VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Heur.Trickbot.3
Gen:Variant.Ser.Mikey.2021
Mal/Generic-S
|
sync.bad.exe
Windows Exe (x86-32)
Created at 2020-05-04T14:35:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402cdb |
Size Of Code | 0x1e00 |
Size Of Initialized Data | 0x1600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-04-30 19:57:11+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1de0 | 0x1e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.19 |
.rdata | 0x403000 | 0x134e | 0x1400 | 0x2200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.17 |
.data | 0x405000 | 0x104 | 0x200 | 0x3600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.27 |
Imports (1)
»
KERNEL32.dll (25)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitProcess | 0x0 | 0x403000 | 0x4114 | 0x3314 | 0x119 |
FindFirstFileW | 0x0 | 0x403004 | 0x4118 | 0x3318 | 0x139 |
HeapAlloc | 0x0 | 0x403008 | 0x411c | 0x331c | 0x2cb |
SetFilePointerEx | 0x0 | 0x40300c | 0x4120 | 0x3320 | 0x467 |
HeapFree | 0x0 | 0x403010 | 0x4124 | 0x3324 | 0x2cf |
WaitForSingleObject | 0x0 | 0x403014 | 0x4128 | 0x3328 | 0x4f9 |
GetLogicalDrives | 0x0 | 0x403018 | 0x412c | 0x332c | 0x209 |
GetProcessHeap | 0x0 | 0x40301c | 0x4130 | 0x3330 | 0x24a |
WriteFile | 0x0 | 0x403020 | 0x4134 | 0x3334 | 0x525 |
ReadFile | 0x0 | 0x403024 | 0x4138 | 0x3338 | 0x3c0 |
CreateFileW | 0x0 | 0x403028 | 0x413c | 0x333c | 0x8f |
GetFileSizeEx | 0x0 | 0x40302c | 0x4140 | 0x3340 | 0x1f1 |
GetLastError | 0x0 | 0x403030 | 0x4144 | 0x3344 | 0x202 |
SetLastError | 0x0 | 0x403034 | 0x4148 | 0x3348 | 0x473 |
MoveFileW | 0x0 | 0x403038 | 0x414c | 0x334c | 0x363 |
FindClose | 0x0 | 0x40303c | 0x4150 | 0x3350 | 0x12e |
lstrcmpiW | 0x0 | 0x403040 | 0x4154 | 0x3354 | 0x545 |
lstrcatW | 0x0 | 0x403044 | 0x4158 | 0x3358 | 0x53f |
FindNextFileW | 0x0 | 0x403048 | 0x415c | 0x335c | 0x145 |
CloseHandle | 0x0 | 0x40304c | 0x4160 | 0x3360 | 0x52 |
lstrcpyW | 0x0 | 0x403050 | 0x4164 | 0x3364 | 0x548 |
GetTempPathW | 0x0 | 0x403054 | 0x4168 | 0x3368 | 0x285 |
LoadLibraryA | 0x0 | 0x403058 | 0x416c | 0x336c | 0x33c |
CreateMutexA | 0x0 | 0x40305c | 0x4170 | 0x3370 | 0x9b |
GetCommandLineW | 0x0 | 0x403060 | 0x4174 | 0x3374 | 0x187 |
Digital Signatures (2)
»
Certificate: Svos Pty Limited
»
Issued by | Svos Pty Limited |
Parent Certificate | Sectigo RSA Code Signing CA |
Country Name | AU |
Valid From | 2020-04-24 00:00:00+00:00 |
Valid Until | 2021-04-24 23:59:59+00:00 |
Algorithm | sha256_rsa |
Serial Number | A2 F9 03 86 D3 77 F7 F9 13 35 45 4C 4D 7E FA 9A |
Thumbprint | 2C 88 39 29 05 AC 24 50 5B 7C 15 84 F4 9E AF A3 98 22 74 5C |
Certificate: Sectigo RSA Code Signing CA
»
Issued by | Sectigo RSA Code Signing CA |
Country Name | GB |
Valid From | 2018-11-02 00:00:00+00:00 |
Valid Until | 2030-12-31 23:59:59+00:00 |
Algorithm | sha384_rsa |
Serial Number | 1D A2 48 30 6F 9B 26 18 D0 82 E0 96 7D 33 D3 6A |
Thumbprint | 94 C9 5D A1 E8 50 BD 85 20 9A 4A 2A F3 E1 FB 16 04 F9 BB 66 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
sync.bad.exe | 1 | 0x00400000 | 0x00405FFF | Relevant Image |
![]() |
32-bit | 0x00401BF7 |
![]() |
![]() |
...
|
sync.bad.exe | 1 | 0x00400000 | 0x00405FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Trickbot.3 |
Malicious
|
C:/$WINRE_BACKUP_PARTITION.MARKER.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1025\eula.rtf.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1028\eula.rtf.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1028\LocalizedData.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1032\eula.rtf.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1036\eula.rtf.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1036\LocalizedData.xml.OFFWHITE | Dropped File | Binary |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1038\eula.rtf.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1044\LocalizedData.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1049\LocalizedData.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1053\eula.rtf.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\2052\eula.rtf.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\2052\LocalizedData.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\3076\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Client\Parameterinfo.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Client\UiInfo.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Extended\UiInfo.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate2.ico.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate3.ico.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate4.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate7.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Save.ico.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\warn.ico.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\netfx_Core.mzz.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\netfx_Extended.mzz.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\SetupUi.xsd.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Application.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Key Management Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-MUI%4Admin.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-MUI%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-NCSI%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Ntfs%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Ntfs%4WHC.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Store%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\0D0D4EEB-DC03-4B3F-88DF-959FE1EDE5F4\en-us.16\MasterDescriptor.en-us.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\0D0D4EEB-DC03-4B3F-88DF-959FE1EDE5F4\en-us.16\stream.x64.en-us.man.dat.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\0D0D4EEB-DC03-4B3F-88DF-959FE1EDE5F4\x-none.16\s640.hash.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\19B11135-37BD-4FA1-A78E-C20CA2BDA1C0\en-us.16\MasterDescriptor.en-us.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\19B11135-37BD-4FA1-A78E-C20CA2BDA1C0\en-us.16\s641033.hash.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\19B11135-37BD-4FA1-A78E-C20CA2BDA1C0\en-us.16\stream.x64.en-us.man.dat.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\19B11135-37BD-4FA1-A78E-C20CA2BDA1C0\x-none.16\MasterDescriptor.x-none.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\19B11135-37BD-4FA1-A78E-C20CA2BDA1C0\x-none.16\stream.x64.x-none.man.dat.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\201EB7DF-C721-4B8B-9C81-A09DE7F931E6\en-us.16\MasterDescriptor.en-us.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\201EB7DF-C721-4B8B-9C81-A09DE7F931E6\en-us.16\s641033.hash.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\201EB7DF-C721-4B8B-9C81-A09DE7F931E6\x-none.16\MasterDescriptor.x-none.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\201EB7DF-C721-4B8B-9C81-A09DE7F931E6\x-none.16\stream.x64.x-none.man.dat.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\DeploymentConfig.0.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\DeploymentConfig.1.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\Manifest.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\UserDeploymentConfiguration.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\UserManifest.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\en-us.16\MasterDescriptor.en-us.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\en-us.16\stream.Platform.Culture.man.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\en-us.16\stream.x86.en-us.hash.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\x-none.16\stream.Platform.x-none.man.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\x-none.16\stream.x86.x-none.man.dat.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\ProductReleases\A6A87302-92AE-41F2-AC52-73F5EE18259F\x-none.16\stream.x86.x-none.man.dat.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\AirSpace.Etw.man.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Access.Access.x-none.msi.16.x-none.xml.OFFWHITE | Modified File | Binary |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.accessmui.msi.16.en-us.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.accessmuiset.msi.16.en-us.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.DCF.DCF.x-none.msi.16.x-none.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.dcfmui.msi.16.en-us.xml.OFFWHITE | Dropped File | Compressed |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.excelmui.msi.16.en-us.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Groove.Groove.x-none.msi.16.x-none.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Lync.Lync.x-none.msi.16.x-none.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.lyncmui.msi.16.en-us.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office32mui.msi.16.en-us.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.officemui.msi.16.en-us.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.officemuiset.msi.16.en-us.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OneNote.OneNote.x-none.msi.16.x-none.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSMUX.OSMUX.x-none.msi.16.x-none.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Outlook.Outlook.x-none.msi.16.x-none.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.outlookmui.msi.16.en-us.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.PowerPivot.PowerPivot.x-none.msi.16.x-none.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Project.Project.x-none.msi.16.x-none.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.en-us.xml.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.es-es.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.shared.Office.x-none.msi.16.x-none.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1051304884-625712362-2192934891-1000\8de6a3e28b34ce2307b3688fc9d4e39d_33d770d0-06bc-47c5-8714-222cdac43a71 | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1025\LocalizedData.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1033\LocalizedData.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1037\eula.rtf.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1037\LocalizedData.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1041\LocalizedData.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1042\LocalizedData.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1043\LocalizedData.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1044\eula.rtf.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1045\LocalizedData.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1046\LocalizedData.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1049\eula.rtf.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1055\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\3082\eula.rtf.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\3082\LocalizedData.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\Extended\Parameterinfo.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\Graphics\Print.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate8.ico.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\Graphics\Setup.ico.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\ParameterInfo.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\SplashScreen.bmp.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\Strings.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\watermark.bmp.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Internet Explorer.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Known Folders API Service.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-SettingSync%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-SmbClient%4Security.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-TWinUI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Winlogon%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Windows PowerShell.evtx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Recovery\ReAgentOld.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\0D0D4EEB-DC03-4B3F-88DF-959FE1EDE5F4\en-us.16\s641033.hash.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\0D0D4EEB-DC03-4B3F-88DF-959FE1EDE5F4\x-none.16\MasterDescriptor.x-none.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\0D0D4EEB-DC03-4B3F-88DF-959FE1EDE5F4\x-none.16\stream.x64.x-none.man.dat.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\19B11135-37BD-4FA1-A78E-C20CA2BDA1C0\x-none.16\s640.hash.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\201EB7DF-C721-4B8B-9C81-A09DE7F931E6\en-us.16\stream.x64.en-us.man.dat.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\201EB7DF-C721-4B8B-9C81-A09DE7F931E6\x-none.16\s640.hash.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\DeploymentConfig.2.xml.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\DeploymentConfiguration.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\en-us.16\s321033.hash.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\en-us.16\stream.x86.en-us.man.dat.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\x-none.16\MasterDescriptor.x-none.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\x-none.16\s320.hash.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\x-none.16\stream.x86.x-none.hash.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\ProductReleases\A6A87302-92AE-41F2-AC52-73F5EE18259F\en-us.16\stream.x86.en-us.man.dat.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Excel.Excel.x-none.msi.16.x-none.xml.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.groovemui.msi.16.en-us.xml.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office32ww.msi.16.x-none.xml.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.onenotemui.msi.16.en-us.xml.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSM.OSM.x-none.msi.16.x-none.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmmui.msi.16.en-us.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmuxmui.msi.16.en-us.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.PowerPoint.PowerPoint.x-none.msi.16.x-none.xml.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.powerpointmui.msi.16.en-us.xml.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.projectmui.msi.16.en-us.xml.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.fr-fr.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.proofing.msi.16.en-us.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Publisher.Publisher.x-none.msi.16.x-none.xml.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.publishermui.msi.16.en-us.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Visio.Visio.x-none.msi.16.x-none.xml.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»