VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: | - |
Threat Names: |
Gen:Heur.Ransom.Imps.1
Mal/Generic-S
|
Sofreg.exe
Windows Exe (x86-32)
Created at 2020-02-11T13:01:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Sofreg.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4029b0 |
Size Of Code | 0x6800 |
Size Of Initialized Data | 0x3600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-31 21:36:20+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x66af | 0x6800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.52 |
.rdata | 0x408000 | 0x1318 | 0x1400 | 0x6c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.35 |
.data | 0x40a000 | 0x35c | 0x0 | 0x0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.keys | 0x40b000 | 0x1706 | 0x1800 | 0x8000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.44 |
.rsrc | 0x40d000 | 0x1e0 | 0x200 | 0x9800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.7 |
.reloc | 0x40e000 | 0x290 | 0x400 | 0x9a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.81 |
Imports (6)
»
KERNEL32.dll (57)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetTickCount | 0x0 | 0x408068 | 0x8b98 | 0x7798 | 0x293 |
lstrcmpiW | 0x0 | 0x40806c | 0x8b9c | 0x779c | 0x545 |
lstrcpyA | 0x0 | 0x408070 | 0x8ba0 | 0x77a0 | 0x547 |
lstrcpyW | 0x0 | 0x408074 | 0x8ba4 | 0x77a4 | 0x548 |
lstrcatW | 0x0 | 0x408078 | 0x8ba8 | 0x77a8 | 0x53f |
lstrlenA | 0x0 | 0x40807c | 0x8bac | 0x77ac | 0x54d |
lstrlenW | 0x0 | 0x408080 | 0x8bb0 | 0x77b0 | 0x54e |
CreateEventW | 0x0 | 0x408084 | 0x8bb4 | 0x77b4 | 0x85 |
LoadLibraryW | 0x0 | 0x408088 | 0x8bb8 | 0x77b8 | 0x33f |
CreateProcessW | 0x0 | 0x40808c | 0x8bbc | 0x77bc | 0xa8 |
GetStartupInfoW | 0x0 | 0x408090 | 0x8bc0 | 0x77c0 | 0x263 |
GetDriveTypeW | 0x0 | 0x408094 | 0x8bc4 | 0x77c4 | 0x1d3 |
GetSystemDirectoryW | 0x0 | 0x408098 | 0x8bc8 | 0x77c8 | 0x270 |
GetWindowsDirectoryW | 0x0 | 0x40809c | 0x8bcc | 0x77cc | 0x2af |
GetFullPathNameW | 0x0 | 0x4080a0 | 0x8bd0 | 0x77d0 | 0x1fb |
CreateFileW | 0x0 | 0x4080a4 | 0x8bd4 | 0x77d4 | 0x8f |
SetFileAttributesW | 0x0 | 0x4080a8 | 0x8bd8 | 0x77d8 | 0x461 |
CloseHandle | 0x0 | 0x4080ac | 0x8bdc | 0x77dc | 0x52 |
FindFirstFileW | 0x0 | 0x4080b0 | 0x8be0 | 0x77e0 | 0x139 |
FindNextFileW | 0x0 | 0x4080b4 | 0x8be4 | 0x77e4 | 0x145 |
CopyFileW | 0x0 | 0x4080b8 | 0x8be8 | 0x77e8 | 0x75 |
MoveFileExW | 0x0 | 0x4080bc | 0x8bec | 0x77ec | 0x360 |
GetVolumeInformationA | 0x0 | 0x4080c0 | 0x8bf0 | 0x77f0 | 0x2a5 |
GetVolumeInformationW | 0x0 | 0x4080c4 | 0x8bf4 | 0x77f4 | 0x2a7 |
GetComputerNameW | 0x0 | 0x4080c8 | 0x8bf8 | 0x77f8 | 0x18f |
FindFirstVolumeA | 0x0 | 0x4080cc | 0x8bfc | 0x77fc | 0x13c |
FindNextVolumeA | 0x0 | 0x4080d0 | 0x8c00 | 0x7800 | 0x147 |
FindVolumeClose | 0x0 | 0x4080d4 | 0x8c04 | 0x7804 | 0x150 |
SetVolumeMountPointA | 0x0 | 0x4080d8 | 0x8c08 | 0x7808 | 0x4aa |
GetVolumePathNamesForVolumeNameA | 0x0 | 0x4080dc | 0x8c0c | 0x780c | 0x2ac |
WTSGetActiveConsoleSessionId | 0x0 | 0x4080e0 | 0x8c10 | 0x7810 | 0x4f4 |
MultiByteToWideChar | 0x0 | 0x4080e4 | 0x8c14 | 0x7814 | 0x367 |
GetLocaleInfoW | 0x0 | 0x4080e8 | 0x8c18 | 0x7818 | 0x206 |
GetNativeSystemInfo | 0x0 | 0x4080ec | 0x8c1c | 0x781c | 0x225 |
FindClose | 0x0 | 0x4080f0 | 0x8c20 | 0x7820 | 0x12e |
SetFilePointerEx | 0x0 | 0x4080f4 | 0x8c24 | 0x7824 | 0x467 |
ReadFile | 0x0 | 0x4080f8 | 0x8c28 | 0x7828 | 0x3c0 |
DeviceIoControl | 0x0 | 0x4080fc | 0x8c2c | 0x782c | 0xdd |
WriteFile | 0x0 | 0x408100 | 0x8c30 | 0x7830 | 0x525 |
GetFileSizeEx | 0x0 | 0x408104 | 0x8c34 | 0x7834 | 0x1f1 |
UnlockFile | 0x0 | 0x408108 | 0x8c38 | 0x7838 | 0x4d4 |
LockFile | 0x0 | 0x40810c | 0x8c3c | 0x783c | 0x352 |
GetLogicalDrives | 0x0 | 0x408110 | 0x8c40 | 0x7840 | 0x209 |
Sleep | 0x0 | 0x408114 | 0x8c44 | 0x7844 | 0x4b2 |
WaitForSingleObject | 0x0 | 0x408118 | 0x8c48 | 0x7848 | 0x4f9 |
GetLastError | 0x0 | 0x40811c | 0x8c4c | 0x784c | 0x202 |
TerminateProcess | 0x0 | 0x408120 | 0x8c50 | 0x7850 | 0x4c0 |
ExitProcess | 0x0 | 0x408124 | 0x8c54 | 0x7854 | 0x119 |
GetCurrentProcess | 0x0 | 0x408128 | 0x8c58 | 0x7858 | 0x1c0 |
GetProcessHeap | 0x0 | 0x40812c | 0x8c5c | 0x785c | 0x24a |
HeapFree | 0x0 | 0x408130 | 0x8c60 | 0x7860 | 0x2cf |
HeapAlloc | 0x0 | 0x408134 | 0x8c64 | 0x7864 | 0x2cb |
VirtualFree | 0x0 | 0x408138 | 0x8c68 | 0x7868 | 0x4ec |
VirtualAlloc | 0x0 | 0x40813c | 0x8c6c | 0x786c | 0x4e9 |
LocalFree | 0x0 | 0x408140 | 0x8c70 | 0x7870 | 0x348 |
GetFileAttributesW | 0x0 | 0x408144 | 0x8c74 | 0x7874 | 0x1ea |
GetProcAddress | 0x0 | 0x408148 | 0x8c78 | 0x7878 | 0x245 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfA | 0x0 | 0x408168 | 0x8c98 | 0x7898 | 0x332 |
wsprintfW | 0x0 | 0x40816c | 0x8c9c | 0x789c | 0x333 |
ADVAPI32.dll (20)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptGenRandom | 0x0 | 0x408000 | 0x8b30 | 0x7730 | 0xc1 |
CryptReleaseContext | 0x0 | 0x408004 | 0x8b34 | 0x7734 | 0xcb |
QueryServiceStatusEx | 0x0 | 0x408008 | 0x8b38 | 0x7738 | 0x229 |
OpenServiceA | 0x0 | 0x40800c | 0x8b3c | 0x773c | 0x1fa |
OpenSCManagerA | 0x0 | 0x408010 | 0x8b40 | 0x7740 | 0x1f8 |
EnumServicesStatusA | 0x0 | 0x408014 | 0x8b44 | 0x7744 | 0xff |
EnumDependentServicesA | 0x0 | 0x408018 | 0x8b48 | 0x7748 | 0xfc |
ControlService | 0x0 | 0x40801c | 0x8b4c | 0x774c | 0x5c |
CloseServiceHandle | 0x0 | 0x408020 | 0x8b50 | 0x7750 | 0x57 |
CryptEncrypt | 0x0 | 0x408024 | 0x8b54 | 0x7754 | 0xba |
CryptDestroyKey | 0x0 | 0x408028 | 0x8b58 | 0x7758 | 0xb7 |
CryptAcquireContextW | 0x0 | 0x40802c | 0x8b5c | 0x775c | 0xb1 |
RegQueryValueExW | 0x0 | 0x408030 | 0x8b60 | 0x7760 | 0x26e |
RegOpenKeyExW | 0x0 | 0x408034 | 0x8b64 | 0x7764 | 0x261 |
RegCloseKey | 0x0 | 0x408038 | 0x8b68 | 0x7768 | 0x230 |
DuplicateTokenEx | 0x0 | 0x40803c | 0x8b6c | 0x776c | 0xdf |
CreateProcessAsUserW | 0x0 | 0x408040 | 0x8b70 | 0x7770 | 0x7c |
GetUserNameW | 0x0 | 0x408044 | 0x8b74 | 0x7774 | 0x165 |
SetTokenInformation | 0x0 | 0x408048 | 0x8b78 | 0x7778 | 0x2c2 |
OpenProcessToken | 0x0 | 0x40804c | 0x8b7c | 0x777c | 0x1f7 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathW | 0x0 | 0x408150 | 0x8c80 | 0x7880 | 0xe1 |
SHLWAPI.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StrStrIA | 0x0 | 0x408158 | 0x8c88 | 0x7888 | 0x144 |
PathFindExtensionW | 0x0 | 0x40815c | 0x8c8c | 0x788c | 0x47 |
StrToIntA | 0x0 | 0x408160 | 0x8c90 | 0x7890 | 0x14b |
CRYPT32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptDecodeObjectEx | 0x0 | 0x408054 | 0x8b84 | 0x7784 | 0x83 |
CryptStringToBinaryW | 0x0 | 0x408058 | 0x8b88 | 0x7788 | 0xd9 |
CryptBinaryToStringA | 0x0 | 0x40805c | 0x8b8c | 0x778c | 0x7c |
CryptImportPublicKeyInfo | 0x0 | 0x408060 | 0x8b90 | 0x7790 | 0xa4 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
sofreg.exe | 1 | 0x002F0000 | 0x002FEFFF | First Execution |
![]() |
32-bit | 0x002F29B0 |
![]() |
![]() |
...
|
sofreg.exe | 1 | 0x002F0000 | 0x002FEFFF | Content Changed |
![]() |
32-bit | 0x002F11B5 |
![]() |
![]() |
...
|
sofreg.exe | 1 | 0x002F0000 | 0x002FEFFF | Content Changed |
![]() |
32-bit | 0x002F3000 |
![]() |
![]() |
...
|
sofreg.exe | 1 | 0x002F0000 | 0x002FEFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.1 |
Malicious
|
\\?\C:\Boot\BOOTSTAT.DAT.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.CFG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.FLT.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\CGMIMP32.FNT.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\EPSIMP32.FLT.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\JPEGIM32.FLT | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.CGM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.WPG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\PICTIM32.FLT.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\PNG32.FLT.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\WPGIMP32.FLT | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\ADO210.CHM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\MSOINTL.DLL.IDX_DLL | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\README.HTM.ragnar_FD7BD9FC | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUISet.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\ExcelMUI.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\GrooveMUI.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\InfoPathMUI.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OCT.CHM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUI.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUISet.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSCONFIG.CHM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10O.CHM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10R.CHM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.CHM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\Office32MUI.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.WW\Office32WW.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\OneNoteMUI.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\OutlookMUI.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\PowerPointMUI.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\PrjProrWW.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\ProjectMUI.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.en\Proof.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.fr\Proof.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\Proofing.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\ProPlusrWW.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\SETUP.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\VisiorWW.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\SETUP.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\WordMUI.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\pkeyconfig-office.xrm-ms | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MUAUTH.CAB | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppobjs-spp-plugin-manifest-signed.xrm-ms.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPWMI.MOF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_EN.LEX | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_ES.LEX.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\MCABOUT.HTM.ragnar_FD7BD9FC | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\STINTL.DLL.IDX_DLL | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\PHONE.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.DAT | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\TIME.XML | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\BASMLA.XSL | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\MSTAG.TLB.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\RECOVR32.CNV.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\Wks9Pxy.cnv.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\WPFT532.CNV | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\AFTRNOON.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\ARCTIC.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\ARCTIC.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\AXIS.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\BLENDS.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\BLUECALM.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\BLUEPRNT.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\BLUEPRNT.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\BOLDSTRI.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\BREEZE.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\CANYON.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\CANYON.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\CAPSULES.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\CASCADE.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\CASCADE.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\COMPASS.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\CONCRETE.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\CONCRETE.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\DEEPBLUE.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\DEEPBLUE.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\ECHO.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\EDGE.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\EDGE.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\EVRGREEN.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\EVRGREEN.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\EXPEDITN.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\EXPEDITN.INF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\ICE.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\ICE.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\INDUST.ELM | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\PREVIEW.GIF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\IRIS.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\IRIS.INF | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\PREVIEW.GIF.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\JOURNAL.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\RGNR_FD7BD9FC.txt | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.CNT | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\eqnedt32.exe.manifest | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.HLP.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\MTEXTRA.TTF.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\GIFIMP32.FLT.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\MSOINTL.REST.IDX_DLL.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUI.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\BRANDING.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.es\Proof.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\PublisherMUI.XML | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\VisioMUI.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\PROOF\MSWDS_FR.LEX.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\DATES.XML.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\TextConv\WPFT632.CNV.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\AFTRNOON.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\AXIS.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\BLENDS.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\BLUECALM.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\BOLDSTRI.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\THMBNAIL.PNG.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\BREEZE.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\CAPSULES.ELM | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\COMPASS.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\ECHO.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\ECLIPSE.ELM.ragnar_FD7BD9FC | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\ECLIPSE.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\INDUST.INF | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»