VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware |
qwywod.exe
Windows Exe (x86-32)
Created at 2019-10-14T08:53:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402690 |
Size Of Code | 0x6600 |
Size Of Initialized Data | 0x4200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-10-08 15:56:28+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x65da | 0x6600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.25 |
.rdata | 0x408000 | 0x1228 | 0x1400 | 0x6a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.81 |
.data | 0x40a000 | 0x2314 | 0x200 | 0x7e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.26 |
.rsrc | 0x40d000 | 0x360 | 0x400 | 0x8000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.96 |
.reloc | 0x40e000 | 0x4a0 | 0x600 | 0x8400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.66 |
.key | 0x40f000 | 0x1000 | 0x600 | 0x8a00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.51 |
Imports (9)
»
MPR.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetEnumResourceW | 0x0 | 0x408158 | 0x8964 | 0x7364 | 0x23 |
WNetOpenEnumW | 0x0 | 0x40815c | 0x8968 | 0x7368 | 0x44 |
WNetCloseEnum | 0x0 | 0x408160 | 0x896c | 0x736c | 0x17 |
SHLWAPI.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StrStrW | 0x0 | 0x408174 | 0x8980 | 0x7380 | 0x152 |
PathRemoveFileSpecW | 0x0 | 0x408178 | 0x8984 | 0x7384 | 0x8f |
StrStrA | 0x0 | 0x40817c | 0x8988 | 0x7388 | 0x14d |
StrStrIA | 0x0 | 0x408180 | 0x898c | 0x738c | 0x14e |
wvnsprintfA | 0x0 | 0x408184 | 0x8990 | 0x7390 | 0x179 |
wvnsprintfW | 0x0 | 0x408188 | 0x8994 | 0x7394 | 0x17a |
PathAddBackslashW | 0x0 | 0x40818c | 0x8998 | 0x7398 | 0x33 |
PathRemoveBackslashW | 0x0 | 0x408190 | 0x899c | 0x739c | 0x89 |
StrToIntW | 0x0 | 0x408194 | 0x89a0 | 0x73a0 | 0x158 |
PathFileExistsW | 0x0 | 0x408198 | 0x89a4 | 0x73a4 | 0x49 |
PathCombineW | 0x0 | 0x40819c | 0x89a8 | 0x73a8 | 0x3d |
KERNEL32.dll (65)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetLastError | 0x0 | 0x408050 | 0x885c | 0x725c | 0x250 |
GetProcAddress | 0x0 | 0x408054 | 0x8860 | 0x7260 | 0x29d |
GetModuleHandleA | 0x0 | 0x408058 | 0x8864 | 0x7264 | 0x264 |
FindFirstFileW | 0x0 | 0x40805c | 0x8868 | 0x7268 | 0x173 |
FindClose | 0x0 | 0x408060 | 0x886c | 0x726c | 0x168 |
FindNextFileW | 0x0 | 0x408064 | 0x8870 | 0x7270 | 0x17f |
DeleteFileW | 0x0 | 0x408068 | 0x8874 | 0x7274 | 0x10a |
ExitProcess | 0x0 | 0x40806c | 0x8878 | 0x7278 | 0x151 |
SetUnhandledExceptionFilter | 0x0 | 0x408070 | 0x887c | 0x727c | 0x543 |
SetEvent | 0x0 | 0x408074 | 0x8880 | 0x7280 | 0x4f0 |
GetCommandLineA | 0x0 | 0x408078 | 0x8884 | 0x7284 | 0x1c8 |
TerminateThread | 0x0 | 0x40807c | 0x8888 | 0x7288 | 0x562 |
CreateEventW | 0x0 | 0x408080 | 0x888c | 0x728c | 0xb6 |
GetModuleFileNameA | 0x0 | 0x408084 | 0x8890 | 0x7290 | 0x262 |
CreateProcessA | 0x0 | 0x408088 | 0x8894 | 0x7294 | 0xd7 |
GetUserDefaultUILanguage | 0x0 | 0x40808c | 0x8898 | 0x7298 | 0x2ff |
AllocConsole | 0x0 | 0x408090 | 0x889c | 0x729c | 0x15 |
WriteFile | 0x0 | 0x408094 | 0x88a0 | 0x72a0 | 0x5e1 |
LeaveCriticalSection | 0x0 | 0x408098 | 0x88a4 | 0x72a4 | 0x3a2 |
GetStdHandle | 0x0 | 0x40809c | 0x88a8 | 0x72a8 | 0x2c0 |
EnterCriticalSection | 0x0 | 0x4080a0 | 0x88ac | 0x72ac | 0x125 |
lstrcatW | 0x0 | 0x4080a4 | 0x88b0 | 0x72b0 | 0x5fc |
Wow64RevertWow64FsRedirection | 0x0 | 0x4080a8 | 0x88b4 | 0x72b4 | 0x5d3 |
Wow64DisableWow64FsRedirection | 0x0 | 0x4080ac | 0x88b8 | 0x72b8 | 0x5cf |
LoadLibraryW | 0x0 | 0x4080b0 | 0x88bc | 0x72bc | 0x3a8 |
GetSystemDirectoryW | 0x0 | 0x4080b4 | 0x88c0 | 0x72c0 | 0x2cd |
WaitForSingleObject | 0x0 | 0x4080b8 | 0x88c4 | 0x72c4 | 0x5ab |
GetCurrentProcess | 0x0 | 0x4080bc | 0x88c8 | 0x72c8 | 0x209 |
VirtualQuery | 0x0 | 0x4080c0 | 0x88cc | 0x72cc | 0x5a3 |
GetUserDefaultLocaleName | 0x0 | 0x4080c4 | 0x88d0 | 0x72d0 | 0x2fe |
GetVolumeNameForVolumeMountPointW | 0x0 | 0x4080c8 | 0x88d4 | 0x72d4 | 0x30a |
WideCharToMultiByte | 0x0 | 0x4080cc | 0x88d8 | 0x72d8 | 0x5cd |
MultiByteToWideChar | 0x0 | 0x4080d0 | 0x88dc | 0x72dc | 0x3d1 |
lstrcpynA | 0x0 | 0x4080d4 | 0x88e0 | 0x72e0 | 0x607 |
Sleep | 0x0 | 0x4080d8 | 0x88e4 | 0x72e4 | 0x552 |
MoveFileW | 0x0 | 0x4080dc | 0x88e8 | 0x72e8 | 0x3cd |
GetFileAttributesW | 0x0 | 0x4080e0 | 0x88ec | 0x72ec | 0x235 |
CreateFileW | 0x0 | 0x4080e4 | 0x88f0 | 0x72f0 | 0xc2 |
GetFileSizeEx | 0x0 | 0x4080e8 | 0x88f4 | 0x72f4 | 0x23c |
CreateMutexW | 0x0 | 0x4080ec | 0x88f8 | 0x72f8 | 0xd1 |
GetProcessHeap | 0x0 | 0x4080f0 | 0x88fc | 0x72fc | 0x2a2 |
HeapFree | 0x0 | 0x4080f4 | 0x8900 | 0x7300 | 0x333 |
HeapAlloc | 0x0 | 0x4080f8 | 0x8904 | 0x7304 | 0x32f |
HeapReAlloc | 0x0 | 0x4080fc | 0x8908 | 0x7308 | 0x336 |
CreateThread | 0x0 | 0x408100 | 0x890c | 0x730c | 0xe8 |
GetCurrentProcessId | 0x0 | 0x408104 | 0x8910 | 0x7310 | 0x20a |
GetWindowsDirectoryW | 0x0 | 0x408108 | 0x8914 | 0x7314 | 0x310 |
CloseHandle | 0x0 | 0x40810c | 0x8918 | 0x7318 | 0x7f |
WaitForMultipleObjects | 0x0 | 0x408110 | 0x891c | 0x731c | 0x5a9 |
SetThreadPriority | 0x0 | 0x408114 | 0x8920 | 0x7320 | 0x535 |
ExitThread | 0x0 | 0x408118 | 0x8924 | 0x7324 | 0x152 |
lstrcatA | 0x0 | 0x40811c | 0x8928 | 0x7328 | 0x5fb |
InitializeCriticalSection | 0x0 | 0x408120 | 0x892c | 0x732c | 0x347 |
GetCurrentThread | 0x0 | 0x408124 | 0x8930 | 0x7330 | 0x20d |
GetLogicalDrives | 0x0 | 0x408128 | 0x8934 | 0x7334 | 0x257 |
GetDriveTypeW | 0x0 | 0x40812c | 0x8938 | 0x7338 | 0x21f |
ReadFile | 0x0 | 0x408130 | 0x893c | 0x733c | 0x450 |
CreateFileMappingW | 0x0 | 0x408134 | 0x8940 | 0x7340 | 0xbf |
UnmapViewOfFile | 0x0 | 0x408138 | 0x8944 | 0x7344 | 0x585 |
MapViewOfFile | 0x0 | 0x40813c | 0x8948 | 0x7348 | 0x3c0 |
GetTickCount | 0x0 | 0x408140 | 0x894c | 0x734c | 0x2f2 |
SetFilePointerEx | 0x0 | 0x408144 | 0x8950 | 0x7350 | 0x4fd |
SetEndOfFile | 0x0 | 0x408148 | 0x8954 | 0x7354 | 0x4ea |
FlushFileBuffers | 0x0 | 0x40814c | 0x8958 | 0x7358 | 0x192 |
lstrlenA | 0x0 | 0x408150 | 0x895c | 0x735c | 0x60a |
USER32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetKeyboardLayoutList | 0x0 | 0x4081a4 | 0x89b0 | 0x73b0 | 0x155 |
MessageBoxA | 0x0 | 0x4081a8 | 0x89b4 | 0x73b4 | 0x246 |
wvsprintfA | 0x0 | 0x4081ac | 0x89b8 | 0x73b8 | 0x37c |
GetDlgItemTextA | 0x0 | 0x4081b0 | 0x89bc | 0x73bc | 0x13e |
DialogBoxParamA | 0x0 | 0x4081b4 | 0x89c0 | 0x73c0 | 0xb1 |
EndDialog | 0x0 | 0x4081b8 | 0x89c4 | 0x73c4 | 0xe7 |
wsprintfW | 0x0 | 0x4081bc | 0x89c8 | 0x73c8 | 0x37b |
ADVAPI32.dll (16)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegDeleteValueA | 0x0 | 0x408000 | 0x880c | 0x720c | 0x26b |
CryptExportKey | 0x0 | 0x408004 | 0x8810 | 0x7210 | 0xcf |
CryptSetKeyParam | 0x0 | 0x408008 | 0x8814 | 0x7214 | 0xdd |
RegQueryValueExW | 0x0 | 0x40800c | 0x8818 | 0x7218 | 0x292 |
CryptDecrypt | 0x0 | 0x408010 | 0x881c | 0x721c | 0xc4 |
CryptEncrypt | 0x0 | 0x408014 | 0x8820 | 0x7220 | 0xca |
CryptDestroyKey | 0x0 | 0x408018 | 0x8824 | 0x7224 | 0xc7 |
CryptGenKey | 0x0 | 0x40801c | 0x8828 | 0x7228 | 0xd0 |
RegSetValueExW | 0x0 | 0x408020 | 0x882c | 0x722c | 0x2a2 |
RegCloseKey | 0x0 | 0x408024 | 0x8830 | 0x7230 | 0x254 |
RegFlushKey | 0x0 | 0x408028 | 0x8834 | 0x7234 | 0x277 |
RegOpenKeyExW | 0x0 | 0x40802c | 0x8838 | 0x7238 | 0x285 |
CryptImportKey | 0x0 | 0x408030 | 0x883c | 0x723c | 0xda |
RegCreateKeyExW | 0x0 | 0x408034 | 0x8840 | 0x7240 | 0x25d |
CryptReleaseContext | 0x0 | 0x408038 | 0x8844 | 0x7244 | 0xdb |
CryptAcquireContextW | 0x0 | 0x40803c | 0x8848 | 0x7248 | 0xc1 |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetFolderPathW | 0x0 | 0x408168 | 0x8974 | 0x7374 | 0xd2 |
ShellExecuteExW | 0x0 | 0x40816c | 0x8978 | 0x7378 | 0x136 |
ole32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoInitializeEx | 0x0 | 0x4081cc | 0x89d8 | 0x73d8 | 0x50 |
CLSIDFromString | 0x0 | 0x4081d0 | 0x89dc | 0x73dc | 0xc |
CoInitialize | 0x0 | 0x4081d4 | 0x89e0 | 0x73e0 | 0x4f |
CoCreateInstance | 0x0 | 0x4081d8 | 0x89e4 | 0x73e4 | 0x1a |
msvcrt.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_except_handler3 | 0x0 | 0x4081c4 | 0x89d0 | 0x73d0 | 0x158 |
CRYPT32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptBinaryToStringA | 0x0 | 0x408044 | 0x8850 | 0x7250 | 0x7d |
CryptStringToBinaryA | 0x0 | 0x408048 | 0x8854 | 0x7254 | 0xe2 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
qwywod.exe | 1 | 0x00A60000 | 0x00A6FFFF | Relevant Image | - | 32-bit | - |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.3 |
Malicious
|
C:\Users\FD1HVy\Desktop\DECRYPT_FILES.lnk | Dropped File | Shortcut |
Unknown
|
...
|
»
C:\Users\FD1HVy\ntuser.ini.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\ntuser.ini.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\0uznes.gif.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\1d7dZR0.jpg.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\1X4wmVa.bmp.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\aar4wXwobwm8v j.mp3.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\aar4wXwobwm8v j.mp3.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\AcOLQjuLNXMql.gif.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\dFw90W0ozbqlw.mkv.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\DUv6 W1yQ.jpg.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\fXjbV28LC0IFk.png.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\gRmt1-B0wood4cXHs.png.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\hHGe8VXor0p6BX.m4a.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\I-BWfibG3J13RaqGB.pptx.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\i74al7MC18tUuay.m4a.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\i74al7MC18tUuay.m4a.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\JDQEwi6ArW.xls.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\k0UuJx_g_DcQHkPS7.png.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\KEBUC5mjwXRfQmP-VL.wav.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\LC8mHy4MO_lq.flv.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\LX62 bOC84McF_7.jpg.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\mUD1TZtWU.flv.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\puH1 V9zpzVTs8eyCQ.mp4.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\puH1 V9zpzVTs8eyCQ.mp4.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\R7Xo1pIDUa2Xzbh.m4a.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\R7Xo1pIDUa2Xzbh.m4a.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\s5dkeFUgebSmSVLuL.gif.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\STG7KypQe_U5z55v6.wav.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\t9rbGMSGn.xlsx.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\tiIa0efX69B.jpg.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\u2ZUuS8-WjDeO2.wav.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\unique_decrypt.key.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\wuPx.mp3.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Yfgph0gV.swf.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Yfgph0gV.swf.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\ywvxv9U.gif.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\yxoK.bmp.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\ZazBvQZ_SvZ5b.flv.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\_kDdpHsuJIdzTzf4Y7D.jpg.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\_kDdpHsuJIdzTzf4Y7D.jpg.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\XCVUDUNH\#AppContainer\aa.online-metrix.net\fpc.swf\session.sol.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\XCVUDUNH\#AppContainer\aa.online-metrix.net\fpc.swf\session.sol.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#aa.online-metrix.net\settings.sol.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#aa.online-metrix.net\settings.sol.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Access\System.mdw.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\APASixthEditionOfficeOnline.xsl.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\APASixthEditionOfficeOnline.xsl.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\CHICAGO.XSL.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\GostName.XSL.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\GostTitle.XSL.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\HarvardAnglia2008OfficeOnline.xsl.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\HarvardAnglia2008OfficeOnline.xsl.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\IEEE2006OfficeOnline.xsl.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\ISO690.XSL.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\ISO690Nmerical.XSL.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\MLASeventhEditionOfficeOnline.xsl.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\SIST02.XSL.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\TURABIAN.XSL.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\TURABIAN.XSL.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1051304884-625712362-2192934891-1000\83aa4cc77f591dfc2374580bbd95f6ba_33d770d0-06bc-47c5-8714-222cdac43a71.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1051304884-625712362-2192934891-1000\ec679dec92129330b5b05a3aa424ac05_33d770d0-06bc-47c5-8714-222cdac43a71.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Document Building Blocks\1033\16\Built-In Building Blocks.dotx.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\desktop.ini.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\desktop.ini.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\MS Project\16\en-US\Global.MPT.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Office\MSO1033.acl.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Office\MSO1033.acl.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Office\Recent\con2.LNK.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Office\Recent\Database1.LNK.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Office\Recent\Documents.LNK.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Office\Recent\Global.LNK.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Office\Recent\index.dat.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Office\Recent\Templates.LNK.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Office\Recent\Templates.LNK.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Outlook\Outlook.srs.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Outlook\Outlook.xml.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\CREDHIST.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\SYNCHIST.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\SYNCHIST.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\S-1-5-21-1051304884-625712362-2192934891-1000\20cac00a-26e8-46c6-ab84-90a52b05e557.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\S-1-5-21-1051304884-625712362-2192934891-1000\5c4d6ef6-b3c3-469c-83d7-eb4debf6bfd1.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\S-1-5-21-1051304884-625712362-2192934891-1000\b1334ab7-7773-4cde-b00c-b3b6e1e6ed9f.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\S-1-5-21-1051304884-625712362-2192934891-1000\ddbd6a25-732f-4175-9949-5cdf51e0bd09.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\S-1-5-21-1051304884-625712362-2192934891-1000\Preferred.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Speech\Files\UserLexicons\SP_31FD1255772945E99CBED4370F39872D.dat.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Speech\Files\UserLexicons\SP_31FD1255772945E99CBED4370F39872D.dat.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Templates\Cashflow analysis.xltm.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Templates\Normal.dotm.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\AccountPictures\desktop.ini.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\AccountPictures\desktop.ini.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Libraries\CameraRoll.library-ms.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Libraries\SavedPictures.library-ms.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\- BGCTQP_oc.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\- BGCTQP_oc.lnk.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\-8uAG9oxUf-hK.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\-dJtnAUOOQzvv7Sta.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\-HpIv8B0j5lezuuXMs.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\0-X9v.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\0BMtIgULhsjNh69RE4R.lnk.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\0YKCZvD.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\1fJbXUeqaQ0.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\1KJv1fN7ry_.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\1vHknANfpxmxhu.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\1X4wmVa.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\1_FD.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\2 yXsPUC0GNavVxC Fst.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\2HMvxJbgu86g.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\2jZdV25MK2Ss.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\388f.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\39aQ.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\4vvwNb6.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\5Fvi.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\6rJr.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\6XR7YRGHkty.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\7npl KTnMO.flv.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\7sYqE1e.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\8AH6.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\97fA0RJbCRegJ90g4.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\9XgYhPYcWzu1Fe.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\a1X2_-WPNwQzbcqj.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\AcOLQjuLNXMql.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\AGjmuyB-BW6pOtioq.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\aPnyZYbrX3YqN-JqGl2Q.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Ar6kH-cK.lnk.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\AWZI9 (2).lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\AWZI9.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\BIa5loVm.lnk.omnisphere | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\BIa5loVm.lnk.omnisphere.id | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Adobe\Sonar\Sonar1.0\!DECRYPT_OMNISPHERE.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\MS Project\16\en-US\unique_decrypt.key | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\0qM7PXCSnWH2CmmBFnz8.avi.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\0qM7PXCSnWH2CmmBFnz8.avi.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\gRmt1-B0wood4cXHs.png.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\hp5HOWNcI9SrI.xlsx.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\I-BWfibG3J13RaqGB.pptx.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\k0UuJx_g_DcQHkPS7.png.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\KEBUC5mjwXRfQmP-VL.wav.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\LX62 bOC84McF_7.jpg.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\s5dkeFUgebSmSVLuL.gif.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\STG7KypQe_U5z55v6.wav.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\tx_oE.avi.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\xrFH_.wav.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Access\AccessCache.accdb.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Access\System.mdw.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\GB.XSL.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\GostName.XSL.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\GostTitle.XSL.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\IEEE2006OfficeOnline.xsl.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Bibliography\Style\MLASeventhEditionOfficeOnline.xsl.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1051304884-625712362-2192934891-1000\83aa4cc77f591dfc2374580bbd95f6ba_33d770d0-06bc-47c5-8714-222cdac43a71.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1051304884-625712362-2192934891-1000\ec679dec92129330b5b05a3aa424ac05_33d770d0-06bc-47c5-8714-222cdac43a71.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Office\Recent\Documents.LNK.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Outlook\Outlook.srs.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Outlook\Outlook.xml.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\CREDHIST.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\S-1-5-21-1051304884-625712362-2192934891-1000\20cac00a-26e8-46c6-ab84-90a52b05e557.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\S-1-5-21-1051304884-625712362-2192934891-1000\5c4d6ef6-b3c3-469c-83d7-eb4debf6bfd1.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\S-1-5-21-1051304884-625712362-2192934891-1000\67634331-9abb-48ea-9c31-082141ff901d.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\S-1-5-21-1051304884-625712362-2192934891-1000\67634331-9abb-48ea-9c31-082141ff901d.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\S-1-5-21-1051304884-625712362-2192934891-1000\7a70842e-d6a2-46c1-966c-384a4ef9d347.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\S-1-5-21-1051304884-625712362-2192934891-1000\7a70842e-d6a2-46c1-966c-384a4ef9d347.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\S-1-5-21-1051304884-625712362-2192934891-1000\b1334ab7-7773-4cde-b00c-b3b6e1e6ed9f.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Protect\S-1-5-21-1051304884-625712362-2192934891-1000\ddbd6a25-732f-4175-9949-5cdf51e0bd09.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Templates\Welcome to Excel.xltx.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Templates\Welcome to Excel.xltx.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Libraries\desktop.ini.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Libraries\SavedPictures.library-ms.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt.omnisphere | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\-FRHxieAIkz.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\-tJJk6- Iis.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\0BMtIgULhsjNh69RE4R.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\0tq M_cT tEcyU 7qggP.flv.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\0uznes.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\1d7dZR0.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\5QADBusLM.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\6nik2H95B_ogXKnNe.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\7cwY3XNtx1KVaERb.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\9cb4lAWmT4epM 8gG.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\9Knv8Dbpe8QFyRb.flv.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\aar4wXwobwm8v j.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Ar6kH-cK.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\BiUlTgA5fV_8e8CfhUI.lnk.omnisphere.id | Dropped File | Stream |
Not Queried
|
...
|
»