Dynamic Analysis Report |
Classification: Riskware, Trojan, Ransomware |
1c2bdfa5e30cbf8eb92c3764de9b106aa722a81b50641698d2620a49b530b0b4 (SHA256)
1c2bdfa5e30cbf8eb92c3764de9b106aa722a81b50641698d2620a49b530b0b4.exe
Created at 2018-08-28 15:01:00
Notifications (2/4)
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
The overall sleep time of all monitored processes was truncated from "10 minutes" to "10 seconds" to reveal dormant functionality.
The operating system was rebooted during the analysis.
Remarks
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
This list contains only the embedded files and created files
Filters: |
There are no files for this filter
Filename | Category | Type | Severity | Actions |
---|
C:\Users\CIiHmnxMn6Ps\Desktop\1c2bdfa5e30cbf8eb92c3764de9b106aa722a81b50641698d2620a49b530b0b4.exe | Sample File | Binary |
Blacklisted
|
...
|
Severity |
Blacklisted
|
First Seen | 2018-08-21 13:43 (UTC+2) |
Last Seen | 2018-08-25 00:07 (UTC+2) |
Names | Win32.Trojan.Antiav |
Families | Antiav |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x401e4a |
Size Of Code | 0x1400 |
Size Of Initialized Data | 0x2600 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2018-08-10 10:40:27+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1384 | 0x1400 | 0x400 | cnt_code, mem_execute, mem_read | 5.67 |
.rdata | 0x403000 | 0x86c | 0xa00 | 0x1800 | cnt_initialized_data, mem_read | 4.52 |
.data | 0x404000 | 0x1210 | 0xa00 | 0x2200 | cnt_initialized_data, mem_read, mem_write | 7.51 |
.rsrc | 0x406000 | 0x620 | 0x800 | 0x2c00 | cnt_initialized_data, mem_read | 6.1 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
UpdateWindow | 0x0 | 0x40311c | 0x32f8 | 0x1af8 | 0x26a |
TranslateMessage | 0x0 | 0x403120 | 0x32fc | 0x1afc | 0x25e |
ShowWindow | 0x0 | 0x403124 | 0x3300 | 0x1b00 | 0x248 |
SetTimer | 0x0 | 0x403128 | 0x3304 | 0x1b04 | 0x232 |
SendMessageA | 0x0 | 0x40312c | 0x3308 | 0x1b08 | 0x1fd |
GetMessageA | 0x0 | 0x403130 | 0x330c | 0x1b0c | 0x122 |
GetDlgItem | 0x0 | 0x403134 | 0x3310 | 0x1b10 | 0xfa |
DispatchMessageA | 0x0 | 0x403138 | 0x3314 | 0x1b14 | 0x93 |
CreateDialogParamA | 0x0 | 0x40313c | 0x3318 | 0x1b18 | 0x4c |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindClose | 0x0 | 0x403048 | 0x3224 | 0x1a24 | 0xad |
FindFirstFileW | 0x0 | 0x40304c | 0x3228 | 0x1a28 | 0xb4 |
FindNextFileW | 0x0 | 0x403050 | 0x322c | 0x1a2c | 0xbb |
FindResourceA | 0x0 | 0x403054 | 0x3230 | 0x1a30 | 0xc0 |
GetCurrentProcessId | 0x0 | 0x403058 | 0x3234 | 0x1a34 | 0x101 |
GetEnvironmentVariableA | 0x0 | 0x40305c | 0x3238 | 0x1a38 | 0x113 |
GetFileAttributesW | 0x0 | 0x403060 | 0x323c | 0x1a3c | 0x11a |
GetLogicalDrives | 0x0 | 0x403064 | 0x3240 | 0x1a40 | 0x12e |
GetModuleFileNameA | 0x0 | 0x403068 | 0x3244 | 0x1a44 | 0x132 |
GetModuleHandleA | 0x0 | 0x40306c | 0x3248 | 0x1a48 | 0x134 |
GlobalAlloc | 0x0 | 0x403070 | 0x324c | 0x1a4c | 0x1a5 |
GlobalFree | 0x0 | 0x403074 | 0x3250 | 0x1a50 | 0x1ac |
GlobalMemoryStatus | 0x0 | 0x403078 | 0x3254 | 0x1a54 | 0x1b1 |
LoadResource | 0x0 | 0x40307c | 0x3258 | 0x1a58 | 0x1ef |
CreateThread | 0x0 | 0x403080 | 0x325c | 0x1a5c | 0x56 |
MoveFileW | 0x0 | 0x403084 | 0x3260 | 0x1a60 | 0x207 |
MultiByteToWideChar | 0x0 | 0x403088 | 0x3264 | 0x1a64 | 0x20b |
OpenProcess | 0x0 | 0x40308c | 0x3268 | 0x1a68 | 0x216 |
Process32FirstW | 0x0 | 0x403090 | 0x326c | 0x1a6c | 0x223 |
Process32NextW | 0x0 | 0x403094 | 0x3270 | 0x1a70 | 0x224 |
RtlMoveMemory | 0x0 | 0x403098 | 0x3274 | 0x1a74 | 0x256 |
ExitProcess | 0x0 | 0x40309c | 0x3278 | 0x1a78 | 0x9b |
CreateFileW | 0x0 | 0x4030a0 | 0x327c | 0x1a7c | 0x40 |
SetFileAttributesW | 0x0 | 0x4030a4 | 0x3280 | 0x1a80 | 0x284 |
SetFilePointer | 0x0 | 0x4030a8 | 0x3284 | 0x1a84 | 0x285 |
SetThreadPriority | 0x0 | 0x4030ac | 0x3288 | 0x1a88 | 0x2a9 |
SizeofResource | 0x0 | 0x4030b0 | 0x328c | 0x1a8c | 0x2b6 |
Sleep | 0x0 | 0x4030b4 | 0x3290 | 0x1a90 | 0x2b7 |
TerminateProcess | 0x0 | 0x4030b8 | 0x3294 | 0x1a94 | 0x2bf |
UnmapViewOfFile | 0x0 | 0x4030bc | 0x3298 | 0x1a98 | 0x2cf |
WriteFile | 0x0 | 0x4030c0 | 0x329c | 0x1a9c | 0x2f7 |
lstrcatW | 0x0 | 0x4030c4 | 0x32a0 | 0x1aa0 | 0x310 |
lstrcmpW | 0x0 | 0x4030c8 | 0x32a4 | 0x1aa4 | 0x312 |
lstrcmpiA | 0x0 | 0x4030cc | 0x32a8 | 0x1aa8 | 0x313 |
lstrcmpiW | 0x0 | 0x4030d0 | 0x32ac | 0x1aac | 0x314 |
lstrcpyW | 0x0 | 0x4030d4 | 0x32b0 | 0x1ab0 | 0x316 |
lstrlenA | 0x0 | 0x4030d8 | 0x32b4 | 0x1ab4 | 0x319 |
lstrlenW | 0x0 | 0x4030dc | 0x32b8 | 0x1ab8 | 0x31a |
CreateFileMappingA | 0x0 | 0x4030e0 | 0x32bc | 0x1abc | 0x3e |
CreateFileA | 0x0 | 0x4030e4 | 0x32c0 | 0x1ac0 | 0x3d |
CopyFileA | 0x0 | 0x4030e8 | 0x32c4 | 0x1ac4 | 0x2e |
CloseHandle | 0x0 | 0x4030ec | 0x32c8 | 0x1ac8 | 0x23 |
RtlZeroMemory | 0x0 | 0x4030f0 | 0x32cc | 0x1acc | 0x258 |
CreateToolhelp32Snapshot | 0x0 | 0x4030f4 | 0x32d0 | 0x1ad0 | 0x59 |
MapViewOfFile | 0x0 | 0x4030f8 | 0x32d4 | 0x1ad4 | 0x200 |
SetErrorMode | 0x0 | 0x4030fc | 0x32d8 | 0x1ad8 | 0x27f |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x403114 | 0x32f0 | 0x1af0 | 0xd9 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LookupPrivilegeValueA | 0x0 | 0x403000 | 0x31dc | 0x19dc | 0x141 |
CryptReleaseContext | 0x0 | 0x403004 | 0x31e0 | 0x19e0 | 0x98 |
CryptImportKey | 0x0 | 0x403008 | 0x31e4 | 0x19e4 | 0x97 |
CryptGenKey | 0x0 | 0x40300c | 0x31e8 | 0x19e8 | 0x8d |
CryptDestroyKey | 0x0 | 0x403010 | 0x31ec | 0x19ec | 0x84 |
CryptDecrypt | 0x0 | 0x403014 | 0x31f0 | 0x19f0 | 0x81 |
RegSetValueExA | 0x0 | 0x403018 | 0x31f4 | 0x19f4 | 0x1e7 |
RegQueryValueExA | 0x0 | 0x40301c | 0x31f8 | 0x19f8 | 0x1da |
RegOpenKeyExA | 0x0 | 0x403020 | 0x31fc | 0x19fc | 0x1d0 |
CryptAcquireContextA | 0x0 | 0x403024 | 0x3200 | 0x1a00 | 0x7d |
AdjustTokenPrivileges | 0x0 | 0x403028 | 0x3204 | 0x1a04 | 0x19 |
OpenProcessToken | 0x0 | 0x40302c | 0x3208 | 0x1a08 | 0x198 |
RegCloseKey | 0x0 | 0x403030 | 0x320c | 0x1a0c | 0x1b7 |
CryptExportKey | 0x0 | 0x403034 | 0x3210 | 0x1a10 | 0x8c |
CryptEncrypt | 0x0 | 0x403038 | 0x3214 | 0x1a14 | 0x87 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InitCommonControls | 0x0 | 0x403040 | 0x321c | 0x1a1c | 0x54 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetEnumResourceA | 0x0 | 0x403104 | 0x32e0 | 0x1ae0 | 0x13 |
WNetOpenEnumA | 0x0 | 0x403108 | 0x32e4 | 0x1ae4 | 0x25 |
WNetCloseEnum | 0x0 | 0x40310c | 0x32e8 | 0x1ae8 | 0xc |
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
WiltedTulip_Tools_clrlg | Windows eventlog cleaner used in Operation Wilted Tulip (file: clrlg.bat) | - |
5/5
|
...
|
\\?\C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Suspicious
|
...
|
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
Shellcode_GetPC_fstenv | x86 GetPC code using fstenv; possible shellcode | - |
3/5
|
...
|
\\?\C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll ID NL5VaVIIqOZA.BadNews | Modified File | Stream |
Unknown
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Contacts\chucu jadnvk.contact ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\MqqaQUIOXt.avi ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Pictures\FTCT.png ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Searches\Indexed Locations.search-ms ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\PowerShellGet.psd1 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Videos\crv__X6D-6VzmL-1hsmr.swf ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.014.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Uninstall Information\broadwaychildrenvocational.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\kD qBQuoHge89T\opDlC6QUcl.doc ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\kD qBQuoHge89T\zKc7RH_1b.rtf ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.011.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Localization Component.swidtag ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\1pUvjwM8UwKSFGy.gif ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\PSGet.Format.ps1xml ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\a80ysSR.flv ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\EnKHxADYKnu.csv ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Searches\Everywhere.search-ms ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Package Cache\{929FBD26-9020-399B-9A7A-751D61F0B942}v12.0.21005\packages\vcRuntimeAdditional_amd64\cab1.cab ID NL5VaVIIqOZA.BadNews | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\Provisioning\{f11899f2-71ec-4621-9997-e17ae2f6eb26}\customizations.xml ID NL5VaVIIqOZA.BadNews | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\Provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\customizations.xml ID NL5VaVIIqOZA.BadNews | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\Provisioning\{1e05dd5d-a022-46c5-963c-b20de341170f}\customizations.xml ID NL5VaVIIqOZA.BadNews | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4eccd106f69e31c1b12304e5463bb71d_427a1946-e0ff-4097-8c9e-ca2c1e22780b ID NL5VaVIIqOZA.BadNews | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\Provisioning\{9aec5bda-1e87-46b3-bb96-1a01c606555e}\customizations.xml ID NL5VaVIIqOZA.BadNews | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.019.etl ID NL5VaVIIqOZA.BadNews | Modified File | Stream |
Not Queried
|
...
|
c:\users\ciihmnxmn6ps\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1462094071-1423818996-289466292-1000\46a78fa46b43fb180b4fa21773f8ff3e_427a1946-e0ff-4097-8c9e-ca2c1e22780b | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\Provisioning\{8fb7d64e-70fc-4f9d-89ee-d486817534df}\customizations.xml ID NL5VaVIIqOZA.BadNews | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Default\NTUSER.DAT.LOG1 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Office 15\debate gs response.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\1XisO9.avi ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dll ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
c:\users\ciihmnxmn6ps\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1462094071-1423818996-289466292-1000\46a78fa46b43fb180b4fa21773f8ff3e_427a1946-e0ff-4097-8c9e-ca2c1e22780b | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Links\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Boot\BOOTSTAT.DAT ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.015.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\L9ZzdDugiqj.pptx ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.016.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Pictures\YZAivOG1xExfHd6\SChpKyqP63Wc3Ifl.jpg ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Default\NTUSER.DAT{77a2c7ed-26f0-11e5-80da-e41d2d741090}.TMContainer00000000000000000001.regtrans-ms ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Recovery\WindowsRE\boot.sdi ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Music\2F5ig6v.mp3 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\kD qBQuoHge89T\N83zhof_RAlqZS5ui.csv ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\1494870C-9912-C184-4CC9-B401-A53F4D8DE290.pdf ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\gru-RJpD1yp7Z.mp4 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\PSGet.psm1 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\MSBuild\delivered-sapphire-divisions.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\2 u0.xlsx ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\BOOTSECT.BAK ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Uninstall Information\product-fears-seafood.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\ptRBp.docx ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Music\_ s2ts\3hWv.wav ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\5VlZfX9.wav ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Favorites\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Maintenance Service\updater.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Documents\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\SoPLA--zPj.pptx ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{e6e75766-da0f-4ba2-9788-6ea593ce702d}\state.rsm ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\NIIxcls.doc ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.012.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.003.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Contacts\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\58.0.3029.110.manifest ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Firefox\AccessibleMarshal.dll ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Windows Journal\family-parliamentary.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.017.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Default\NTUSER.DAT ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\IqG7uC.pdf ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\Provisioning\{f11899f2-71ec-4621-9997-e17ae2f6eb26}\MasterDatastore.xml ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\aclfz Zg378Y6_qpE5.gif ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\AQyW3K.docx ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Videos\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.010.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{e6e75766-da0f-4ba2-9788-6ea593ce702d}\vcredist_x86.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.004.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Default\NTUSER.DAT{77a2c7ed-26f0-11e5-80da-e41d2d741090}.TMContainer00000000000000000002.regtrans-ms ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
c:\users\ciihmnxmn6ps\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1462094071-1423818996-289466292-1000\46a78fa46b43fb180b4fa21773f8ff3e_427a1946-e0ff-4097-8c9e-ca2c1e22780b | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\3lc6q9_bWuznu2v.jpg ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Firefox\api-ms-win-core-errorhandling-l1-1-0.dll ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-processthreads-l1-1-1.dll ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\Diagnosis\ETLLogs\AutoLogger\AutoLogger-Diagtrack-Listener.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Pictures\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Windows Portable Devices\advantageknowledgestormdaddy.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\8i3uwnGFbhZjcDNzr5.docx ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Adobe\Acrobat Reader DC\Resource\ENUtxt.pdf ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Links\Downloads.lnk ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Pictures\YZAivOG1xExfHd6\ijOxx.png ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Music\5rnBuaW9.wav ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\NK_VOcd7S.pptx ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Videos\aP-_O_tjBmfT6a OG.mkv ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.1.xml ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\3H9CRbT.m4a ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Pictures\3VA2_ n7PHo9aZ3-odx\m4dkHJVzpeWkT.png ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\M5-6yrLRIKeVPVkftsA.avi ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\8EXUdg A.pptx ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\PSGet.Format.ps1xml ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Licensing Component.swidtag ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\MF\Pending.GRL ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\9RHfa dbtHtO.docx ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Office\AppXManifest.xml ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Java\jre1.8.0_131\COPYRIGHT ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Favorites\Bing.url ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.007.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Firefox\api-ms-win-core-console-l1-1-0.dll ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Office 15\italianbreakfastinstructors.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\Database1.accdb ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Default\NTUSER.DAT.LOG2 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Videos\7mLe.flv ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Uninstall Information\admit-marvel.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Music\_ s2ts\q4 MB-.wav ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\kD qBQuoHge89T\Oao-IUQTyvQHV.ppt ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Contacts\Aclviho ASldjfl.contact ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Pictures\OgQN5HkjveTjh\DEgCXYOGoIw\2An4F5UkE42NKunbAyO.gif ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\kD qBQuoHge89T\qfKkMd0PO54RLkUoc.ppt ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\2Gnkxda mKIU4zQx0C6.bmp ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Recovery\WindowsRE\ReAgent.xml ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\Cya8Law.jpg ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Searches\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\.LNK ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Microsoft.NET\slovenia.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Office 15\teach.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\jTCAfcL.odt ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.018.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Local\IconCache.db ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Music\_ s2ts\l6EWU.mp3 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Google\hydrocodone against.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\CFjEQ bOBiRCfbhCuV.flv ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Internet Explorer\SIGNUP\install.ins ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Libraries\RecordedTV.library-ms ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Pictures\OgQN5HkjveTjh\MfY1knry.png ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.009.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Firefox\Accessible.tlb ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Pictures\Camera Roll\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\$Recycle.Bin\S-1-5-18\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Links\OneDrive.lnk ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\NyyvnPP1BI6PgL4VR.mp3 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Videos\3UjFJ6JLsAT.flv ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\6q_eLYz.jpg ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Downloads\ChromeSetup.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\Apw7UW24n2 BSd.swf ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\kD qBQuoHge89T\iBXyNeSQbG8k2j2VxRd.rtf ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\User Account Pictures\guest.bmp ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\ALtT7KM4YXT5j.mp4 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\hWmuV_qSmeO41umFIVp.png ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Java\nigeriareached.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Music\_ s2ts\CjE8McLdEkgi.mp3 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Firefox\api-ms-win-core-datetime-l1-1-0.dll ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Google\reprinttruepressing.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Music\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Pictures\nKHtrkHwLM.bmp ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\86vGSbXUZ0qa-T9SqPfh.csv ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\Windows Live\WLive48x48.png ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\VC\msdia100.dll ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\MSEnv\PublicAssemblies\extensibility.dll ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\$Recycle.Bin\S-1-5-21-1462094071-1423818996-289466292-1000\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Java\jre1.8.0_131\LICENSE ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Music\_ s2ts\BVppIdoXOn97lDi7t.mp3 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Videos\cZv6LGehH1hnz1Esk.mp4 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\kD qBQuoHge89T\3F3q Hjy8bvd.pps ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\vc_runtimeAdditional_x86.msi ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Recovery\WindowsRE\Winre.wim ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\Jnx1y.png ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\MF\Active.GRL ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.0.xml ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Adobe\lib-nice-selections.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Extensibility Component.swidtag ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.008.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Microsoft.NET\Primary Interop Assemblies\adodb.dll ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.002.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Downloads\jre-8u131-windows-x64.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Firefox\api-ms-win-core-debug-l1-1-0.dll ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.006.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Pictures\3VA2_ n7PHo9aZ3-odx\F_Sh.bmp ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\8UCpExLC7l2W3oQ.m4a ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Contacts\asdlfk poopvy.contact ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\kD qBQuoHge89T\oesk.xls ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.005.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\CE_872L.m4a ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\1yqOOzLcsJ3FR.m4a ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Music\sspHkttho.wav ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\-QpA4lkxEM8e.png ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{e52a6842-b0ac-476e-b48f-378a97a67346}\state.rsm ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\Stationery\Desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Pictures\3VA2_ n7PHo9aZ3-odx\wPaLCxLVEk8sPBNTFG7.jpg ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Office\FileSystemMetadata.xml ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\chy2jv8x1kFmLn3.mp4 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\AccountPictures\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\fdRbj2oK_nU-_WAAnwEH.wav ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\PowerShellGet.psd1 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Music\_ s2ts\dqAisKMgdCnXXjVAB.mp3 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Music\_ s2ts\72oUps5XOa844yewySkH.wav ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Microsoft.NET\tactics.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOPrivate\UpdateStore\updatestore51b519d5-b6f5-4333-8df6-e74d7c9aead4.xml ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Windows Journal\style_percent.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Maintenance Service\logs\maintenanceservice-install.log ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Windows Mail\definitionselectionsea.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Downloads\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\kD qBQuoHge89T\_u6 QD_8eem.rtf ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\state.rsm ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\154E23D0-C644-4E6F-8CE6-5069272F999F.vsch ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\5FiXE7dIdDZr.docx ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\OMivT7VX5I.ods ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Contacts\sikvnb huvuib.contact ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\np6OUKpYp7Ul0SvY.xlsx ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\Adobe\HelpCfg\en_US\Reader_DC.helpcfg ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Office 15\ClientX64\IntegratedOffice.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{e52a6842-b0ac-476e-b48f-378a97a67346}\VC_redist.x64.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Default\NTUSER.DAT{77a2c7ed-26f0-11e5-80da-e41d2d741090}.TM.blf ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\Qf3SxHIN vDvfU.docx ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Internet Explorer\highlight.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\VC_redist.x86.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Local\Comms\UnistoreDB\store.vol ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\christopher_pro_recruiting.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Downloads\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\IdentityCRL\INT\ppcrlconfig600.dll ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\iNW77vJzgdGc.xlsx ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Music\geAKxrY-UH.mp3 ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Windows NT\demand_sony.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\OneDrive\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\txRbXrt.pptx ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\Provisioning\{1e05dd5d-a022-46c5-963c-b20de341170f}\MasterDatastore.xml ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Pictures\Saved Pictures\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Pictures\8cto6DsS0Tc56.png ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{3c3aafc8-d898-43ec-998f-965ffdae065a}\vcredist_x64.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Internet Explorer\SIGNUP\install.ins ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\TlHV7.odt ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Pictures\3VA2_ n7PHo9aZ3-odx\N1DLcW3msNrt.png ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.013.etl ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Videos\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Links\Desktop.lnk ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Contacts\lulcit amkdfe.contact ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Adobe\Acrobat Reader DC\ReadMe.htm ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Saved Games\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Libraries\desktop.ini ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Windows Photo Viewer\biotechnology.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\i3m1GJbjrf1Ucd.doc ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Adq 0VvG-dOZN4Cm.swf ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Package Cache\{3c3aafc8-d898-43ec-998f-965ffdae065a}\state.rsm ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Reference Assemblies\rely.exe ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
c:\users\ciihmnxmn6ps\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1462094071-1423818996-289466292-1000\46a78fa46b43fb180b4fa21773f8ff3e_427a1946-e0ff-4097-8c9e-ca2c1e22780b | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Desktop\qwlvWbcYpxVH bnTQ.wav ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\CIiHmnxMn6Ps\Documents\kD qBQuoHge89T\IwOfL2HaN.pdf ID NL5VaVIIqOZA.BadNews | Created File | Stream |
Not Queried
|
...
|