Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
Trojan
...
|
Threat Names: |
Generic.Ransom.Matrix.D7248D5E
Trojan.GenericKD.40672878
Generic.Ransom.Matrix.0D6A71DB
...
|
bwng.exe
Created at 2020-01-21T14:54:00
Remarks (2/2)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "6 minutes" to "1 minute" to reveal dormant functionality.
(0x0200003A): A task was rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200000C): The maximum memory dump size was exceeded. Some dumps may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bwng.exe | Sample File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2020-01-15 13:31 (UTC+1) |
Last Seen | 2020-01-15 17:52 (UTC+1) |
Names | Win32.Trojan.Matrix |
Families | Matrix |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x4dca54 |
Size Of Code | 0xe0400 |
Size Of Initialized Data | 0x49c00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-12-13 21:52:42+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xdaf04 | 0xdb000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.38 |
.itext | 0x4dc000 | 0x52d8 | 0x5400 | 0xdb400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.74 |
.data | 0x4e2000 | 0x5b08 | 0x5c00 | 0xe0800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.19 |
.bss | 0x4e8000 | 0x645c | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x4ef000 | 0x1236 | 0x1400 | 0xe6400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.81 |
.didata | 0x4f1000 | 0xfa | 0x200 | 0xe7800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.0 |
.edata | 0x4f2000 | 0x6c | 0x200 | 0xe7a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.31 |
.tls | 0x4f3000 | 0x14 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x4f4000 | 0x18 | 0x200 | 0xe7c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.21 |
.rsrc | 0x4f5000 | 0x42600 | 0x42600 | 0xe7e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.96 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x4ef36c | 0xef0b4 | 0xe64b4 | 0x0 |
SysReAllocStringLen | 0x0 | 0x4ef370 | 0xef0b8 | 0xe64b8 | 0x0 |
SysAllocStringLen | 0x0 | 0x4ef374 | 0xef0bc | 0xe64bc | 0x0 |
SafeArrayPtrOfIndex | 0x0 | 0x4ef378 | 0xef0c0 | 0xe64c0 | 0x0 |
SafeArrayGetUBound | 0x0 | 0x4ef37c | 0xef0c4 | 0xe64c4 | 0x0 |
SafeArrayGetLBound | 0x0 | 0x4ef380 | 0xef0c8 | 0xe64c8 | 0x0 |
SafeArrayCreate | 0x0 | 0x4ef384 | 0xef0cc | 0xe64cc | 0x0 |
VariantChangeType | 0x0 | 0x4ef388 | 0xef0d0 | 0xe64d0 | 0x0 |
VariantCopy | 0x0 | 0x4ef38c | 0xef0d4 | 0xe64d4 | 0x0 |
VariantClear | 0x0 | 0x4ef390 | 0xef0d8 | 0xe64d8 | 0x0 |
VariantInit | 0x0 | 0x4ef394 | 0xef0dc | 0xe64dc | 0x0 |
GetErrorInfo | 0x0 | 0x4ef398 | 0xef0e0 | 0xe64e0 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExW | 0x0 | 0x4ef3a0 | 0xef0e8 | 0xe64e8 | 0x0 |
RegOpenKeyExW | 0x0 | 0x4ef3a4 | 0xef0ec | 0xe64ec | 0x0 |
RegCloseKey | 0x0 | 0x4ef3a8 | 0xef0f0 | 0xe64f0 | 0x0 |
OpenThreadToken | 0x0 | 0x4ef3ac | 0xef0f4 | 0xe64f4 | 0x0 |
OpenProcessToken | 0x0 | 0x4ef3b0 | 0xef0f8 | 0xe64f8 | 0x0 |
GetUserNameA | 0x0 | 0x4ef3b4 | 0xef0fc | 0xe64fc | 0x0 |
GetTokenInformation | 0x0 | 0x4ef3b8 | 0xef100 | 0xe6500 | 0x0 |
GetSidSubAuthorityCount | 0x0 | 0x4ef3bc | 0xef104 | 0xe6504 | 0x0 |
GetSidSubAuthority | 0x0 | 0x4ef3c0 | 0xef108 | 0xe6508 | 0x0 |
FreeSid | 0x0 | 0x4ef3c4 | 0xef10c | 0xe650c | 0x0 |
EqualSid | 0x0 | 0x4ef3c8 | 0xef110 | 0xe6510 | 0x0 |
AllocateAndInitializeSid | 0x0 | 0x4ef3cc | 0xef114 | 0xe6514 | 0x0 |
CryptGenRandom | 0x0 | 0x4ef3d0 | 0xef118 | 0xe6518 | 0x0 |
CryptReleaseContext | 0x0 | 0x4ef3d4 | 0xef11c | 0xe651c | 0x0 |
CryptAcquireContextW | 0x0 | 0x4ef3d8 | 0xef120 | 0xe6520 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x4ef3e0 | 0xef128 | 0xe6528 | 0x0 |
CharNextW | 0x0 | 0x4ef3e4 | 0xef12c | 0xe652c | 0x0 |
LoadStringW | 0x0 | 0x4ef3e8 | 0xef130 | 0xe6530 | 0x0 |
PeekMessageW | 0x0 | 0x4ef3ec | 0xef134 | 0xe6534 | 0x0 |
MsgWaitForMultipleObjects | 0x0 | 0x4ef3f0 | 0xef138 | 0xe6538 | 0x0 |
MessageBoxW | 0x0 | 0x4ef3f4 | 0xef13c | 0xe653c | 0x0 |
GetSystemMetrics | 0x0 | 0x4ef3f8 | 0xef140 | 0xe6540 | 0x0 |
CharUpperBuffW | 0x0 | 0x4ef3fc | 0xef144 | 0xe6544 | 0x0 |
CharUpperW | 0x0 | 0x4ef400 | 0xef148 | 0xe6548 | 0x0 |
CharLowerBuffW | 0x0 | 0x4ef404 | 0xef14c | 0xe654c | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x4ef40c | 0xef154 | 0xe6554 | 0x0 |
VirtualFree | 0x0 | 0x4ef410 | 0xef158 | 0xe6558 | 0x0 |
VirtualAlloc | 0x0 | 0x4ef414 | 0xef15c | 0xe655c | 0x0 |
lstrlenW | 0x0 | 0x4ef418 | 0xef160 | 0xe6560 | 0x0 |
VirtualQuery | 0x0 | 0x4ef41c | 0xef164 | 0xe6564 | 0x0 |
GetTickCount | 0x0 | 0x4ef420 | 0xef168 | 0xe6568 | 0x0 |
GetSystemInfo | 0x0 | 0x4ef424 | 0xef16c | 0xe656c | 0x0 |
GetVersion | 0x0 | 0x4ef428 | 0xef170 | 0xe6570 | 0x0 |
CompareStringW | 0x0 | 0x4ef42c | 0xef174 | 0xe6574 | 0x0 |
IsDBCSLeadByteEx | 0x0 | 0x4ef430 | 0xef178 | 0xe6578 | 0x0 |
IsValidLocale | 0x0 | 0x4ef434 | 0xef17c | 0xe657c | 0x0 |
SetThreadLocale | 0x0 | 0x4ef438 | 0xef180 | 0xe6580 | 0x0 |
GetSystemDefaultUILanguage | 0x0 | 0x4ef43c | 0xef184 | 0xe6584 | 0x0 |
GetUserDefaultUILanguage | 0x0 | 0x4ef440 | 0xef188 | 0xe6588 | 0x0 |
GetLocaleInfoW | 0x0 | 0x4ef444 | 0xef18c | 0xe658c | 0x0 |
WideCharToMultiByte | 0x0 | 0x4ef448 | 0xef190 | 0xe6590 | 0x0 |
MultiByteToWideChar | 0x0 | 0x4ef44c | 0xef194 | 0xe6594 | 0x0 |
GetConsoleOutputCP | 0x0 | 0x4ef450 | 0xef198 | 0xe6598 | 0x0 |
GetConsoleCP | 0x0 | 0x4ef454 | 0xef19c | 0xe659c | 0x0 |
GetACP | 0x0 | 0x4ef458 | 0xef1a0 | 0xe65a0 | 0x0 |
LoadLibraryExW | 0x0 | 0x4ef45c | 0xef1a4 | 0xe65a4 | 0x0 |
GetStartupInfoW | 0x0 | 0x4ef460 | 0xef1a8 | 0xe65a8 | 0x0 |
GetProcAddress | 0x0 | 0x4ef464 | 0xef1ac | 0xe65ac | 0x0 |
GetModuleHandleW | 0x0 | 0x4ef468 | 0xef1b0 | 0xe65b0 | 0x0 |
GetModuleFileNameW | 0x0 | 0x4ef46c | 0xef1b4 | 0xe65b4 | 0x0 |
GetCommandLineW | 0x0 | 0x4ef470 | 0xef1b8 | 0xe65b8 | 0x0 |
FreeLibrary | 0x0 | 0x4ef474 | 0xef1bc | 0xe65bc | 0x0 |
GetLastError | 0x0 | 0x4ef478 | 0xef1c0 | 0xe65c0 | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x4ef47c | 0xef1c4 | 0xe65c4 | 0x0 |
RtlUnwind | 0x0 | 0x4ef480 | 0xef1c8 | 0xe65c8 | 0x0 |
RaiseException | 0x0 | 0x4ef484 | 0xef1cc | 0xe65cc | 0x0 |
ExitProcess | 0x0 | 0x4ef488 | 0xef1d0 | 0xe65d0 | 0x0 |
ExitThread | 0x0 | 0x4ef48c | 0xef1d4 | 0xe65d4 | 0x0 |
SwitchToThread | 0x0 | 0x4ef490 | 0xef1d8 | 0xe65d8 | 0x0 |
GetCurrentThreadId | 0x0 | 0x4ef494 | 0xef1dc | 0xe65dc | 0x0 |
CreateThread | 0x0 | 0x4ef498 | 0xef1e0 | 0xe65e0 | 0x0 |
DeleteCriticalSection | 0x0 | 0x4ef49c | 0xef1e4 | 0xe65e4 | 0x0 |
LeaveCriticalSection | 0x0 | 0x4ef4a0 | 0xef1e8 | 0xe65e8 | 0x0 |
EnterCriticalSection | 0x0 | 0x4ef4a4 | 0xef1ec | 0xe65ec | 0x0 |
InitializeCriticalSection | 0x0 | 0x4ef4a8 | 0xef1f0 | 0xe65f0 | 0x0 |
FindFirstFileW | 0x0 | 0x4ef4ac | 0xef1f4 | 0xe65f4 | 0x0 |
FindClose | 0x0 | 0x4ef4b0 | 0xef1f8 | 0xe65f8 | 0x0 |
WriteFile | 0x0 | 0x4ef4b4 | 0xef1fc | 0xe65fc | 0x0 |
SetFilePointer | 0x0 | 0x4ef4b8 | 0xef200 | 0xe6600 | 0x0 |
SetEndOfFile | 0x0 | 0x4ef4bc | 0xef204 | 0xe6604 | 0x0 |
ReadFile | 0x0 | 0x4ef4c0 | 0xef208 | 0xe6608 | 0x0 |
GetFileType | 0x0 | 0x4ef4c4 | 0xef20c | 0xe660c | 0x0 |
GetFileSize | 0x0 | 0x4ef4c8 | 0xef210 | 0xe6610 | 0x0 |
CreateFileW | 0x0 | 0x4ef4cc | 0xef214 | 0xe6614 | 0x0 |
GetStdHandle | 0x0 | 0x4ef4d0 | 0xef218 | 0xe6618 | 0x0 |
CloseHandle | 0x0 | 0x4ef4d4 | 0xef21c | 0xe661c | 0x0 |
LoadLibraryA | 0x0 | 0x4ef4d8 | 0xef220 | 0xe6620 | 0x0 |
TlsSetValue | 0x0 | 0x4ef4dc | 0xef224 | 0xe6624 | 0x0 |
TlsGetValue | 0x0 | 0x4ef4e0 | 0xef228 | 0xe6628 | 0x0 |
LocalFree | 0x0 | 0x4ef4e4 | 0xef22c | 0xe662c | 0x0 |
LocalAlloc | 0x0 | 0x4ef4e8 | 0xef230 | 0xe6630 | 0x0 |
WaitForSingleObject | 0x0 | 0x4ef4ec | 0xef234 | 0xe6634 | 0x0 |
WaitForMultipleObjects | 0x0 | 0x4ef4f0 | 0xef238 | 0xe6638 | 0x0 |
VirtualQueryEx | 0x0 | 0x4ef4f4 | 0xef23c | 0xe663c | 0x0 |
VirtualProtect | 0x0 | 0x4ef4f8 | 0xef240 | 0xe6640 | 0x0 |
VerSetConditionMask | 0x0 | 0x4ef4fc | 0xef244 | 0xe6644 | 0x0 |
VerifyVersionInfoW | 0x0 | 0x4ef500 | 0xef248 | 0xe6648 | 0x0 |
SuspendThread | 0x0 | 0x4ef504 | 0xef24c | 0xe664c | 0x0 |
SizeofResource | 0x0 | 0x4ef508 | 0xef250 | 0xe6650 | 0x0 |
SetThreadPriority | 0x0 | 0x4ef50c | 0xef254 | 0xe6654 | 0x0 |
SetLastError | 0x0 | 0x4ef510 | 0xef258 | 0xe6658 | 0x0 |
SetFileAttributesW | 0x0 | 0x4ef514 | 0xef25c | 0xe665c | 0x0 |
SetEvent | 0x0 | 0x4ef518 | 0xef260 | 0xe6660 | 0x0 |
SetErrorMode | 0x0 | 0x4ef51c | 0xef264 | 0xe6664 | 0x0 |
ResumeThread | 0x0 | 0x4ef520 | 0xef268 | 0xe6668 | 0x0 |
ResetEvent | 0x0 | 0x4ef524 | 0xef26c | 0xe666c | 0x0 |
ReleaseMutex | 0x0 | 0x4ef528 | 0xef270 | 0xe6670 | 0x0 |
QueryPerformanceFrequency | 0x0 | 0x4ef52c | 0xef274 | 0xe6674 | 0x0 |
QueryPerformanceCounter | 0x0 | 0x4ef530 | 0xef278 | 0xe6678 | 0x0 |
OpenMutexW | 0x0 | 0x4ef534 | 0xef27c | 0xe667c | 0x0 |
MoveFileExW | 0x0 | 0x4ef538 | 0xef280 | 0xe6680 | 0x0 |
LockResource | 0x0 | 0x4ef53c | 0xef284 | 0xe6684 | 0x0 |
LoadResource | 0x0 | 0x4ef540 | 0xef288 | 0xe6688 | 0x0 |
LoadLibraryW | 0x0 | 0x4ef544 | 0xef28c | 0xe668c | 0x0 |
HeapFree | 0x0 | 0x4ef548 | 0xef290 | 0xe6690 | 0x0 |
HeapDestroy | 0x0 | 0x4ef54c | 0xef294 | 0xe6694 | 0x0 |
HeapCreate | 0x0 | 0x4ef550 | 0xef298 | 0xe6698 | 0x0 |
HeapAlloc | 0x0 | 0x4ef554 | 0xef29c | 0xe669c | 0x0 |
GetVolumeInformationW | 0x0 | 0x4ef558 | 0xef2a0 | 0xe66a0 | 0x0 |
GetVersionExW | 0x0 | 0x4ef55c | 0xef2a4 | 0xe66a4 | 0x0 |
GetUserDefaultLangID | 0x0 | 0x4ef560 | 0xef2a8 | 0xe66a8 | 0x0 |
GetUserDefaultLCID | 0x0 | 0x4ef564 | 0xef2ac | 0xe66ac | 0x0 |
GetThreadTimes | 0x0 | 0x4ef568 | 0xef2b0 | 0xe66b0 | 0x0 |
GetThreadPriority | 0x0 | 0x4ef56c | 0xef2b4 | 0xe66b4 | 0x0 |
GetThreadLocale | 0x0 | 0x4ef570 | 0xef2b8 | 0xe66b8 | 0x0 |
GetSystemTimes | 0x0 | 0x4ef574 | 0xef2bc | 0xe66bc | 0x0 |
GetSystemDefaultLangID | 0x0 | 0x4ef578 | 0xef2c0 | 0xe66c0 | 0x0 |
GetSystemDefaultLCID | 0x0 | 0x4ef57c | 0xef2c4 | 0xe66c4 | 0x0 |
GetProcessTimes | 0x0 | 0x4ef580 | 0xef2c8 | 0xe66c8 | 0x0 |
GetLocalTime | 0x0 | 0x4ef584 | 0xef2cc | 0xe66cc | 0x0 |
GetFullPathNameW | 0x0 | 0x4ef588 | 0xef2d0 | 0xe66d0 | 0x0 |
GetFileAttributesW | 0x0 | 0x4ef58c | 0xef2d4 | 0xe66d4 | 0x0 |
GetExitCodeThread | 0x0 | 0x4ef590 | 0xef2d8 | 0xe66d8 | 0x0 |
GetDriveTypeW | 0x0 | 0x4ef594 | 0xef2dc | 0xe66dc | 0x0 |
GetDiskFreeSpaceW | 0x0 | 0x4ef598 | 0xef2e0 | 0xe66e0 | 0x0 |
GetDateFormatW | 0x0 | 0x4ef59c | 0xef2e4 | 0xe66e4 | 0x0 |
GetCurrentThread | 0x0 | 0x4ef5a0 | 0xef2e8 | 0xe66e8 | 0x0 |
GetCurrentProcessId | 0x0 | 0x4ef5a4 | 0xef2ec | 0xe66ec | 0x0 |
GetCurrentProcess | 0x0 | 0x4ef5a8 | 0xef2f0 | 0xe66f0 | 0x0 |
GetComputerNameA | 0x0 | 0x4ef5ac | 0xef2f4 | 0xe66f4 | 0x0 |
GetCPInfoExW | 0x0 | 0x4ef5b0 | 0xef2f8 | 0xe66f8 | 0x0 |
GetCPInfo | 0x0 | 0x4ef5b4 | 0xef2fc | 0xe66fc | 0x0 |
FreeResource | 0x0 | 0x4ef5b8 | 0xef300 | 0xe6700 | 0x0 |
InterlockedCompareExchange | 0x0 | 0x4ef5bc | 0xef304 | 0xe6704 | 0x0 |
FormatMessageW | 0x0 | 0x4ef5c0 | 0xef308 | 0xe6708 | 0x0 |
FindResourceW | 0x0 | 0x4ef5c4 | 0xef30c | 0xe670c | 0x0 |
FindNextFileW | 0x0 | 0x4ef5c8 | 0xef310 | 0xe6710 | 0x0 |
ExpandEnvironmentStringsW | 0x0 | 0x4ef5cc | 0xef314 | 0xe6714 | 0x0 |
EnumSystemLocalesW | 0x0 | 0x4ef5d0 | 0xef318 | 0xe6718 | 0x0 |
EnumCalendarInfoW | 0x0 | 0x4ef5d4 | 0xef31c | 0xe671c | 0x0 |
DeleteFileW | 0x0 | 0x4ef5d8 | 0xef320 | 0xe6720 | 0x0 |
CreateProcessW | 0x0 | 0x4ef5dc | 0xef324 | 0xe6724 | 0x0 |
CreateMutexW | 0x0 | 0x4ef5e0 | 0xef328 | 0xe6728 | 0x0 |
CreateEventW | 0x0 | 0x4ef5e4 | 0xef32c | 0xe672c | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoUninitialize | 0x0 | 0x4ef5ec | 0xef334 | 0xe6734 | 0x0 |
CoInitialize | 0x0 | 0x4ef5f0 | 0xef338 | 0xe6738 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathW | 0x0 | 0x4ef5f8 | 0xef340 | 0xe6740 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSACleanup | 0x0 | 0x4ef600 | 0xef348 | 0xe6748 | 0x0 |
WSAStartup | 0x0 | 0x4ef604 | 0xef34c | 0xe674c | 0x0 |
gethostname | 0x0 | 0x4ef608 | 0xef350 | 0xe6750 | 0x0 |
gethostbyname | 0x0 | 0x4ef60c | 0xef354 | 0xe6754 | 0x0 |
inet_ntoa | 0x0 | 0x4ef610 | 0xef358 | 0xe6758 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareEnum | 0x0 | 0x4ef618 | 0xef360 | 0xe6760 | 0x0 |
NetApiBufferFree | 0x0 | 0x4ef61c | 0xef364 | 0xe6764 | 0x0 |
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0x509b8 | 0x1 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
bwng.exe | 1 | 0x00400000 | 0x00537FFF | Relevant Image |
![]() |
32-bit | 0x00407620 |
![]() |
![]() |
...
|
bwng.exe | 3 | 0x00400000 | 0x00537FFF | Relevant Image |
![]() |
32-bit | 0x00407620 |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Generic.Ransom.Matrix.D7248D5E |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bv6ncK8c.exe | Dropped File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2018-04-08 16:54 (UTC+2) |
Last Seen | 2019-07-07 07:59 (UTC+2) |
Names | Win32.Trojan.Cryptinject |
Families | Cryptinject |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x475810 |
Size Of Code | 0x29000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x4c000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-12-10 21:18:46+00:00 |
CompanyName | Sysinternals - www.sysinternals.com |
FileDescription | Handle viewer |
FileVersion | 4.11 |
InternalName | Nthandle |
LegalCopyright | Copyright (C) 1997-2017 Mark Russinovich |
OriginalFilename | Nthandle.exe |
ProductName | Sysinternals Handle |
ProductVersion | 4.11 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x4c000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x44d000 | 0x29000 | 0x28a00 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.93 |
.rsrc | 0x476000 | 0x1000 | 0x800 | 0x28e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.04 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyW | 0x0 | 0x47666c | 0x7666c | 0x2946c | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PrintDlgW | 0x0 | 0x476674 | 0x76674 | 0x29474 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDoc | 0x0 | 0x47667c | 0x7667c | 0x2947c | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x476684 | 0x76684 | 0x29484 | 0x0 |
ExitProcess | 0x0 | 0x476688 | 0x76688 | 0x29488 | 0x0 |
GetProcAddress | 0x0 | 0x47668c | 0x7668c | 0x2948c | 0x0 |
VirtualProtect | 0x0 | 0x476690 | 0x76690 | 0x29490 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDialog | 0x0 | 0x476698 | 0x76698 | 0x29498 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x4766a0 | 0x766a0 | 0x294a0 | 0x0 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
bv6nck8c.exe | 17 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00475810 |
![]() |
![]() |
...
|
bv6nck8c.exe | 17 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
bv6nck8c.exe | 17 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
bv6nck8c.exe | 21 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 17 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
bv6nck8c.exe | 17 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00406078 |
![]() |
![]() |
...
|
bv6nck8c.exe | 17 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
bv6nck8c.exe | 17 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
bv6nck8c.exe | 17 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 25 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 25 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 27 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 27 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 130 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 130 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 136 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 136 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 21 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 140 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 143 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 143 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 145 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 140 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 146 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 146 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 145 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 151 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 155 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 155 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 158 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 151 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 160 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 160 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 167 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 167 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 171 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 171 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 173 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 175 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 158 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 179 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 175 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 179 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 184 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 193 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 193 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 195 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 184 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 195 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 198 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 203 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 198 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 208 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 208 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 209 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 209 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 203 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 212 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 212 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
bv6nck8c.exe | 217 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
bv6nck8c.exe | 217 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Trojan.GenericKD.40672878 |
Malicious
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\[billwong73@yahoo.com].kHnF8C8q-MNRon4Ry.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Class.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SettingsInternal.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\mh5S3pNH.xlsx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\[billwong73@yahoo.com].cb18Z26I-CxGr3OqA.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\ResourceInternal.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\[billwong73@yahoo.com].cq1U1xhB-11dEpAQO.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\[billwong73@yahoo.com].k5l7PwtD-xM6DLxrV.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\FMeUiSrQlp.odt | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\permissions.sqlite | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfoInternal.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Settings.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Text.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\zLDBHXnLH.xlsx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\[billwong73@yahoo.com].FTurEc43-jRcNzsmw.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5lcB5sR2E7Db5N.odt | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\FRA\[billwong73@yahoo.com].8MFNQPoC-yajH8MSG.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\CHT\[billwong73@yahoo.com].xcPF6Uqb-NFOBM5KI.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\JPN\DefaultID.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CAT\Pointers.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CHT\[billwong73@yahoo.com].MCA6wKhE-WkMBT5DF.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\cookies.sqlite | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\KOR\[billwong73@yahoo.com].6RUiNF6R-qIPzAvbw.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CHT\[billwong73@yahoo.com].ZeR0wPjc-717ZPALe.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Csm9.docx | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\EUQ\[billwong73@yahoo.com].4bY3VaiA-TckjKlfh.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\Pointers.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\TUR\SignHere.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\KOR\[billwong73@yahoo.com].g4guJYyj-RZVInMLA.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\[billwong73@yahoo.com].wlWYfoKq-mhWWNfsg.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUM\[billwong73@yahoo.com].OuaFtJF9-H9OvA1Zx.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SKY\[billwong73@yahoo.com].dCBO03nX-tpkWOTEj.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\[billwong73@yahoo.com].bGnVLIUv-EihsYorf.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\TUR\[billwong73@yahoo.com].x0av7A7m-Efc0hJaT.BWNG | Dropped File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\DAN\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\FRA\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ITA\AdobeID.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\KOR\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SLV\AdobeID.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\RUM\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\SVE\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\PDFSigQFormalRep.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\updater.CAT | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CHS\StandardBusiness.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\SaveAsRTF.CZE | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\AdobeCollabSync.DAN | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\NOR\DefaultID.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SKY\DefaultID.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\sql90.xsl | Modified File | Stream |
Unknown
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\Informix.xsl | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CHS\SignHere.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\LeesMij.htm | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://www.adobe.com/nl/products/acrobat | - | - | - |
Unknown
|
Not Queried
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroTextExtractor.exe | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.POL | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ITA\DefaultID.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\POL\DefaultID.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CHT\Dynamic.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\UKR\AdobeID.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ENU\SignHere.pdf | Modified File | Binary |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\RdLang32.CAT | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\PTB\StandardBusiness.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUS\SignHere.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.HUN | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\CAT\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\DEU\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\HRV\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\NLD\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\RUS\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\PTB\SignHere.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SVE\SignHere.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CZE\StandardBusiness.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\pddom.DAN | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\de_DE\DVA.DEU | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\NOR\StandardBusiness.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\de_DE\DigSig.DEU | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Benioku.htm | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://www.adobe.com/products/acrobat | - | - | - |
Unknown
|
Not Queried
|
C:\Program Files (x86)\Adobe\Reader 10.0\LueMinut.htm | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\TUR\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\Acroform.CZE | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\makeaccessible.CZE | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\rzeIpzt3BVrhrzzHVNx.doc | Modified File | Stream |
Unknown
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\accessibility.ESP | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\IA32.ESP | Modified File | Stream |
Unknown
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\makeaccessible.ESP | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fi_FI\eBook.SUO | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\Checkers.EUQ | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\RdLang32.EUQ | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\MvvfDTDdUJ-88.jpg | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\UKR\SignHere.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NQ9coU\crQ_xNat6aF2t-ugx.jpg | Modified File | Stream |
Unknown
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Resources\1033\msolui100.rll | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Lisezmoi.htm | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.CAT | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\ENUtxt.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\CHT\AdobeID.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\JPN\[billwong73@yahoo.com].DF107YNs-2Srb4Snx.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\PTB\[billwong73@yahoo.com].E5z9FN0O-8RNC32q7.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CHT\[billwong73@yahoo.com].JjeqxZ0W-TiMH6LyU.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\DAN\[billwong73@yahoo.com].Gf51LSZ5-mtgHblvx.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\[billwong73@yahoo.com].kcAjrdNX-Bgplbb0v.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\FBwe\[billwong73@yahoo.com].fwfIXdAM-53xZwIHJ.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\[billwong73@yahoo.com].IOTEvnIJ-8u6HfHMm.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\[billwong73@yahoo.com].Gan1bHlE-NfA0mFlu.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Form.zip | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Llegiu-me.htm | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://www.adobe.com/products/acrobat | - | - | - |
Unknown
|
Not Queried
|
C:\Program Files (x86)\Adobe\Reader 10.0\[billwong73@yahoo.com].ChAdKUVe-XeieBGxR.BWNG | Dropped File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://www.adobe.com/products/acrobat | - | - | - |
Unknown
|
Not Queried
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HRV\Dynamic.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroBroker.exe | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\KOR\Hanko.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\Faces.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\[billwong73@yahoo.com].sYEeVumM-PHInjmq5.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.SVE | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SKY\Dynamic.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.EUQ | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SLV\[billwong73@yahoo.com].DGQngFA3-LFo7wCXK.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.PTB | Modified File | Stream |
Unknown
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\[billwong73@yahoo.com].SIhpieLs-y8ZdtfJt.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\RUS\[billwong73@yahoo.com].toUS6YKD-oXDEOox7.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\sql2000.xsl | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\TUR\[billwong73@yahoo.com].iqVEAKyr-i5UhAsMV.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\IrakHau.htm | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
http://www.adobe.com/products/acrobat | - | - | - |
Unknown
|
Not Queried
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\DEU\StandardBusiness.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Java\jre7\lib\deploy\[billwong73@yahoo.com].UDa4oRi3-7x6WJZk2.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Form.zip | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\XmlFile.zip | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\NLD\[billwong73@yahoo.com].B4DBg0Cn-NBLqTtTw.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\StandardBusiness.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\[billwong73@yahoo.com].le0nY3Dp-zmrIC5fh.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUS\Dynamic.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\TUR\[billwong73@yahoo.com].DG2Vjk1e-nVU0AUEu.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Eula.exe | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\CAT\[billwong73@yahoo.com].EJT71GZd-P0BZI4vG.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\[billwong73@yahoo.com].afCeWuaW-ENSnxWkO.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\DEU\[billwong73@yahoo.com].CZ98cIaa-PwdiEHdb.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\[billwong73@yahoo.com].Ezn7TLHg-KxK19V7D.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\UKR\[billwong73@yahoo.com].oWof6Ecf-WqnVy3Xv.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\[billwong73@yahoo.com].HEJCc0m0-huNsASfj.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\[billwong73@yahoo.com].1hOj1e4p-ezdJ7CLR.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\HUN\[billwong73@yahoo.com].PTYjAor5-eXNVMUPa.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\[billwong73@yahoo.com].9osfR0cR-WfDltKIX.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\FBwe\[billwong73@yahoo.com].8WmHA8lc-n6abdg1W.BWNG | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\ABkyVQkE.vbs | Dropped File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SKY\!BWNG_INFO!.rtf | Dropped File | RTF |
Unknown
|
...
|
SHIT H PPENS! WE H VE T INF RM Y U TH T LL Y UR FILES WERE ENCRYPTED!PLE SE BE SURE, Y UR FILES RE N T BR KEN! Y ur fil s w rn r pt d with str ng r ptlg rithms. * Pl s n t th t th r is n w t d r pt ur fil s with ut uniqu d r pti n knd sp i l s ftw r . Y ur uniqu d r pti n k is s ur l st r d n ur s rv r. * T d r pt ur d tu n d ur sp ifiut m ti d r pti n t l nd ur uniqu d r pti n k . * ll ur fil s w r r n m d but ft r d r pti n pr ss fil n m s will b r v r d trigin l st t . D t stru tur will n t h ng . * Pl s b sur th t ll thtt mpts t r v r ur fil s burs lf r using third p rt t ls n r sult in irr v bl l ss f ur d t ! WH T D Y U NEED T D ? First f ll u h v t writ us b-m il: ur first -m il:billwong73@yahoo.com ur s nd -m il: tab billwong73@protonmail.com ur third -m il: tab billwong73@aol.comTTENTI N! If u w nt t r v r ur d t pl s writ us tll ur -m il dr ss s! It is r ll imp rt nt b usf d liv r pr bl ms with s m m ... |
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\[billwong73@yahoo.com].H5IYVfAq-JJMgT5VW.BWNG | Dropped File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\extensions.sqlite | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\[billwong73@yahoo.com].SMJlzPis-RY30TPJ8.BWNG | Dropped File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\[billwong73@yahoo.com].WUgwNl8B-blCJYfqQ.BWNG | Dropped File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfo.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yx6VyYSZGTItiuaP9AhS.xlsx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ML4wSod4aTRjVy6SEl.docx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\key3.db | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dialog.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\CZE\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ESP\[billwong73@yahoo.com].Fl2BTjFJ-HCUrXoB7.BWNG | Dropped File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\PTB\DefaultID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SUO\DefaultID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\DAN\[billwong73@yahoo.com].Hl32PYyj-59v2g2xY.BWNG | Dropped File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\EUQ\[billwong73@yahoo.com].4lHpi0zX-fabgxWMU.BWNG | Dropped File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\ResourceInternal.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\dR4b.xlsx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J5Yv0DCaKIe7OBm.docx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\RlQwkMJD.doc | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\NOR\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Javascripts\JSByteCodeWin.bin | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AboutBox.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\RUM\[billwong73@yahoo.com].ZZyrXyyT-8PYVsVbL.BWNG | Dropped File | Unknown |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\CHS\DefaultID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Interface.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SKY\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SVE\[billwong73@yahoo.com].m972WmOV-TwTIEmDM.BWNG | Dropped File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CAT\SignHere.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\secmod.db | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AppConfigurationInternal.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Module.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\AYMdR8qxGSd3dzB.xlsx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KR-jP1j.doc | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\DEU\[billwong73@yahoo.com].U9xHl9uq-TvG7o6hX.BWNG | Dropped File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HRV\Pointers.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ITA\Dynamic.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HRV\[billwong73@yahoo.com].QYg4SRtG-hfNjyCbs.BWNG | Dropped File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HUN\StandardBusiness.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\KOR\SignHere.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUM\SignHere.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SKY\[billwong73@yahoo.com].OnwANM5V-F3nnY89Z.BWNG | Dropped File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SLV\[billwong73@yahoo.com].AHQicU1X-HOi1kifs.BWNG | Dropped File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\[billwong73@yahoo.com].Zukbumz3-WMcVBcRw.BWNG | Dropped File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\TextFile.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SUO\Dynamic.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\CHS\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\BRdlang32.CAT | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ENU\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\POL\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\PPKLite.CAT | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\eBook.CZE | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\Multimedia.DAN | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ENU\DefaultID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\UKR\DefaultID.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CZE\Standard.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ENU\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.ESP | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SLV\DefaultID.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CAT\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\DAN\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ESP\SignHere.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CHS\Hanko.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CZE\SignHere.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\Checkers.CAT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\EUQ\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\Services\Services.asfx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files\Microsoft Sync Framework\v1.0\Runtime\x64\resources\1033\Synchronization.rll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\FRA\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HUN\Faces.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.CAT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\JPN\SignHere.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\NOR\SignHere.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SLV\Faces.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SVE\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.SKY | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\FRA\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HUN\SignHere.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\KOR\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUM\Faces.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUS\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SLV\SignHere.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\TUR\Faces.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Defb0F5pup.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HUN\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\JPN\Hanko.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\NOR\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\WebLink.CAT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUS\Pointers.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SLV\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\EScript.CZE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\Search.CZE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\UKR\Pointers.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\_70TnXBhVpE1DtNBE.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\Annots.DAN | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\Spelling.DAN | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ESP\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\FRA\SignHere.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HUN\Pointers.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\de_DE\reflow.DEU | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\JPN\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\Acroform.ESP | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUM\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUS\Standard.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\de_DE\ReadOutLoud.DEU | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.CHT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.JPN | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.SUO | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.ESP | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\DVA.CAT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\reflow.CAT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\UKR\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2QhrP VqiRTmxAY.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\Services\DEXShare.asfx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\[billwong73@yahoo.com].ko92Gweu-1beMoREA.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\[billwong73@yahoo.com].HfXq3o4W-idZVaCtT.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\[billwong73@yahoo.com].XaZWImVy-tPoZNMhT.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NQ9coU\AOzRwuhQidc.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\SendMail.ESP | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Resources\1033\msmdsrv.rll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\BRdlang32.EUQ | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\PPKLite.EUQ | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\updater.EUQ | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\Services\DEXShare.asfx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SLV\Pointers.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\TUR\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\UKR\Standard.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\r87X_.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.POL | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\8OLLNGA.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\Checkers.DAN | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\as80.xsl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\[billwong73@yahoo.com].qHduhodG-qBY6YKzh.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\FBwe\[billwong73@yahoo.com].7JNwdTAT-CdHSW2tq.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\[billwong73@yahoo.com].0Ov5R8a7-yfPGthmy.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.HUN | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\as90.xsl | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.SKY | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ESP\AdobeID.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.DAN | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.NLD | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.TUR | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SUO\AdobeID.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CAT\[billwong73@yahoo.com].V2vZo0gL-esI38xLw.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\webappsstore.sqlite | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\DataSet.zip | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ESP\[billwong73@yahoo.com].uYKKrJYx-66AaDCmt.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.CHS | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.ITA | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.SLV | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.DEU | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.NOR | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.UKR | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HUN\Standard.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.CZE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUM\[billwong73@yahoo.com].5nwKcoPh-bjCBwZo2.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\DAN\[billwong73@yahoo.com].xDwsmivi-y8ZLM5IL.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\HRV\AdobeID.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\Firefox\Profiles\silmbjec.default\OfflineCache\index.sqlite | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\sessionstore.bak | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\NLD\AdobeID.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\[billwong73@yahoo.com].cJmy3dSN-qh0YBYkx.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\[billwong73@yahoo.com].K79gC864-kIjY11DF.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\[billwong73@yahoo.com].BrHSihLB-18pMHLvO.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CAT\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CZE\[billwong73@yahoo.com].yjxx7ILZ-VllliFwM.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\EUQ\SignHere.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HRV\Standard.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\[billwong73@yahoo.com].VqWZD1lo-wo75D1Ev.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ITA\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\[billwong73@yahoo.com].S6jgFVqC-fhPBdrmq.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\CkDL.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\[billwong73@yahoo.com].BkSe9G8u-Xi0TT4Sd.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.DAN | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\CAT\DefaultID.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8QVH.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\AfX5b2r--ls.doc | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SKY\Standard.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SUO\[billwong73@yahoo.com].7xZzhHIp-0lve78eu.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\EAvGGvTw.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ltC_LU5_qwr7.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\DAN\[billwong73@yahoo.com].rGtxbwpe-XADVNl4M.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\DEU\DefaultID.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\[billwong73@yahoo.com].SRQEyrC1-JAOgPfVL.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\FRA\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\KOR\[billwong73@yahoo.com].MIpH37Jn-xePpEVKb.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\RUM\[billwong73@yahoo.com].cHLTAG5K-KlEwTRWy.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\MDIParent.zip | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\SVE\[billwong73@yahoo.com].JeAKvHY0-WDcA7MGj.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.RUM | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AssemblyInfoInternal.zip | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\[billwong73@yahoo.com].d1ycW9D6-6AyII7jW.BWNG | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\HUN\AdobeID.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ALL_dmp.fldp | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\log.txt | Dropped File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\DSsABWsd.bmp | Dropped File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\YW0T0jSM.bat | Dropped File | Batch |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Bt3xnwko.bat | Dropped File | Batch |
Not Queried
|
...
|