VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
zprxqb.exe
Windows Exe (x86-32)
Created at 2019-05-29T16:19:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Suspicious
|
First Seen | 2019-05-28 11:01 (UTC+2) |
Last Seen | 2019-05-29 09:50 (UTC+2) |
Names | Win32.Trojan.Genkryptik |
Families | Genkryptik |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x409fa7 |
Size Of Code | 0x14200 |
Size Of Initialized Data | 0x63e00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-05-27 20:03:22+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x14043 | 0x14200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.63 |
.rdata | 0x416000 | 0x65be | 0x6600 | 0x14600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.76 |
.data | 0x41d000 | 0x5c240 | 0x5a400 | 0x1ac00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.99 |
.reloc | 0x47a000 | 0x1214 | 0x1400 | 0x75000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.22 |
Imports (2)
»
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x416120 | 0x1c084 | 0x1a684 | 0x246 |
KERNEL32.dll (71)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetEnvironmentStringsW | 0x0 | 0x416000 | 0x1bf64 | 0x1a564 | 0x227 |
CloseHandle | 0x0 | 0x416004 | 0x1bf68 | 0x1a568 | 0x7f |
lstrlenA | 0x0 | 0x416008 | 0x1bf6c | 0x1a56c | 0x608 |
GetModuleHandleA | 0x0 | 0x41600c | 0x1bf70 | 0x1a570 | 0x264 |
LoadLibraryA | 0x0 | 0x416010 | 0x1bf74 | 0x1a574 | 0x3a5 |
lstrcpyA | 0x0 | 0x416014 | 0x1bf78 | 0x1a578 | 0x602 |
lstrcatA | 0x0 | 0x416018 | 0x1bf7c | 0x1a57c | 0x5f9 |
GetProcAddress | 0x0 | 0x41601c | 0x1bf80 | 0x1a580 | 0x29d |
VirtualAlloc | 0x0 | 0x416020 | 0x1bf84 | 0x1a584 | 0x599 |
CreateThread | 0x0 | 0x416024 | 0x1bf88 | 0x1a588 | 0xe8 |
OutputDebugStringA | 0x0 | 0x416028 | 0x1bf8c | 0x1a58c | 0x3f9 |
ExitProcess | 0x0 | 0x41602c | 0x1bf90 | 0x1a590 | 0x151 |
CreateTimerQueueTimer | 0x0 | 0x416030 | 0x1bf94 | 0x1a594 | 0xf0 |
Sleep | 0x0 | 0x416034 | 0x1bf98 | 0x1a598 | 0x550 |
ExitThread | 0x0 | 0x416038 | 0x1bf9c | 0x1a59c | 0x152 |
EncodePointer | 0x0 | 0x41603c | 0x1bfa0 | 0x1a5a0 | 0x121 |
DecodePointer | 0x0 | 0x416040 | 0x1bfa4 | 0x1a5a4 | 0xfe |
RtlUnwind | 0x0 | 0x416044 | 0x1bfa8 | 0x1a5a8 | 0x4ac |
GetCommandLineA | 0x0 | 0x416048 | 0x1bfac | 0x1a5ac | 0x1c8 |
IsProcessorFeaturePresent | 0x0 | 0x41604c | 0x1bfb0 | 0x1a5b0 | 0x36d |
GetLastError | 0x0 | 0x416050 | 0x1bfb4 | 0x1a5b4 | 0x250 |
GetModuleHandleExW | 0x0 | 0x416054 | 0x1bfb8 | 0x1a5b8 | 0x266 |
MultiByteToWideChar | 0x0 | 0x416058 | 0x1bfbc | 0x1a5bc | 0x3d1 |
WideCharToMultiByte | 0x0 | 0x41605c | 0x1bfc0 | 0x1a5c0 | 0x5cb |
HeapSize | 0x0 | 0x416060 | 0x1bfc4 | 0x1a5c4 | 0x338 |
HeapFree | 0x0 | 0x416064 | 0x1bfc8 | 0x1a5c8 | 0x333 |
HeapAlloc | 0x0 | 0x416068 | 0x1bfcc | 0x1a5cc | 0x32f |
RaiseException | 0x0 | 0x41606c | 0x1bfd0 | 0x1a5d0 | 0x43f |
SetLastError | 0x0 | 0x416070 | 0x1bfd4 | 0x1a5d4 | 0x50a |
GetCurrentThreadId | 0x0 | 0x416074 | 0x1bfd8 | 0x1a5d8 | 0x20e |
GetProcessHeap | 0x0 | 0x416078 | 0x1bfdc | 0x1a5dc | 0x2a2 |
GetStdHandle | 0x0 | 0x41607c | 0x1bfe0 | 0x1a5e0 | 0x2c0 |
GetFileType | 0x0 | 0x416080 | 0x1bfe4 | 0x1a5e4 | 0x23e |
DeleteCriticalSection | 0x0 | 0x416084 | 0x1bfe8 | 0x1a5e8 | 0x105 |
GetStartupInfoW | 0x0 | 0x416088 | 0x1bfec | 0x1a5ec | 0x2be |
GetModuleFileNameA | 0x0 | 0x41608c | 0x1bff0 | 0x1a5f0 | 0x262 |
WriteFile | 0x0 | 0x416090 | 0x1bff4 | 0x1a5f4 | 0x5df |
GetModuleFileNameW | 0x0 | 0x416094 | 0x1bff8 | 0x1a5f8 | 0x263 |
QueryPerformanceCounter | 0x0 | 0x416098 | 0x1bffc | 0x1a5fc | 0x42d |
GetCurrentProcessId | 0x0 | 0x41609c | 0x1c000 | 0x1a600 | 0x20a |
GetSystemTimeAsFileTime | 0x0 | 0x4160a0 | 0x1c004 | 0x1a604 | 0x2d6 |
CreateFileW | 0x0 | 0x4160a4 | 0x1c008 | 0x1a608 | 0xc2 |
FreeEnvironmentStringsW | 0x0 | 0x4160a8 | 0x1c00c | 0x1a60c | 0x19d |
UnhandledExceptionFilter | 0x0 | 0x4160ac | 0x1c010 | 0x1a610 | 0x580 |
SetUnhandledExceptionFilter | 0x0 | 0x4160b0 | 0x1c014 | 0x1a614 | 0x541 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4160b4 | 0x1c018 | 0x1a618 | 0x348 |
GetCurrentProcess | 0x0 | 0x4160b8 | 0x1c01c | 0x1a61c | 0x209 |
TerminateProcess | 0x0 | 0x4160bc | 0x1c020 | 0x1a620 | 0x55f |
TlsAlloc | 0x0 | 0x4160c0 | 0x1c024 | 0x1a624 | 0x571 |
TlsGetValue | 0x0 | 0x4160c4 | 0x1c028 | 0x1a628 | 0x573 |
TlsSetValue | 0x0 | 0x4160c8 | 0x1c02c | 0x1a62c | 0x574 |
TlsFree | 0x0 | 0x4160cc | 0x1c030 | 0x1a630 | 0x572 |
GetModuleHandleW | 0x0 | 0x4160d0 | 0x1c034 | 0x1a634 | 0x267 |
IsDebuggerPresent | 0x0 | 0x4160d4 | 0x1c038 | 0x1a638 | 0x367 |
EnterCriticalSection | 0x0 | 0x4160d8 | 0x1c03c | 0x1a63c | 0x125 |
LeaveCriticalSection | 0x0 | 0x4160dc | 0x1c040 | 0x1a640 | 0x3a2 |
LoadLibraryExW | 0x0 | 0x4160e0 | 0x1c044 | 0x1a644 | 0x3a7 |
IsValidCodePage | 0x0 | 0x4160e4 | 0x1c048 | 0x1a648 | 0x372 |
GetACP | 0x0 | 0x4160e8 | 0x1c04c | 0x1a64c | 0x1a4 |
GetOEMCP | 0x0 | 0x4160ec | 0x1c050 | 0x1a650 | 0x286 |
GetCPInfo | 0x0 | 0x4160f0 | 0x1c054 | 0x1a654 | 0x1b3 |
HeapReAlloc | 0x0 | 0x4160f4 | 0x1c058 | 0x1a658 | 0x336 |
LCMapStringW | 0x0 | 0x4160f8 | 0x1c05c | 0x1a65c | 0x396 |
OutputDebugStringW | 0x0 | 0x4160fc | 0x1c060 | 0x1a660 | 0x3fa |
GetStringTypeW | 0x0 | 0x416100 | 0x1c064 | 0x1a664 | 0x2c5 |
FlushFileBuffers | 0x0 | 0x416104 | 0x1c068 | 0x1a668 | 0x192 |
GetConsoleCP | 0x0 | 0x416108 | 0x1c06c | 0x1a66c | 0x1dc |
GetConsoleMode | 0x0 | 0x41610c | 0x1c070 | 0x1a670 | 0x1ee |
SetStdHandle | 0x0 | 0x416110 | 0x1c074 | 0x1a674 | 0x520 |
SetFilePointerEx | 0x0 | 0x416114 | 0x1c078 | 0x1a678 | 0x4fc |
WriteConsoleW | 0x0 | 0x416118 | 0x1c07c | 0x1a67c | 0x5de |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
zprxqb.exe | 1 | 0x01330000 | 0x013ABFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00DD0000 | 0x00E28FFF | First Execution | - | 32-bit | 0x00DD1180, 0x00DD0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00120000 | 0x0017AFFF | Marked Executable | - | 32-bit | 0x001561CC, 0x00147A10, ... |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77BB0000 | 0x77D3DFFF | Content Changed | - | 32-bit | 0x77C16390, 0x77C23550, ... |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Adware.Kazy.734873 |
Suspicious
|
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Unknown |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Unknown |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd | Modified File | Unknown |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1025\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1030\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1040\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x64.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Setup.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupEngine.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUi.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUtility.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\sqmapi.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\HardwareEvents.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Internet Explorer.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\microsoft\windows\inetcache\counters2.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz.sgaA | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.LFwu | Dropped File | Stream |
Not Queried
|
...
|
»