Dynamic Analysis Report |
Classification: Riskware, Dropper, Trojan, Ransomware |
1d4342cf02142227e7fa3437f4ee06ed4ef3d59a136eb2fb4e657e1bd782361f (SHA256)
symnfa.exe
Created at 2019-02-27 00:28:00
Notifications (2/4)
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
The overall sleep time of all monitored processes was truncated from "32 minutes, 5 seconds" to "7 minutes" to reveal dormant functionality.
Remarks
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
This list contains only the embedded files and created files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
Severity |
Suspicious
|
First Seen | 2019-02-26 22:14 (UTC+1) |
Last Seen | 2019-02-26 23:47 (UTC+1) |
Names | Win32.Trojan.Filecoder |
Families | Filecoder |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x401a62 |
Size Of Code | 0xb000 |
Size Of Initialized Data | 0x64000 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2019-02-17 17:16:34+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xae87 | 0xb000 | 0x400 | cnt_code, mem_execute, mem_read | 6.61 |
.rdata | 0x40c000 | 0x5956 | 0x5a00 | 0xb400 | cnt_initialized_data, mem_read | 4.89 |
.data | 0x412000 | 0x5d3fc | 0x5ca00 | 0x10e00 | cnt_initialized_data, mem_read, mem_write | 7.03 |
.gfids | 0x470000 | 0xb4 | 0x200 | 0x6d800 | cnt_initialized_data, mem_read | 1.47 |
.reloc | 0x471000 | 0xe30 | 0x1000 | 0x6da00 | cnt_initialized_data, mem_discardable, mem_read | 6.19 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleFileNameW | 0x0 | 0x40c008 | 0x112fc | 0x106fc | 0x214 |
CreateFileW | 0x0 | 0x40c00c | 0x11300 | 0x10700 | 0x8f |
GetVersionExW | 0x0 | 0x40c010 | 0x11304 | 0x10704 | 0x2a4 |
Sleep | 0x0 | 0x40c014 | 0x11308 | 0x10708 | 0x4b2 |
LoadLibraryA | 0x0 | 0x40c018 | 0x1130c | 0x1070c | 0x33c |
WriteFile | 0x0 | 0x40c01c | 0x11310 | 0x10710 | 0x525 |
GetWindowsDirectoryW | 0x0 | 0x40c020 | 0x11314 | 0x10714 | 0x2af |
GetProcAddress | 0x0 | 0x40c024 | 0x11318 | 0x10718 | 0x245 |
FreeLibrary | 0x0 | 0x40c028 | 0x1131c | 0x1071c | 0x162 |
GetTickCount | 0x0 | 0x40c02c | 0x11320 | 0x10720 | 0x293 |
CloseHandle | 0x0 | 0x40c030 | 0x11324 | 0x10724 | 0x52 |
RaiseException | 0x0 | 0x40c034 | 0x11328 | 0x10728 | 0x3b1 |
QueryPerformanceCounter | 0x0 | 0x40c038 | 0x1132c | 0x1072c | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x40c03c | 0x11330 | 0x10730 | 0x1c1 |
GetCurrentThreadId | 0x0 | 0x40c040 | 0x11334 | 0x10734 | 0x1c5 |
GetSystemTimeAsFileTime | 0x0 | 0x40c044 | 0x11338 | 0x10738 | 0x279 |
InitializeSListHead | 0x0 | 0x40c048 | 0x1133c | 0x1073c | 0x2e7 |
IsDebuggerPresent | 0x0 | 0x40c04c | 0x11340 | 0x10740 | 0x300 |
UnhandledExceptionFilter | 0x0 | 0x40c050 | 0x11344 | 0x10744 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x40c054 | 0x11348 | 0x10748 | 0x4a5 |
GetStartupInfoW | 0x0 | 0x40c058 | 0x1134c | 0x1074c | 0x263 |
IsProcessorFeaturePresent | 0x0 | 0x40c05c | 0x11350 | 0x10750 | 0x304 |
GetModuleHandleW | 0x0 | 0x40c060 | 0x11354 | 0x10754 | 0x218 |
TerminateProcess | 0x0 | 0x40c064 | 0x11358 | 0x10758 | 0x4c0 |
GetLastError | 0x0 | 0x40c068 | 0x1135c | 0x1075c | 0x202 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40c06c | 0x11360 | 0x10760 | 0x2e3 |
TlsAlloc | 0x0 | 0x40c070 | 0x11364 | 0x10764 | 0x4c5 |
TlsGetValue | 0x0 | 0x40c074 | 0x11368 | 0x10768 | 0x4c7 |
TlsSetValue | 0x0 | 0x40c078 | 0x1136c | 0x1076c | 0x4c8 |
TlsFree | 0x0 | 0x40c07c | 0x11370 | 0x10770 | 0x4c6 |
LoadLibraryExW | 0x0 | 0x40c080 | 0x11374 | 0x10774 | 0x33e |
RtlUnwind | 0x0 | 0x40c084 | 0x11378 | 0x10778 | 0x418 |
SetLastError | 0x0 | 0x40c088 | 0x1137c | 0x1077c | 0x473 |
EnterCriticalSection | 0x0 | 0x40c08c | 0x11380 | 0x10780 | 0xee |
LeaveCriticalSection | 0x0 | 0x40c090 | 0x11384 | 0x10784 | 0x339 |
DeleteCriticalSection | 0x0 | 0x40c094 | 0x11388 | 0x10788 | 0xd1 |
GetStdHandle | 0x0 | 0x40c098 | 0x1138c | 0x1078c | 0x264 |
GetModuleFileNameA | 0x0 | 0x40c09c | 0x11390 | 0x10790 | 0x213 |
MultiByteToWideChar | 0x0 | 0x40c0a0 | 0x11394 | 0x10794 | 0x367 |
WideCharToMultiByte | 0x0 | 0x40c0a4 | 0x11398 | 0x10798 | 0x511 |
ExitProcess | 0x0 | 0x40c0a8 | 0x1139c | 0x1079c | 0x119 |
GetModuleHandleExW | 0x0 | 0x40c0ac | 0x113a0 | 0x107a0 | 0x217 |
GetACP | 0x0 | 0x40c0b0 | 0x113a4 | 0x107a4 | 0x168 |
HeapFree | 0x0 | 0x40c0b4 | 0x113a8 | 0x107a8 | 0x2cf |
HeapAlloc | 0x0 | 0x40c0b8 | 0x113ac | 0x107ac | 0x2cb |
FindClose | 0x0 | 0x40c0bc | 0x113b0 | 0x107b0 | 0x12e |
FindFirstFileExA | 0x0 | 0x40c0c0 | 0x113b4 | 0x107b4 | 0x133 |
FindNextFileA | 0x0 | 0x40c0c4 | 0x113b8 | 0x107b8 | 0x143 |
IsValidCodePage | 0x0 | 0x40c0c8 | 0x113bc | 0x107bc | 0x30a |
GetOEMCP | 0x0 | 0x40c0cc | 0x113c0 | 0x107c0 | 0x237 |
GetCPInfo | 0x0 | 0x40c0d0 | 0x113c4 | 0x107c4 | 0x172 |
GetCommandLineA | 0x0 | 0x40c0d4 | 0x113c8 | 0x107c8 | 0x186 |
GetCommandLineW | 0x0 | 0x40c0d8 | 0x113cc | 0x107cc | 0x187 |
GetEnvironmentStringsW | 0x0 | 0x40c0dc | 0x113d0 | 0x107d0 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x40c0e0 | 0x113d4 | 0x107d4 | 0x161 |
LCMapStringW | 0x0 | 0x40c0e4 | 0x113d8 | 0x107d8 | 0x32d |
SetStdHandle | 0x0 | 0x40c0e8 | 0x113dc | 0x107dc | 0x487 |
GetFileType | 0x0 | 0x40c0ec | 0x113e0 | 0x107e0 | 0x1f3 |
GetStringTypeW | 0x0 | 0x40c0f0 | 0x113e4 | 0x107e4 | 0x269 |
GetProcessHeap | 0x0 | 0x40c0f4 | 0x113e8 | 0x107e8 | 0x24a |
HeapSize | 0x0 | 0x40c0f8 | 0x113ec | 0x107ec | 0x2d4 |
HeapReAlloc | 0x0 | 0x40c0fc | 0x113f0 | 0x107f0 | 0x2d2 |
FlushFileBuffers | 0x0 | 0x40c100 | 0x113f4 | 0x107f4 | 0x157 |
GetConsoleCP | 0x0 | 0x40c104 | 0x113f8 | 0x107f8 | 0x19a |
GetConsoleMode | 0x0 | 0x40c108 | 0x113fc | 0x107fc | 0x1ac |
SetFilePointerEx | 0x0 | 0x40c10c | 0x11400 | 0x10800 | 0x467 |
WriteConsoleW | 0x0 | 0x40c110 | 0x11404 | 0x10804 | 0x524 |
DecodePointer | 0x0 | 0x40c114 | 0x11408 | 0x10808 | 0xca |
GetCurrentProcess | 0x0 | 0x40c118 | 0x1140c | 0x1080c | 0x1c0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x40c120 | 0x11414 | 0x10814 | 0x122 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SystemFunction036 | 0x0 | 0x40c000 | 0x112f4 | 0x106f4 | 0x2f1 |
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user.bmp.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessibility\Desktop.ini.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\20\189.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\XPS Viewer.lnk.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.007.etl.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\09\238.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Sticky Notes.lnk.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\desktop.ini.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\MetaStore\2\61\EFAE1E6619D4EE51.dat.RYK | Modified File | Stream |
Unknown
|
...
|
c:\programdata\microsoft\user account pictures\user-192.png | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.014.etl.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\05\191.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.018.etl.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\05\317.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft OneDrive\setup\refcount.ini.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Acrobat Reader DC.lnk.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\About Java.lnk.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Wordpad.lnk.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Word 2016.lnk.RYK | Modified File | Stream |
Unknown
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Tablet PC\Desktop.ini.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user-32.png.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\03\324.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\17\193.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\09\13711.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\Get Help.url.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.021.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\PowerPoint.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\15\288 | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\10\286.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.005.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\04\259.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\MF\Active.GRL.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Visio.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\04\261.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.009.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Project.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\06\13710.RYK | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\22\323 | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\Check For Updates.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\adobe\arm\reader_17.012.20098\acrordrdcupd1800920044_incr.msp | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.010.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\MpDiag.bin.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\01\263.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\21\260.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents\My Music\desktop.ini.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\01\198.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Devices Flow.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Outlook.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\desktop.ini.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\OneDrive for Business.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Desktop\desktop.ini.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Access.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\System Tools\Task Manager.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.002.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Outlook 2016.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Math Input Panel.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\DeploymentConfig.0.xml.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\guest.bmp.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Oracle\Java\installcache_x64\baseimagefam8.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\17\300.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Access 2016.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.006.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\09\287.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Search.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\MetaStore\3\0000000000000000.idx.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user-40.png.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\guest.png.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\PrintDialog.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\10\267.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\DownloadedSettings\utc.app.json.bk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\11\200.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\15\262.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\MiracastView.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\07\273.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live\WLive48x48.png.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.004.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\DeploymentConfig.2.xml.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\10\197.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents\desktop.ini.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Desktop.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.019.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\18\107001 | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Word.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user-48.png.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\14\9664.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Immersive Control Panel.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\Visit Java.com.url.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\19\272.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\dfrgui.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\StartUp\desktop.ini.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\19\328.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\18\107002.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\05\199.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\MetaStore\1\0000000000000000.idx.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents\My Videos\desktop.ini.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.015.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Publisher.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Snipping Tool.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\DeploymentConfig.1.xml.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Skype for Business.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Paint.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\System Tools\Desktop.ini.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.008.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\01\271.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.016.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\00\192.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\System Tools\Default Programs.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\15\196.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Adobe\ARM\Reader_17.012.20098\AcroRdrDCUpd1800920044_incr.msp.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\OneNote 2016.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\19\266.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateUx.001.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\21\13719.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user.png.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Skype for Business 2016.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\windows\start menu\programs\accessories\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.011.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\Policy.vpol.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\13\278.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.020.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Steps Recorder.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\12\194.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\desktop.ini.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Excel 2016.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\02\303.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Mput\MputHistory\15\13712.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\MF\Pending.GRL.RYK | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\windows defender\scans\history\mput\mputhistory\18\195 | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Visio 2016.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents\My Pictures\desktop.ini.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.001.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.003.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\PowerPoint 2016.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.012.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\DownloadedScenarios\Windows.Uif.static.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Project 2016.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\Configure Java.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Publisher 2016.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.013.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.017.etl.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\MetaStore\2\90\B6D0EAFA5E8634A6.dat.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Desktop\Acrobat Reader DC.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Excel.lnk.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\MetaStore\2\0000000000000000.idx.RYK | Modified File | Stream |
Not Queried
|
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Maintenance\Desktop.ini.RYK | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\crypto\rsa\machinekeys\08e575673cce10c72090304839888e02_427a1946-e0ff-4097-8c9e-ca2c1e22780b | Created File | Stream |
Not Queried
|
...
|
Image Base | 0x140000000 |
Entry Point | 0x140008b44 |
Size Of Code | 0x16a00 |
Size Of Initialized Data | 0x379800 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | amd64 |
Compile Timestamp | 2019-02-17 17:16:26+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x140001000 | 0x16850 | 0x16a00 | 0x400 | cnt_code, mem_execute, mem_read | 6.29 |
.rdata | 0x140018000 | 0xa508 | 0xa600 | 0x16e00 | cnt_initialized_data, mem_read | 5.11 |
.data | 0x140023000 | 0x36d3c0 | 0xfa00 | 0x21400 | cnt_initialized_data, mem_read, mem_write | 1.62 |
.pdata | 0x140391000 | 0x1128 | 0x1200 | 0x30e00 | cnt_initialized_data, mem_read | 5.02 |
.gfids | 0x140393000 | 0xa8 | 0x200 | 0x32000 | cnt_initialized_data, mem_read | 1.44 |
.rsrc | 0x140394000 | 0x1e0 | 0x200 | 0x32200 | cnt_initialized_data, mem_read | 4.72 |
.reloc | 0x140395000 | 0x61c | 0x800 | 0x32400 | cnt_initialized_data, mem_discardable, mem_read | 4.76 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleHandleA | 0x0 | 0x140018058 | 0x21af8 | 0x208f8 | 0x21b |
OpenProcess | 0x0 | 0x140018060 | 0x21b00 | 0x20900 | 0x382 |
CreateToolhelp32Snapshot | 0x0 | 0x140018068 | 0x21b08 | 0x20908 | 0xbd |
Sleep | 0x0 | 0x140018070 | 0x21b10 | 0x20910 | 0x4c0 |
GetLastError | 0x0 | 0x140018078 | 0x21b18 | 0x20918 | 0x208 |
Process32NextW | 0x0 | 0x140018080 | 0x21b20 | 0x20920 | 0x39a |
GetCurrentThread | 0x0 | 0x140018088 | 0x21b28 | 0x20928 | 0x1ca |
LoadLibraryA | 0x0 | 0x140018090 | 0x21b30 | 0x20930 | 0x33e |
GlobalAlloc | 0x0 | 0x140018098 | 0x21b38 | 0x20938 | 0x2bb |
DeleteFileW | 0x0 | 0x1400180a0 | 0x21b40 | 0x20940 | 0xd7 |
Process32FirstW | 0x0 | 0x1400180a8 | 0x21b48 | 0x20948 | 0x398 |
GetVersionExW | 0x0 | 0x1400180b0 | 0x21b50 | 0x20950 | 0x2ac |
CloseHandle | 0x0 | 0x1400180b8 | 0x21b58 | 0x20958 | 0x52 |
CreateThread | 0x0 | 0x1400180c0 | 0x21b60 | 0x20960 | 0xb4 |
HeapAlloc | 0x0 | 0x1400180c8 | 0x21b68 | 0x20968 | 0x2d3 |
GetWindowsDirectoryW | 0x0 | 0x1400180d0 | 0x21b70 | 0x20970 | 0x2b7 |
GetProcAddress | 0x0 | 0x1400180d8 | 0x21b78 | 0x20978 | 0x24c |
VirtualAllocEx | 0x0 | 0x1400180e0 | 0x21b80 | 0x20980 | 0x4f9 |
LocalFree | 0x0 | 0x1400180e8 | 0x21b88 | 0x20988 | 0x34a |
GetProcessHeap | 0x0 | 0x1400180f0 | 0x21b90 | 0x20990 | 0x251 |
FreeLibrary | 0x0 | 0x1400180f8 | 0x21b98 | 0x20998 | 0x168 |
CreateRemoteThread | 0x0 | 0x140018100 | 0x21ba0 | 0x209a0 | 0xa9 |
VirtualFreeEx | 0x0 | 0x140018108 | 0x21ba8 | 0x209a8 | 0x4fc |
CreateFileW | 0x0 | 0x140018110 | 0x21bb0 | 0x209b0 | 0x8f |
GetModuleFileNameW | 0x0 | 0x140018118 | 0x21bb8 | 0x209b8 | 0x21a |
VirtualAlloc | 0x0 | 0x140018120 | 0x21bc0 | 0x209c0 | 0x4f8 |
GetCurrentProcess | 0x0 | 0x140018128 | 0x21bc8 | 0x209c8 | 0x1c6 |
GetCommandLineW | 0x0 | 0x140018130 | 0x21bd0 | 0x209d0 | 0x18d |
VirtualFree | 0x0 | 0x140018138 | 0x21bd8 | 0x209d8 | 0x4fb |
SetLastError | 0x0 | 0x140018140 | 0x21be0 | 0x209e0 | 0x480 |
HeapFree | 0x0 | 0x140018148 | 0x21be8 | 0x209e8 | 0x2d7 |
GlobalFree | 0x0 | 0x140018150 | 0x21bf0 | 0x209f0 | 0x2c2 |
WriteConsoleW | 0x0 | 0x140018158 | 0x21bf8 | 0x209f8 | 0x533 |
SetFilePointerEx | 0x0 | 0x140018160 | 0x21c00 | 0x20a00 | 0x475 |
HeapReAlloc | 0x0 | 0x140018168 | 0x21c08 | 0x20a08 | 0x2da |
RtlCaptureContext | 0x0 | 0x140018170 | 0x21c10 | 0x20a10 | 0x418 |
RtlLookupFunctionEntry | 0x0 | 0x140018178 | 0x21c18 | 0x20a18 | 0x41f |
RtlVirtualUnwind | 0x0 | 0x140018180 | 0x21c20 | 0x20a20 | 0x426 |
UnhandledExceptionFilter | 0x0 | 0x140018188 | 0x21c28 | 0x20a28 | 0x4e2 |
SetUnhandledExceptionFilter | 0x0 | 0x140018190 | 0x21c30 | 0x20a30 | 0x4b3 |
TerminateProcess | 0x0 | 0x140018198 | 0x21c38 | 0x20a38 | 0x4ce |
IsProcessorFeaturePresent | 0x0 | 0x1400181a0 | 0x21c40 | 0x20a40 | 0x306 |
QueryPerformanceCounter | 0x0 | 0x1400181a8 | 0x21c48 | 0x20a48 | 0x3a9 |
GetCurrentProcessId | 0x0 | 0x1400181b0 | 0x21c50 | 0x20a50 | 0x1c7 |
GetCurrentThreadId | 0x0 | 0x1400181b8 | 0x21c58 | 0x20a58 | 0x1cb |
GetSystemTimeAsFileTime | 0x0 | 0x1400181c0 | 0x21c60 | 0x20a60 | 0x280 |
InitializeSListHead | 0x0 | 0x1400181c8 | 0x21c68 | 0x20a68 | 0x2ef |
IsDebuggerPresent | 0x0 | 0x1400181d0 | 0x21c70 | 0x20a70 | 0x302 |
GetStartupInfoW | 0x0 | 0x1400181d8 | 0x21c78 | 0x20a78 | 0x26a |
GetModuleHandleW | 0x0 | 0x1400181e0 | 0x21c80 | 0x20a80 | 0x21e |
RtlUnwindEx | 0x0 | 0x1400181e8 | 0x21c88 | 0x20a88 | 0x425 |
RaiseException | 0x0 | 0x1400181f0 | 0x21c90 | 0x20a90 | 0x3b4 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x1400181f8 | 0x21c98 | 0x20a98 | 0x2eb |
TlsAlloc | 0x0 | 0x140018200 | 0x21ca0 | 0x20aa0 | 0x4d3 |
TlsGetValue | 0x0 | 0x140018208 | 0x21ca8 | 0x20aa8 | 0x4d5 |
TlsSetValue | 0x0 | 0x140018210 | 0x21cb0 | 0x20ab0 | 0x4d6 |
TlsFree | 0x0 | 0x140018218 | 0x21cb8 | 0x20ab8 | 0x4d4 |
LoadLibraryExW | 0x0 | 0x140018220 | 0x21cc0 | 0x20ac0 | 0x340 |
EnterCriticalSection | 0x0 | 0x140018228 | 0x21cc8 | 0x20ac8 | 0xf2 |
LeaveCriticalSection | 0x0 | 0x140018230 | 0x21cd0 | 0x20ad0 | 0x33b |
DeleteCriticalSection | 0x0 | 0x140018238 | 0x21cd8 | 0x20ad8 | 0xd2 |
ExitProcess | 0x0 | 0x140018240 | 0x21ce0 | 0x20ae0 | 0x11f |
GetModuleHandleExW | 0x0 | 0x140018248 | 0x21ce8 | 0x20ae8 | 0x21d |
GetStdHandle | 0x0 | 0x140018250 | 0x21cf0 | 0x20af0 | 0x26b |
WriteFile | 0x0 | 0x140018258 | 0x21cf8 | 0x20af8 | 0x534 |
MultiByteToWideChar | 0x0 | 0x140018260 | 0x21d00 | 0x20b00 | 0x369 |
WideCharToMultiByte | 0x0 | 0x140018268 | 0x21d08 | 0x20b08 | 0x520 |
GetACP | 0x0 | 0x140018270 | 0x21d10 | 0x20b10 | 0x16e |
LCMapStringW | 0x0 | 0x140018278 | 0x21d18 | 0x20b18 | 0x32f |
GetStringTypeW | 0x0 | 0x140018280 | 0x21d20 | 0x20b20 | 0x270 |
GetFileType | 0x0 | 0x140018288 | 0x21d28 | 0x20b28 | 0x1fa |
FindClose | 0x0 | 0x140018290 | 0x21d30 | 0x20b30 | 0x134 |
FindFirstFileExW | 0x0 | 0x140018298 | 0x21d38 | 0x20b38 | 0x13a |
FindNextFileW | 0x0 | 0x1400182a0 | 0x21d40 | 0x20b40 | 0x14b |
IsValidCodePage | 0x0 | 0x1400182a8 | 0x21d48 | 0x20b48 | 0x30c |
GetOEMCP | 0x0 | 0x1400182b0 | 0x21d50 | 0x20b50 | 0x23e |
GetCPInfo | 0x0 | 0x1400182b8 | 0x21d58 | 0x20b58 | 0x178 |
GetCommandLineA | 0x0 | 0x1400182c0 | 0x21d60 | 0x20b60 | 0x18c |
GetEnvironmentStringsW | 0x0 | 0x1400182c8 | 0x21d68 | 0x20b68 | 0x1e1 |
FreeEnvironmentStringsW | 0x0 | 0x1400182d0 | 0x21d70 | 0x20b70 | 0x167 |
SetStdHandle | 0x0 | 0x1400182d8 | 0x21d78 | 0x20b78 | 0x494 |
FlushFileBuffers | 0x0 | 0x1400182e0 | 0x21d80 | 0x20b80 | 0x15d |
GetConsoleCP | 0x0 | 0x1400182e8 | 0x21d88 | 0x20b88 | 0x1a0 |
GetConsoleMode | 0x0 | 0x1400182f0 | 0x21d90 | 0x20b90 | 0x1b2 |
HeapSize | 0x0 | 0x1400182f8 | 0x21d98 | 0x20b98 | 0x2dc |
WriteProcessMemory | 0x0 | 0x140018300 | 0x21da0 | 0x20ba0 | 0x53d |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SystemFunction036 | 0x0 | 0x140018000 | 0x21aa0 | 0x208a0 | 0x2f1 |
LookupPrivilegeValueW | 0x0 | 0x140018008 | 0x21aa8 | 0x208a8 | 0x197 |
AdjustTokenPrivileges | 0x0 | 0x140018010 | 0x21ab0 | 0x208b0 | 0x1f |
OpenSCManagerW | 0x0 | 0x140018018 | 0x21ab8 | 0x208b8 | 0x1f9 |
ImpersonateSelf | 0x0 | 0x140018020 | 0x21ac0 | 0x208c0 | 0x175 |
OpenProcessToken | 0x0 | 0x140018028 | 0x21ac8 | 0x208c8 | 0x1f7 |
EnumServicesStatusW | 0x0 | 0x140018030 | 0x21ad0 | 0x208d0 | 0x102 |
OpenThreadToken | 0x0 | 0x140018038 | 0x21ad8 | 0x208d8 | 0x1fc |
LookupAccountSidW | 0x0 | 0x140018040 | 0x21ae0 | 0x208e0 | 0x191 |
GetTokenInformation | 0x0 | 0x140018048 | 0x21ae8 | 0x208e8 | 0x15a |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x140018310 | 0x21db0 | 0x20bb0 | 0x122 |
CommandLineToArgvW | 0x0 | 0x140018318 | 0x21db8 | 0x20bb8 | 0x6 |