Backdoor Ransomware Spyware
Mal/Generic-S
Created on 2022-04-23T11:57:00
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe
Remarks (2/2)
(0x02000057): Static Analysis failed to decrypt some TLS connections.
(0x0200000E): The overall sleep time of all monitored processes was truncated from "6 hours, 21 minutes, 36 seconds" to "2 minutes, 20 seconds" to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200004A): 3 dumps were skipped because they exceeded the maximum dump size of 7 MB. The largest one was 516 MB.
(0x0200005D): 5997 additional dumps with the reason "Content Changed" and a total of 28977 MB were skipped because the respective maximum limit was reached.
(0x0200001B): The maximum number of file Reputation Analysis requests per analysis (150) was exceeded.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | Sample File | Binary |
malicious
|
...
|
Verdict |
malicious
|
Names | Mal/Generic-S |
Image Base | 0x400000 |
Entry Point | 0x8d35a0 |
Size Of Code | 0x1cc000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x307000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 1970-01-01 00:00:00+00:00 |
Packer | UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x307000 | 0x0 | 0x200 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x708000 | 0x1cc000 | 0x1cb800 | 0x200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.91 |
UPX2 | 0x8d4000 | 0x1000 | 0x200 | 0x1cba00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.37 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | - | 0x8d4050 | 0x4d4050 | 0x1cba50 | 0x0 |
ExitProcess | - | 0x8d4054 | 0x4d4054 | 0x1cba54 | 0x0 |
GetProcAddress | - | 0x8d4058 | 0x4d4058 | 0x1cba58 | 0x0 |
VirtualProtect | - | 0x8d405c | 0x4d405c | 0x1cba5c | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
timeEndPeriod | - | 0x8d4064 | 0x4d4064 | 0x1cba64 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSAGetOverlappedResult | - | 0x8d406c | 0x4d406c | 0x1cba6c | 0x0 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | First Execution |
![]() |
32-bit | 0x008D35A0 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x0044C760 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x0044B1F4 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x00426D61 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x0042A97A |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x00448950 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x00418EB0 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x00419000 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x004160D0 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x0041CBA0 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x00404980 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x0040FDD0 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x0042B3F0 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x00411260 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x0044A9B0 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x004497E0 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x0045C000 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Content Changed |
![]() |
32-bit | 0x00472FA0 |
![]() |
...
|
buffer | 1 | 0x32AFF000 | 0x32AFFFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x329FF000 | 0x329FFFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x328FE000 | 0x328FFFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x00E1F000 | 0x00E1FFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x0019D000 | 0x0019FFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x009B0000 | 0x009EFFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x009F0000 | 0x009FFFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x00A00000 | 0x00A0FFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x02580000 | 0x025C0FFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x127A0000 | 0x127DFFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x12800000 | 0x12BFFFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | First Network Behavior |
![]() |
32-bit | 0x00425B40 |
![]() |
...
|
dd286a4d79d0f4c2b906073c7f46680252ca09c1c39b0dc12c92097c56662876.exe | 1 | 0x00400000 | 0x008D4FFF | Process Termination |
![]() |
32-bit | - |
![]() |
...
|
C:\Users\#_THIS_FILE_IS_ENCRYPTED_[3A136CBCB741ABD6]-[ID-9893949947FDA5A23D8DE0930B74801F]-[EMAIL-MREncptor@protonmail.com].satan | Dropped File | Unknown |
N/A
Not Available because the file was not extracted successfully.
|
...
|
Also Known As | C:\Users\desktop.ini (Dropped File) |
MIME Type | - |
File Size | - |
MD5 | - |
SHA1 | - |
SHA256 | - |
SSDeep | - |
ImpHash | - |
C:\ProgramData\Microsoft\ClickToRun\4BAD322A-C043-4DED-A97A-6FE0C4412FBE\x-none.16\MasterDescriptor.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\4BAD322A-C043-4DED-A97A-6FE0C4412FBE\en-us.16\s321033.hash | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\4BAD322A-C043-4DED-A97A-6FE0C4412FBE\en-us.16\MasterDescriptor.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\4BAD322A-C043-4DED-A97A-6FE0C4412FBE\en-us.16\stream.x86.en-us.man.dat | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\4BAD322A-C043-4DED-A97A-6FE0C4412FBE\x-none.16\s320.hash | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\4BAD322A-C043-4DED-A97A-6FE0C4412FBE\x-none.16\stream.x86.x-none.man.dat | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\UserDeploymentConfiguration.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\DeploymentConfiguration.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.0.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\Manifest.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\UserManifest.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\AirSpace.Etw.man | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Access.Access.x-none.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.DCF.DCF.x-none.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Excel.Excel.x-none.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Groove.Groove.x-none.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Lync.Lync.x-none.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSM.OSM.x-none.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSMUX.OSMUX.x-none.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OneNote.OneNote.x-none.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Outlook.Outlook.x-none.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.PowerPivot.PowerPivot.x-none.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.PowerPoint.PowerPoint.x-none.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.es-es.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.fr-fr.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Publisher.Publisher.x-none.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Word.Word.x-none.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.accessmui.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.accessmuiset.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.dcfmui.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.excelmui.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.groovemui.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.lyncmui.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office64mui.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office64muiset.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office64ww.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.officemui.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.officemuiset.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.onenotemui.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmmui.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmuxmui.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.outlookmui.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.powerpointmui.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.proofing.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.publishermui.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.shared.Office.x-none.msi.16.x-none.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.wordmui.msi.16.en-us.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\Microsoft_Office_OfficeTelemetryAgentFallBack2016.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\Microsoft_Office_OfficeTelemetryAgentLogOn2016.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\msoutilstat.etw.man | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\wordEtw.man | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_03845cb8-7441-4a2f-8c0f-c90408af5778 | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Crypto\SystemKeys\1fd8a841971dc8f18facf1d9475e3f87_03845cb8-7441-4a2f-8c0f-c90408af5778 | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\Windows.Uif.static | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.ASM-WindowsDefault.json.bk | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json.bk | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\IdentityCRL\INT\ppcrlconfig600.dll | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\MF\Pending.GRL | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\MF\Active.GRL | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{18dcffd4-37d6-4bc6-87e0-4266fdbb8e49}\MasterDatastore.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{18dcffd4-37d6-4bc6-87e0-4266fdbb8e49}\Prov\RunTime\Power_0.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{18dcffd4-37d6-4bc6-87e0-4266fdbb8e49}\Prov\RunTime\Power_1.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{18dcffd4-37d6-4bc6-87e0-4266fdbb8e49}\Prov\RunTime.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{18dcffd4-37d6-4bc6-87e0-4266fdbb8e49}\customizations.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{1e05dd5d-a022-46c5-963c-b20de341170f}\MasterDatastore.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{1e05dd5d-a022-46c5-963c-b20de341170f}\Prov\RunTime\Power_1.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{1e05dd5d-a022-46c5-963c-b20de341170f}\Prov\RunTime.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{1e05dd5d-a022-46c5-963c-b20de341170f}\Prov\RunTime\Power_0.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{1e05dd5d-a022-46c5-963c-b20de341170f}\customizations.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{23cb517f-5073-4e96-a202-7fe6122a2271}\MasterDatastore.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{23cb517f-5073-4e96-a202-7fe6122a2271}\Prov\RunTime\Power_0.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{23cb517f-5073-4e96-a202-7fe6122a2271}\Prov\RunTime.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{23cb517f-5073-4e96-a202-7fe6122a2271}\Prov\RunTime\Power_1.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{23cb517f-5073-4e96-a202-7fe6122a2271}\customizations.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\MasterDatastore.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\Prov\RunTime\Power_1.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\Prov\RunTime\Power_2.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\Prov\RunTime\Power_0.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\Prov\RunTime.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\customizations.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{7a30a9be-737f-47a1-a541-6e7b0761ed19}\MasterDatastore.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{7a30a9be-737f-47a1-a541-6e7b0761ed19}\Prov\RunTime.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{7a30a9be-737f-47a1-a541-6e7b0761ed19}\Prov\RunTime\Power_1.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{7a30a9be-737f-47a1-a541-6e7b0761ed19}\Prov\RunTime\Power_2.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{7a30a9be-737f-47a1-a541-6e7b0761ed19}\Prov\RunTime\Power_0.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{7a30a9be-737f-47a1-a541-6e7b0761ed19}\customizations.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{8fb7d64e-70fc-4f9d-89ee-d486817534df}\MasterDatastore.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{8fb7d64e-70fc-4f9d-89ee-d486817534df}\Prov\RunTime\Power_0.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{8fb7d64e-70fc-4f9d-89ee-d486817534df}\Prov\RunTime.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{8fb7d64e-70fc-4f9d-89ee-d486817534df}\customizations.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{99b095d8-5959-4820-bea7-7448c8427b4e}\MasterDatastore.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{99b095d8-5959-4820-bea7-7448c8427b4e}\Prov\RunTime\Power_0.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{99b095d8-5959-4820-bea7-7448c8427b4e}\customizations.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{99b095d8-5959-4820-bea7-7448c8427b4e}\Prov\RunTime.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{9aec5bda-1e87-46b3-bb96-1a01c606555e}\MasterDatastore.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{9aec5bda-1e87-46b3-bb96-1a01c606555e}\Prov\RunTime\Power_0.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{9aec5bda-1e87-46b3-bb96-1a01c606555e}\Prov\RunTime.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{9aec5bda-1e87-46b3-bb96-1a01c606555e}\customizations.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{9df6a4ed-fc16-48bf-8b24-6e2ad2bfcfea}\MasterDatastore.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{9df6a4ed-fc16-48bf-8b24-6e2ad2bfcfea}\Prov\RunTime\Power_1.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{9df6a4ed-fc16-48bf-8b24-6e2ad2bfcfea}\Prov\RunTime\Power_0.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{9df6a4ed-fc16-48bf-8b24-6e2ad2bfcfea}\Prov\RunTime.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{9df6a4ed-fc16-48bf-8b24-6e2ad2bfcfea}\customizations.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{b0b9123d-7d7f-4c6b-9973-ceced46f2a09}\Prov\RunTime\Power_0.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{b0b9123d-7d7f-4c6b-9973-ceced46f2a09}\Prov\RunTime.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{b0b9123d-7d7f-4c6b-9973-ceced46f2a09}\MasterDatastore.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{b0b9123d-7d7f-4c6b-9973-ceced46f2a09}\customizations.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{c5dc3753-b6c8-4057-b396-bf13d769311c}\MasterDatastore.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{c5dc3753-b6c8-4057-b396-bf13d769311c}\Prov\RunTime.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{c5dc3753-b6c8-4057-b396-bf13d769311c}\Prov\RunTime\Power_0.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{c5dc3753-b6c8-4057-b396-bf13d769311c}\customizations.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{ee4aac98-c174-4941-82b1-d121e493e4fb}\MasterDatastore.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{ee4aac98-c174-4941-82b1-d121e493e4fb}\Prov\RunTime.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{ee4aac98-c174-4941-82b1-d121e493e4fb}\customizations.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{ee4aac98-c174-4941-82b1-d121e493e4fb}\Prov\RunTime\Power_0.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{f11899f2-71ec-4621-9997-e17ae2f6eb26}\MasterDatastore.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{f11899f2-71ec-4621-9997-e17ae2f6eb26}\Prov\RunTime\Power_0.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{f11899f2-71ec-4621-9997-e17ae2f6eb26}\Prov\RunTime\Power_1.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{f11899f2-71ec-4621-9997-e17ae2f6eb26}\Prov\RunTime.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{f11899f2-71ec-4621-9997-e17ae2f6eb26}\customizations.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\MasterDatastore.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\Power_0.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\Power_3.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\Power_1.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\Power_4.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\Power_2.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\Power_5.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\Power_6.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\Power_7.provxml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\customizations.xml | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\User Account Pictures\guest.bmp | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\User Account Pictures\guest.png | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\User Account Pictures\user-32.png | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\User Account Pictures\user-192.png | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\User Account Pictures\user-40.png | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\User Account Pictures\user-48.png | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\User Account Pictures\user.bmp | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\User Account Pictures\user.png | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\154E23D0-C644-4E6F-8CE6-5069272F999F.vsch | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\2F1A6504-0641-44CF-8BB5-3612D865F2E5.vsch | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\3CCD5499-87A8-4B10-A215-608888DD3B55.vsch | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\Policy.vpol | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{0FA68574-690B-4B00-89AA-B28946231449}v14.25.28508\packages\vcRuntimeAdditional_x86\cab1.cab | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{0FA68574-690B-4B00-89AA-B28946231449}v14.25.28508\packages\vcRuntimeAdditional_x86\vc_runtimeAdditional_x86.msi | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\cab1.cab | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\vc_runtimeMinimum_x86.msi | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{2BC3BD4D-FABA-4394-93C7-9AC82A263FE2}v14.25.28508\packages\vcRuntimeMinimum_x86\cab1.cab | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{2BC3BD4D-FABA-4394-93C7-9AC82A263FE2}v14.25.28508\packages\vcRuntimeMinimum_x86\vc_runtimeMinimum_x86.msi | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64\cab1.cab | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64\vc_runtimeAdditional_x64.msi | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{3c3aafc8-d898-43ec-998f-965ffdae065a}\state.rsm | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{3c3aafc8-d898-43ec-998f-965ffdae065a}\vcredist_x64.exe | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{65e650ff-30be-469d-b63a-418d71ea1765}\VC_redist.x86.exe | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{65e650ff-30be-469d-b63a-418d71ea1765}\state.rsm | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{6913e92a-b64e-41c9-a5e6-cef39207fe89}\VC_redist.x64.exe | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{6913e92a-b64e-41c9-a5e6-cef39207fe89}\state.rsm | Modified File | Stream |
clean
|
...
|
C:\ProgramData\Package Cache\{7D0B74C2-C3F8-4AF1-940F-CD79AB4B2DCE}v14.25.28508\packages\vcRuntimeAdditional_amd64\cab1.cab | Modified File | Stream |
clean
|
...
|
var winWidth = 800;
var winHeight = 600;
window.resizeTo(winWidth, winHeight);
window.moveTo(screen.width/2-winWidth/2, screen.height/2-winHeight/2);