VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: | - |
Threat Names: |
Trojan.GenericKD.43826496
Gen:Heur.Ransom.Imps.1
Mal/Generic-S
|
vinfk.exe
Windows Exe (x86-32)
Created at 2020-12-09T10:16:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4092a4 |
Size Of Code | 0x15400 |
Size Of Initialized Data | 0x15a600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-09-12 13:54:05+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1534a | 0x15400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.67 |
.rdata | 0x417000 | 0x6154 | 0x6200 | 0x15800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.84 |
.data | 0x41e000 | 0xf6b80 | 0xf6200 | 0x1ba00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.9 |
.rsrc | 0x515000 | 0x5d058 | 0x5d200 | 0x111c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.04 |
.reloc | 0x573000 | 0xfcc | 0x1000 | 0x16ee00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.48 |
Imports (3)
»
KERNEL32.dll (77)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindFirstFileA | 0x0 | 0x417000 | 0x1ca08 | 0x1b208 | 0x179 |
VirtualProtect | 0x0 | 0x417004 | 0x1ca0c | 0x1b20c | 0x5cc |
SetLastError | 0x0 | 0x417008 | 0x1ca10 | 0x1b210 | 0x532 |
GetCurrentProcess | 0x0 | 0x41700c | 0x1ca14 | 0x1b214 | 0x217 |
GetModuleFileNameW | 0x0 | 0x417010 | 0x1ca18 | 0x1b218 | 0x274 |
VirtualAllocExNuma | 0x0 | 0x417014 | 0x1ca1c | 0x1b21c | 0x5c8 |
FindNextFileA | 0x0 | 0x417018 | 0x1ca20 | 0x1b220 | 0x18a |
InitializeCriticalSectionEx | 0x0 | 0x41701c | 0x1ca24 | 0x1b224 | 0x360 |
GetLastError | 0x0 | 0x417020 | 0x1ca28 | 0x1b228 | 0x261 |
GetCurrentThread | 0x0 | 0x417024 | 0x1ca2c | 0x1b22c | 0x21b |
GetSystemDirectoryA | 0x0 | 0x417028 | 0x1ca30 | 0x1b230 | 0x2df |
CloseHandle | 0x0 | 0x41702c | 0x1ca34 | 0x1b234 | 0x86 |
RaiseException | 0x0 | 0x417030 | 0x1ca38 | 0x1b238 | 0x462 |
DecodePointer | 0x0 | 0x417034 | 0x1ca3c | 0x1b23c | 0x109 |
GetSystemWow64DirectoryA | 0x0 | 0x417038 | 0x1ca40 | 0x1b240 | 0x2ee |
GetProcAddress | 0x0 | 0x41703c | 0x1ca44 | 0x1b244 | 0x2ae |
DeleteCriticalSection | 0x0 | 0x417040 | 0x1ca48 | 0x1b248 | 0x110 |
GetModuleHandleW | 0x0 | 0x417044 | 0x1ca4c | 0x1b24c | 0x278 |
AllocConsole | 0x0 | 0x417048 | 0x1ca50 | 0x1b250 | 0x15 |
CreateFileW | 0x0 | 0x41704c | 0x1ca54 | 0x1b254 | 0xcb |
SetFilePointerEx | 0x0 | 0x417050 | 0x1ca58 | 0x1b258 | 0x523 |
GetConsoleMode | 0x0 | 0x417054 | 0x1ca5c | 0x1b25c | 0x1fc |
GetConsoleCP | 0x0 | 0x417058 | 0x1ca60 | 0x1b260 | 0x1ea |
IsDebuggerPresent | 0x0 | 0x41705c | 0x1ca64 | 0x1b264 | 0x37f |
OutputDebugStringW | 0x0 | 0x417060 | 0x1ca68 | 0x1b268 | 0x419 |
EnterCriticalSection | 0x0 | 0x417064 | 0x1ca6c | 0x1b26c | 0x131 |
LeaveCriticalSection | 0x0 | 0x417068 | 0x1ca70 | 0x1b270 | 0x3bd |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41706c | 0x1ca74 | 0x1b274 | 0x35f |
CreateEventW | 0x0 | 0x417070 | 0x1ca78 | 0x1b278 | 0xbf |
UnhandledExceptionFilter | 0x0 | 0x417074 | 0x1ca7c | 0x1b27c | 0x5ad |
SetUnhandledExceptionFilter | 0x0 | 0x417078 | 0x1ca80 | 0x1b280 | 0x56d |
TerminateProcess | 0x0 | 0x41707c | 0x1ca84 | 0x1b284 | 0x58c |
IsProcessorFeaturePresent | 0x0 | 0x417080 | 0x1ca88 | 0x1b288 | 0x386 |
GetStartupInfoW | 0x0 | 0x417084 | 0x1ca8c | 0x1b28c | 0x2d0 |
QueryPerformanceCounter | 0x0 | 0x417088 | 0x1ca90 | 0x1b290 | 0x44d |
GetCurrentProcessId | 0x0 | 0x41708c | 0x1ca94 | 0x1b294 | 0x218 |
GetCurrentThreadId | 0x0 | 0x417090 | 0x1ca98 | 0x1b298 | 0x21c |
GetSystemTimeAsFileTime | 0x0 | 0x417094 | 0x1ca9c | 0x1b29c | 0x2e9 |
InitializeSListHead | 0x0 | 0x417098 | 0x1caa0 | 0x1b2a0 | 0x363 |
RtlUnwind | 0x0 | 0x41709c | 0x1caa4 | 0x1b2a4 | 0x4d3 |
EncodePointer | 0x0 | 0x4170a0 | 0x1caa8 | 0x1b2a8 | 0x12d |
TlsAlloc | 0x0 | 0x4170a4 | 0x1caac | 0x1b2ac | 0x59e |
TlsGetValue | 0x0 | 0x4170a8 | 0x1cab0 | 0x1b2b0 | 0x5a0 |
TlsSetValue | 0x0 | 0x4170ac | 0x1cab4 | 0x1b2b4 | 0x5a1 |
TlsFree | 0x0 | 0x4170b0 | 0x1cab8 | 0x1b2b8 | 0x59f |
FreeLibrary | 0x0 | 0x4170b4 | 0x1cabc | 0x1b2bc | 0x1ab |
LoadLibraryExW | 0x0 | 0x4170b8 | 0x1cac0 | 0x1b2c0 | 0x3c3 |
ExitProcess | 0x0 | 0x4170bc | 0x1cac4 | 0x1b2c4 | 0x15e |
GetModuleHandleExW | 0x0 | 0x4170c0 | 0x1cac8 | 0x1b2c8 | 0x277 |
GetStdHandle | 0x0 | 0x4170c4 | 0x1cacc | 0x1b2cc | 0x2d2 |
WriteFile | 0x0 | 0x4170c8 | 0x1cad0 | 0x1b2d0 | 0x612 |
GetCommandLineA | 0x0 | 0x4170cc | 0x1cad4 | 0x1b2d4 | 0x1d6 |
GetCommandLineW | 0x0 | 0x4170d0 | 0x1cad8 | 0x1b2d8 | 0x1d7 |
CompareStringW | 0x0 | 0x4170d4 | 0x1cadc | 0x1b2dc | 0x9b |
LCMapStringW | 0x0 | 0x4170d8 | 0x1cae0 | 0x1b2e0 | 0x3b1 |
HeapFree | 0x0 | 0x4170dc | 0x1cae4 | 0x1b2e4 | 0x349 |
HeapSize | 0x0 | 0x4170e0 | 0x1cae8 | 0x1b2e8 | 0x34e |
HeapReAlloc | 0x0 | 0x4170e4 | 0x1caec | 0x1b2ec | 0x34c |
HeapAlloc | 0x0 | 0x4170e8 | 0x1caf0 | 0x1b2f0 | 0x345 |
FindClose | 0x0 | 0x4170ec | 0x1caf4 | 0x1b2f4 | 0x175 |
FindFirstFileExW | 0x0 | 0x4170f0 | 0x1caf8 | 0x1b2f8 | 0x17b |
FindNextFileW | 0x0 | 0x4170f4 | 0x1cafc | 0x1b2fc | 0x18c |
IsValidCodePage | 0x0 | 0x4170f8 | 0x1cb00 | 0x1b300 | 0x38b |
GetACP | 0x0 | 0x4170fc | 0x1cb04 | 0x1b304 | 0x1b2 |
GetOEMCP | 0x0 | 0x417100 | 0x1cb08 | 0x1b308 | 0x297 |
GetCPInfo | 0x0 | 0x417104 | 0x1cb0c | 0x1b30c | 0x1c1 |
MultiByteToWideChar | 0x0 | 0x417108 | 0x1cb10 | 0x1b310 | 0x3ef |
WideCharToMultiByte | 0x0 | 0x41710c | 0x1cb14 | 0x1b314 | 0x5fe |
GetEnvironmentStringsW | 0x0 | 0x417110 | 0x1cb18 | 0x1b318 | 0x237 |
FreeEnvironmentStringsW | 0x0 | 0x417114 | 0x1cb1c | 0x1b31c | 0x1aa |
SetEnvironmentVariableW | 0x0 | 0x417118 | 0x1cb20 | 0x1b320 | 0x514 |
GetProcessHeap | 0x0 | 0x41711c | 0x1cb24 | 0x1b324 | 0x2b4 |
GetFileType | 0x0 | 0x417120 | 0x1cb28 | 0x1b328 | 0x24e |
SetStdHandle | 0x0 | 0x417124 | 0x1cb2c | 0x1b32c | 0x54a |
GetStringTypeW | 0x0 | 0x417128 | 0x1cb30 | 0x1b330 | 0x2d7 |
FlushFileBuffers | 0x0 | 0x41712c | 0x1cb34 | 0x1b334 | 0x19f |
WriteConsoleW | 0x0 | 0x417130 | 0x1cb38 | 0x1b338 | 0x611 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindWindowA | 0x0 | 0x417140 | 0x1cb48 | 0x1b348 | 0x111 |
ShowWindow | 0x0 | 0x417144 | 0x1cb4c | 0x1b34c | 0x380 |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindExtensionA | 0x0 | 0x417138 | 0x1cb40 | 0x1b340 | 0x4a |
Digital Signatures (2)
»
Certificate: NCH Software, Inc.
»
Issued by | NCH Software, Inc. |
Parent Certificate | DigiCert EV Code Signing CA |
Country Name | US |
Valid From | 2019-03-23 00:00:00+00:00 |
Valid Until | 2022-03-30 12:00:00+00:00 |
Algorithm | sha1_rsa |
Serial Number | 0A 01 C3 FF 88 55 F0 08 C8 E4 FA 63 97 32 52 E6 |
Thumbprint | 9B 12 4A 8E D8 79 1E 75 C9 72 55 ED C2 AD 48 DE CA 01 DB 8B |
Certificate: DigiCert EV Code Signing CA
»
Issued by | DigiCert EV Code Signing CA |
Country Name | US |
Valid From | 2012-04-18 12:00:00+00:00 |
Valid Until | 2027-04-18 12:00:00+00:00 |
Algorithm | sha1_rsa |
Serial Number | 0D D0 E3 37 4A C9 5B DB FA 6B 43 4B 2A 48 EC 06 |
Thumbprint | 84 68 96 AB 1B CF 45 73 48 55 C6 1B 63 63 4D FD 87 19 62 5B |
Memory Dumps (184)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
vinfk.exe | 1 | 0x01240000 | 0x013B3FFF | Relevant Image | 32-bit | 0x0124A72A |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | First Execution | 32-bit | 0x00464714 |
...
|
|||
vinfk.exe | 3 | 0x01240000 | 0x013B3FFF | Relevant Image | 32-bit | - |
...
|
|||
vinfk.exe | 1 | 0x01240000 | 0x013B3FFF | Process Termination | 32-bit | - |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00467EF9 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00468022 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B8BB |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00470885 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00479E50 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004874B4 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047AC27 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004816C8 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0040A1F0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047EA0E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00480E53 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048A1A6 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047FCCD |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00489135 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004830C6 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004668B0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00409450 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048B917 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00420BB0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00452AA2 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00486094 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048FDC4 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00447FF0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00448000 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0044A520 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00411910 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0044B220 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0044DE30 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0043CA50 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0040EE40 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0043E730 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0040F016 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004276D0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0041D130 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00476000 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0045105F |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00450F99 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00472736 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004617F4 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0045FE6C |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00455B24 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00473AA2 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0045BB70 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00428370 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0044F4E1 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048E310 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0040C0A0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0040BA90 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004136B0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00417BC0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00406570 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00407010 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00464083 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004025F0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004126C0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047C596 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00488F3A |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00474A1C |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047A838 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004526DC |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0045105F |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00450F99 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00428720 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0044F4E1 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00407EDE |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0041D130 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00459B3F |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00464083 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00402ED6 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00480016 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B40E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047E959 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B40E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00491280 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B40E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00491280 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048E47E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004803C1 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B40E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00491280 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048E47E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004803C1 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B40E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00491280 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B40E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00479FB2 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B40E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00491280 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048E47E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004803C1 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B40E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00491280 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B40E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00491280 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B40E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00491280 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047C596 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00488F3A |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00474A1C |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047A838 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00476000 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0040ACB0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0041F7E0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0045261B |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004209B0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00467FEB |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048C031 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00491280 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0045105F |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00450F99 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00428720 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0044F4E1 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004058C0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0041BFA0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048F000 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0040D500 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0041EB50 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004803C1 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B40E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00491280 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004713D6 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00419FCE |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0040C460 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B40E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00491280 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004891D3 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047C596 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00488F3A |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00452897 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0042B035 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0040D500 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048A46F |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00488F3A |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0045105F |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00450F99 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00482D96 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048BE7C |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0044F4E1 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0040F3D0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004498C0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004373B0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004058C0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B8FD |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047A838 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004526DC |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004298E0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00490D90 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004498C0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00450F99 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0044B000 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00495E6E |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004064B0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048BE7C |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00448910 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048285D |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047FCCD |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B8FD |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048BE7C |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00448910 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0045105F |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00482C61 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00448910 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004131E1 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0044B000 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0045105F |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047F13C |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00490D90 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0047B8FD |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0048BE7C |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00448910 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0045105F |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x0044F4E1 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004383EC |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004064B0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004280E0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00416F30 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x00479FB2 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004981F0 |
...
|
|||
buffer | 3 | 0x00400000 | 0x004FAFFF | Content Changed | 32-bit | 0x004876C5 |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.43826496 |
Malicious
|
C:\Users\FD1HVy\AppData\Local\Temp\__PSScriptPolicyTest_agagxbad.r5s.psm1 | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\sad.ps1 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WARNING.html | Dropped File | Text |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico.HOR | Dropped File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico.HOR | Dropped File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico.HOR | Dropped File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.HOR | Dropped File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.HOR | Dropped File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico.HOR | Dropped File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x86.msi.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x64.msi.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9RAST_x64.msi.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9Rast_x86.msi.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.HOR | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.HOR | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\mf\pending.grl.hor | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\oracle\java\installcache_x64\baseimagefam8.hor | Dropped File | Stream |
Unknown
|
...
|
»