
SetCalendarInfoA | 0x0 | 0x44b09c | 0x4ce88 | 0x4b688 | 0x41e |
EnumResourceLanguagesW | 0x0 | 0x44b0a0 | 0x4ce8c | 0x4b68c | 0xfe |
lstrcpyW | 0x0 | 0x44b0a4 | 0x4ce90 | 0x4b690 | 0x548 |
lstrcpyA | 0x0 | 0x44b0a8 | 0x4ce94 | 0x4b694 | 0x547 |
lstrlenA | 0x0 | 0x44b0ac | 0x4ce98 | 0x4b698 | 0x54d |
SetVolumeLabelA | 0x0 | 0x44b0b0 | 0x4ce9c | 0x4b69c | 0x4a8 |
GetLastError | 0x0 | 0x44b0b4 | 0x4cea0 | 0x4b6a0 | 0x202 |
GetVolumeNameForVolumeMountPointA | 0x0 | 0x44b0b8 | 0x4cea4 | 0x4b6a4 | 0x2a8 |
GetCommandLineA | 0x0 | 0x44b0bc | 0x4cea8 | 0x4b6a8 | 0x186 |
HeapSetInformation | 0x0 | 0x44b0c0 | 0x4ceac | 0x4b6ac | 0x2d3 |
GetStartupInfoW | 0x0 | 0x44b0c4 | 0x4ceb0 | 0x4b6b0 | 0x263 |
TerminateProcess | 0x0 | 0x44b0c8 | 0x4ceb4 | 0x4b6b4 | 0x4c0 |
GetCurrentProcess | 0x0 | 0x44b0cc | 0x4ceb8 | 0x4b6b8 | 0x1c0 |
UnhandledExceptionFilter | 0x0 | 0x44b0d0 | 0x4cebc | 0x4b6bc | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x44b0d4 | 0x4cec0 | 0x4b6c0 | 0x4a5 |
IsDebuggerPresent | 0x0 | 0x44b0d8 | 0x4cec4 | 0x4b6c4 | 0x300 |
EnterCriticalSection | 0x0 | 0x44b0dc | 0x4cec8 | 0x4b6c8 | 0xee |
LeaveCriticalSection | 0x0 | 0x44b0e0 | 0x4cecc | 0x4b6cc | 0x339 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x44b0e4 | 0x4ced0 | 0x4b6d0 | 0x2e3 |
EncodePointer | 0x0 | 0x44b0e8 | 0x4ced4 | 0x4b6d4 | 0xea |
DecodePointer | 0x0 | 0x44b0ec | 0x4ced8 | 0x4b6d8 | 0xca |
RtlUnwind | 0x0 | 0x44b0f0 | 0x4cedc | 0x4b6dc | 0x418 |
SetHandleCount | 0x0 | 0x44b0f4 | 0x4cee0 | 0x4b6e0 | 0x46f |
GetStdHandle | 0x0 | 0x44b0f8 | 0x4cee4 | 0x4b6e4 | 0x264 |
GetFileType | 0x0 | 0x44b0fc | 0x4cee8 | 0x4b6e8 | 0x1f3 |
DeleteCriticalSection | 0x0 | 0x44b100 | 0x4ceec | 0x4b6ec | 0xd1 |
SetFilePointer | 0x0 | 0x44b104 | 0x4cef0 | 0x4b6f0 | 0x466 |
HeapFree | 0x0 | 0x44b108 | 0x4cef4 | 0x4b6f4 | 0x2cf |
CloseHandle | 0x0 | 0x44b10c | 0x4cef8 | 0x4b6f8 | 0x52 |
ExitProcess | 0x0 | 0x44b110 | 0x4cefc | 0x4b6fc | 0x119 |
WriteFile | 0x0 | 0x44b114 | 0x4cf00 | 0x4b700 | 0x525 |
GetModuleFileNameA | 0x0 | 0x44b118 | 0x4cf04 | 0x4b704 | 0x213 |
FreeEnvironmentStringsW | 0x0 | 0x44b11c | 0x4cf08 | 0x4b708 | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x44b120 | 0x4cf0c | 0x4b70c | 0x1da |
TlsAlloc | 0x0 | 0x44b124 | 0x4cf10 | 0x4b710 | 0x4c5 |
TlsGetValue | 0x0 | 0x44b128 | 0x4cf14 | 0x4b714 | 0x4c7 |
TlsSetValue | 0x0 | 0x44b12c | 0x4cf18 | 0x4b718 | 0x4c8 |
TlsFree | 0x0 | 0x44b130 | 0x4cf1c | 0x4b71c | 0x4c6 |
InterlockedIncrement | 0x0 | 0x44b134 | 0x4cf20 | 0x4b720 | 0x2ef |
SetLastError | 0x0 | 0x44b138 | 0x4cf24 | 0x4b724 | 0x473 |
GetCurrentThreadId | 0x0 | 0x44b13c | 0x4cf28 | 0x4b728 | 0x1c5 |
InterlockedDecrement | 0x0 | 0x44b140 | 0x4cf2c | 0x4b72c | 0x2eb |
HeapCreate | 0x0 | 0x44b144 | 0x4cf30 | 0x4b730 | 0x2cd |
QueryPerformanceCounter | 0x0 | 0x44b148 | 0x4cf34 | 0x4b734 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x44b14c | 0x4cf38 | 0x4b738 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x44b150 | 0x4cf3c | 0x4b73c | 0x279 |
CreateFileA | 0x0 | 0x44b154 | 0x4cf40 | 0x4b740 | 0x88 |
SetStdHandle | 0x0 | 0x44b158 | 0x4cf44 | 0x4b744 | 0x487 |
GetConsoleCP | 0x0 | 0x44b15c | 0x4cf48 | 0x4b748 | 0x19a |
GetConsoleMode | 0x0 | 0x44b160 | 0x4cf4c | 0x4b74c | 0x1ac |
FlushFileBuffers | 0x0 | 0x44b164 | 0x4cf50 | 0x4b750 | 0x157 |
LoadLibraryW | 0x0 | 0x44b168 | 0x4cf54 | 0x4b754 | 0x33f |
GetCPInfo | 0x0 | 0x44b16c | 0x4cf58 | 0x4b758 | 0x172 |
GetACP | 0x0 | 0x44b170 | 0x4cf5c | 0x4b75c | 0x168 |
GetOEMCP | 0x0 | 0x44b174 | 0x4cf60 | 0x4b760 | 0x237 |
IsValidCodePage | 0x0 | 0x44b178 | 0x4cf64 | 0x4b764 | 0x30a |
HeapReAlloc | 0x0 | 0x44b17c | 0x4cf68 | 0x4b768 | 0x2d2 |
SetEndOfFile | 0x0 | 0x44b180 | 0x4cf6c | 0x4b76c | 0x453 |
GetProcessHeap | 0x0 | 0x44b184 | 0x4cf70 | 0x4b770 | 0x24a |
MultiByteToWideChar | 0x0 | 0x44b188 | 0x4cf74 | 0x4b774 | 0x367 |
ReadFile | 0x0 | 0x44b18c | 0x4cf78 | 0x4b778 | 0x3c0 |
IsProcessorFeaturePresent | 0x0 | 0x44b190 | 0x4cf7c | 0x4b77c | 0x304 |
WriteConsoleW | 0x0 | 0x44b194 | 0x4cf80 | 0x4b780 | 0x524 |
HeapSize | 0x0 | 0x44b198 | 0x4cf84 | 0x4b784 | 0x2d4 |
LCMapStringW | 0x0 | 0x44b19c | 0x4cf88 | 0x4b788 | 0x32d |
GetStringTypeW | 0x0 | 0x44b1a0 | 0x4cf8c | 0x4b78c | 0x269 |
CreateFileW | 0x0 | 0x44b1a4 | 0x4cf90 | 0x4b790 | 0x8f |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCaretPos | 0x0 | 0x44b1ac | 0x4cf98 | 0x4b798 | 0x10a |
ADVAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DeregisterEventSource | 0x0 | 0x44b000 | 0x4cdec | 0x4b5ec | 0xdb |
EnumServicesStatusA | 0x0 | 0x44b004 | 0x4cdf0 | 0x4b5f0 | 0xff |
CloseEventLog | 0x0 | 0x44b008 | 0x4cdf4 | 0x4b5f4 | 0x56 |
Exports (1)
»
Api name | EAT Address | Ordinal |
---|---|---|
@calcPrecision@4 | 0x1000 | 0x1 |
Memory Dumps (38)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Relevant Image |
![]() |
32-bit | 0x004039B9 |
![]() |
![]() |
...
|
buffer | 1 | 0x00312118 | 0x0035287F | First Execution |
![]() |
32-bit | 0x00312118 |
![]() |
![]() |
...
|
buffer | 1 | 0x01CA0000 | 0x01D1FFFF | First Execution |
![]() |
32-bit | 0x01CA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x01CA0000 | 0x01D1FFFF | Content Changed |
![]() |
32-bit | 0x01CA04F6 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x00406C0D |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x00452F08 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x00434FD9 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x0043A636 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x0043F47A |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x00405407 |
![]() |
![]() |
...
|
buffer | 1 | 0x00290000 | 0x00290FFF | First Execution |
![]() |
32-bit | 0x00290000 |
![]() |
![]() |
...
|
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution |
![]() |
32-bit | 0x002D0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution |
![]() |
32-bit | 0x002D0000 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x004211C0 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x0041EFF0 |
![]() |
![]() |
...
|
buffer | 1 | 0x00290000 | 0x00290FFF | First Execution |
![]() |
32-bit | 0x00290000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00290000 | 0x00290FFF | First Execution |
![]() |
32-bit | 0x00290000 |
![]() |
![]() |
...
|
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution |
![]() |
32-bit | 0x002D0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution |
![]() |
32-bit | 0x002D0000 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x0042697D |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x0040D82F |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x0040D000 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x00426103 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x00453040 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x00409006 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x0040345A |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x0041D0D0 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x004231C0 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x0040D000 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x00426103 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x0042F96D |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x004033E7 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x0042EEFE |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x0041D0D0 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x00408FB0 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x0040C000 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Content Changed |
![]() |
32-bit | 0x0042C214 |
![]() |
![]() |
...
|
oiikyy.exe | 1 | 0x00400000 | 0x0050FFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
\\?\C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioLR.cab | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab.~~~~ | Dropped File | Stream |
Unknown
|
...
|
»