VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Trojan.GenericKD.34327466
Mal/Generic-S
|
QUyN8szwNXaqf4vU.exe
Windows Exe (x86-64)
Created at 2020-08-10T22:29:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\QUyN8szwNXaqf4vU.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x140000000 |
Entry Point | 0x140031190 |
Size Of Code | 0x4ea00 |
Size Of Initialized Data | 0x1f000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 2020-08-09 18:09:44+00:00 |
Sections (7)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x140001000 | 0x4e82e | 0x4ea00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.4 |
.rdata | 0x140050000 | 0x17f5c | 0x18000 | 0x4ee00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.59 |
.data | 0x140068000 | 0x2dac | 0x1400 | 0x66e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.68 |
.pdata | 0x14006b000 | 0x3498 | 0x3600 | 0x68200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.63 |
_RDATA | 0x14006f000 | 0x94 | 0x200 | 0x6b800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.43 |
.rsrc | 0x140070000 | 0x1e0 | 0x200 | 0x6ba00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.7 |
.reloc | 0x140071000 | 0x7d8 | 0x800 | 0x6bc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.4 |
Imports (11)
»
CRYPT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptStringToBinaryA | 0x0 | 0x1400500c0 | 0x66e98 | 0x65c98 | 0xde |
MPR.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetGetConnectionW | 0x0 | 0x140050488 | 0x67260 | 0x66060 | 0x2b |
KERNEL32.dll (111)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindNextFileW | 0x0 | 0x140050108 | 0x66ee0 | 0x65ce0 | 0x192 |
RemoveDirectoryW | 0x0 | 0x140050110 | 0x66ee8 | 0x65ce8 | 0x4bd |
SetFileTime | 0x0 | 0x140050118 | 0x66ef0 | 0x65cf0 | 0x534 |
FindClose | 0x0 | 0x140050120 | 0x66ef8 | 0x65cf8 | 0x17b |
CopyFileW | 0x0 | 0x140050128 | 0x66f00 | 0x65d00 | 0xad |
GetFileTime | 0x0 | 0x140050130 | 0x66f08 | 0x65d08 | 0x254 |
GetLastError | 0x0 | 0x140050138 | 0x66f10 | 0x65d10 | 0x267 |
CreateEventW | 0x0 | 0x140050140 | 0x66f18 | 0x65d18 | 0xbf |
SetEvent | 0x0 | 0x140050148 | 0x66f20 | 0x65d20 | 0x524 |
WaitForSingleObjectEx | 0x0 | 0x140050150 | 0x66f28 | 0x65d28 | 0x5e7 |
GetLogicalDrives | 0x0 | 0x140050158 | 0x66f30 | 0x65d30 | 0x26e |
MultiByteToWideChar | 0x0 | 0x140050160 | 0x66f38 | 0x65d38 | 0x3f2 |
WideCharToMultiByte | 0x0 | 0x140050168 | 0x66f40 | 0x65d40 | 0x60d |
CreateProcessW | 0x0 | 0x140050170 | 0x66f48 | 0x65d48 | 0xe5 |
CreateDirectoryW | 0x0 | 0x140050178 | 0x66f50 | 0x65d50 | 0xba |
GetCurrentProcess | 0x0 | 0x140050180 | 0x66f58 | 0x65d58 | 0x21d |
WaitForMultipleObjects | 0x0 | 0x140050188 | 0x66f60 | 0x65d60 | 0x5e4 |
GetQueuedCompletionStatus | 0x0 | 0x140050190 | 0x66f68 | 0x65d68 | 0x2d1 |
ResumeThread | 0x0 | 0x140050198 | 0x66f70 | 0x65d70 | 0x4d1 |
PostQueuedCompletionStatus | 0x0 | 0x1400501a0 | 0x66f78 | 0x65d78 | 0x426 |
GetExitCodeThread | 0x0 | 0x1400501a8 | 0x66f80 | 0x65d80 | 0x244 |
TerminateThread | 0x0 | 0x1400501b0 | 0x66f88 | 0x65d88 | 0x59b |
CreateThread | 0x0 | 0x1400501b8 | 0x66f90 | 0x65d90 | 0xf2 |
ExitProcess | 0x0 | 0x1400501c0 | 0x66f98 | 0x65d98 | 0x164 |
CreateIoCompletionPort | 0x0 | 0x1400501c8 | 0x66fa0 | 0x65da0 | 0xd0 |
FormatMessageA | 0x0 | 0x1400501d0 | 0x66fa8 | 0x65da8 | 0x1ac |
LoadLibraryExA | 0x0 | 0x1400501d8 | 0x66fb0 | 0x65db0 | 0x3c5 |
FreeLibrary | 0x0 | 0x1400501e0 | 0x66fb8 | 0x65db8 | 0x1b1 |
HeapCreate | 0x0 | 0x1400501e8 | 0x66fc0 | 0x65dc0 | 0x350 |
HeapFree | 0x0 | 0x1400501f0 | 0x66fc8 | 0x65dc8 | 0x352 |
HeapLock | 0x0 | 0x1400501f8 | 0x66fd0 | 0x65dd0 | 0x353 |
FindFirstFileW | 0x0 | 0x140050200 | 0x66fd8 | 0x65dd8 | 0x186 |
HeapDestroy | 0x0 | 0x140050208 | 0x66fe0 | 0x65de0 | 0x351 |
HeapUnlock | 0x0 | 0x140050210 | 0x66fe8 | 0x65de8 | 0x359 |
GetConsoleMode | 0x0 | 0x140050218 | 0x66ff0 | 0x65df0 | 0x202 |
GetConsoleCP | 0x0 | 0x140050220 | 0x66ff8 | 0x65df8 | 0x1f0 |
HeapReAlloc | 0x0 | 0x140050228 | 0x67000 | 0x65e00 | 0x355 |
HeapSize | 0x0 | 0x140050230 | 0x67008 | 0x65e08 | 0x357 |
GetStringTypeW | 0x0 | 0x140050238 | 0x67010 | 0x65e10 | 0x2de |
SetStdHandle | 0x0 | 0x140050240 | 0x67018 | 0x65e18 | 0x557 |
lstrcpyW | 0x0 | 0x140050248 | 0x67020 | 0x65e20 | 0x649 |
Process32FirstW | 0x0 | 0x140050250 | 0x67028 | 0x65e28 | 0x42f |
lstrcatW | 0x0 | 0x140050258 | 0x67030 | 0x65e30 | 0x640 |
Process32NextW | 0x0 | 0x140050260 | 0x67038 | 0x65e38 | 0x431 |
CreateToolhelp32Snapshot | 0x0 | 0x140050268 | 0x67040 | 0x65e40 | 0xfb |
OpenProcess | 0x0 | 0x140050270 | 0x67048 | 0x65e48 | 0x410 |
GetEnvironmentVariableW | 0x0 | 0x140050278 | 0x67050 | 0x65e50 | 0x240 |
GetModuleFileNameW | 0x0 | 0x140050280 | 0x67058 | 0x65e58 | 0x27a |
TerminateProcess | 0x0 | 0x140050288 | 0x67060 | 0x65e60 | 0x59a |
GetShortPathNameW | 0x0 | 0x140050290 | 0x67068 | 0x65e68 | 0x2d4 |
LocalFree | 0x0 | 0x140050298 | 0x67070 | 0x65e70 | 0x3d2 |
GetSystemInfo | 0x0 | 0x1400502a0 | 0x67078 | 0x65e78 | 0x2ea |
Sleep | 0x0 | 0x1400502a8 | 0x67080 | 0x65e80 | 0x58b |
GetCommandLineW | 0x0 | 0x1400502b0 | 0x67088 | 0x65e88 | 0x1dd |
FlushFileBuffers | 0x0 | 0x1400502b8 | 0x67090 | 0x65e90 | 0x1a5 |
DeleteCriticalSection | 0x0 | 0x1400502c0 | 0x67098 | 0x65e98 | 0x111 |
SetFilePointerEx | 0x0 | 0x1400502c8 | 0x670a0 | 0x65ea0 | 0x531 |
GetLocalTime | 0x0 | 0x1400502d0 | 0x670a8 | 0x65ea8 | 0x268 |
InitializeCriticalSection | 0x0 | 0x1400502d8 | 0x670b0 | 0x65eb0 | 0x367 |
LeaveCriticalSection | 0x0 | 0x1400502e0 | 0x670b8 | 0x65eb8 | 0x3c0 |
EnterCriticalSection | 0x0 | 0x1400502e8 | 0x670c0 | 0x65ec0 | 0x135 |
SleepEx | 0x0 | 0x1400502f0 | 0x670c8 | 0x65ec8 | 0x58e |
CloseHandle | 0x0 | 0x1400502f8 | 0x670d0 | 0x65ed0 | 0x86 |
DeleteFileW | 0x0 | 0x140050300 | 0x670d8 | 0x65ed8 | 0x116 |
SetFileAttributesW | 0x0 | 0x140050308 | 0x670e0 | 0x65ee0 | 0x52b |
GetProcessHeap | 0x0 | 0x140050310 | 0x670e8 | 0x65ee8 | 0x2bb |
FreeEnvironmentStringsW | 0x0 | 0x140050318 | 0x670f0 | 0x65ef0 | 0x1b0 |
GetEnvironmentStringsW | 0x0 | 0x140050320 | 0x670f8 | 0x65ef8 | 0x23e |
GetCommandLineA | 0x0 | 0x140050328 | 0x67100 | 0x65f00 | 0x1dc |
GetCPInfo | 0x0 | 0x140050330 | 0x67108 | 0x65f08 | 0x1c7 |
GetOEMCP | 0x0 | 0x140050338 | 0x67110 | 0x65f10 | 0x29e |
GetACP | 0x0 | 0x140050340 | 0x67118 | 0x65f18 | 0x1b8 |
IsValidCodePage | 0x0 | 0x140050348 | 0x67120 | 0x65f20 | 0x38e |
FindFirstFileExW | 0x0 | 0x140050350 | 0x67128 | 0x65f28 | 0x181 |
GetFileType | 0x0 | 0x140050358 | 0x67130 | 0x65f30 | 0x255 |
LCMapStringW | 0x0 | 0x140050360 | 0x67138 | 0x65f38 | 0x3b4 |
CreateFileW | 0x0 | 0x140050368 | 0x67140 | 0x65f40 | 0xcb |
WriteFile | 0x0 | 0x140050370 | 0x67148 | 0x65f48 | 0x621 |
GetFileSizeEx | 0x0 | 0x140050378 | 0x67150 | 0x65f50 | 0x253 |
ReadFile | 0x0 | 0x140050380 | 0x67158 | 0x65f58 | 0x477 |
WriteConsoleW | 0x0 | 0x140050388 | 0x67160 | 0x65f60 | 0x620 |
HeapAlloc | 0x0 | 0x140050390 | 0x67168 | 0x65f68 | 0x34e |
GetStdHandle | 0x0 | 0x140050398 | 0x67170 | 0x65f70 | 0x2d9 |
GetModuleHandleExW | 0x0 | 0x1400503a0 | 0x67178 | 0x65f78 | 0x27d |
LoadLibraryExW | 0x0 | 0x1400503a8 | 0x67180 | 0x65f80 | 0x3c6 |
TlsFree | 0x0 | 0x1400503b0 | 0x67188 | 0x65f88 | 0x5ad |
TlsSetValue | 0x0 | 0x1400503b8 | 0x67190 | 0x65f90 | 0x5af |
TlsGetValue | 0x0 | 0x1400503c0 | 0x67198 | 0x65f98 | 0x5ae |
TlsAlloc | 0x0 | 0x1400503c8 | 0x671a0 | 0x65fa0 | 0x5ac |
EncodePointer | 0x0 | 0x1400503d0 | 0x671a8 | 0x65fa8 | 0x131 |
SetLastError | 0x0 | 0x1400503d8 | 0x671b0 | 0x65fb0 | 0x53f |
RaiseException | 0x0 | 0x1400503e0 | 0x671b8 | 0x65fb8 | 0x466 |
RtlPcToFileHeader | 0x0 | 0x1400503e8 | 0x671c0 | 0x65fc0 | 0x4dc |
RtlUnwindEx | 0x0 | 0x1400503f0 | 0x671c8 | 0x65fc8 | 0x4e0 |
InitializeSListHead | 0x0 | 0x1400503f8 | 0x671d0 | 0x65fd0 | 0x36c |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x140050400 | 0x671d8 | 0x65fd8 | 0x368 |
ResetEvent | 0x0 | 0x140050408 | 0x671e0 | 0x65fe0 | 0x4ca |
GetModuleHandleW | 0x0 | 0x140050410 | 0x671e8 | 0x65fe8 | 0x27e |
GetProcAddress | 0x0 | 0x140050418 | 0x671f0 | 0x65ff0 | 0x2b5 |
RtlCaptureContext | 0x0 | 0x140050420 | 0x671f8 | 0x65ff8 | 0x4d3 |
RtlLookupFunctionEntry | 0x0 | 0x140050428 | 0x67200 | 0x66000 | 0x4da |
RtlVirtualUnwind | 0x0 | 0x140050430 | 0x67208 | 0x66008 | 0x4e1 |
IsDebuggerPresent | 0x0 | 0x140050438 | 0x67210 | 0x66010 | 0x382 |
UnhandledExceptionFilter | 0x0 | 0x140050440 | 0x67218 | 0x66018 | 0x5bc |
SetUnhandledExceptionFilter | 0x0 | 0x140050448 | 0x67220 | 0x66020 | 0x57b |
GetStartupInfoW | 0x0 | 0x140050450 | 0x67228 | 0x66028 | 0x2d7 |
IsProcessorFeaturePresent | 0x0 | 0x140050458 | 0x67230 | 0x66030 | 0x389 |
QueryPerformanceCounter | 0x0 | 0x140050460 | 0x67238 | 0x66038 | 0x450 |
GetCurrentProcessId | 0x0 | 0x140050468 | 0x67240 | 0x66040 | 0x21e |
GetCurrentThreadId | 0x0 | 0x140050470 | 0x67248 | 0x66048 | 0x222 |
GetSystemTimeAsFileTime | 0x0 | 0x140050478 | 0x67250 | 0x66050 | 0x2f0 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfW | 0x0 | 0x140050500 | 0x672d8 | 0x660d8 | 0x3e5 |
CharLowerBuffW | 0x0 | 0x140050508 | 0x672e0 | 0x660e0 | 0x30 |
ADVAPI32.dll (23)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OpenServiceW | 0x0 | 0x140050000 | 0x66dd8 | 0x65bd8 | 0x219 |
RegOpenKeyExW | 0x0 | 0x140050008 | 0x66de0 | 0x65be0 | 0x28c |
RegSetValueExW | 0x0 | 0x140050010 | 0x66de8 | 0x65be8 | 0x2a9 |
RegCloseKey | 0x0 | 0x140050018 | 0x66df0 | 0x65bf0 | 0x25b |
CryptReleaseContext | 0x0 | 0x140050020 | 0x66df8 | 0x65bf8 | 0xdc |
CryptGenKey | 0x0 | 0x140050028 | 0x66e00 | 0x65c00 | 0xd1 |
CryptImportKey | 0x0 | 0x140050030 | 0x66e08 | 0x65c08 | 0xdb |
CryptExportKey | 0x0 | 0x140050038 | 0x66e10 | 0x65c10 | 0xd0 |
CryptDecrypt | 0x0 | 0x140050040 | 0x66e18 | 0x65c18 | 0xc5 |
OpenProcessToken | 0x0 | 0x140050048 | 0x66e20 | 0x65c20 | 0x215 |
GetTokenInformation | 0x0 | 0x140050050 | 0x66e28 | 0x65c28 | 0x170 |
CloseServiceHandle | 0x0 | 0x140050058 | 0x66e30 | 0x65c30 | 0x65 |
OpenSCManagerW | 0x0 | 0x140050060 | 0x66e38 | 0x65c38 | 0x217 |
DeleteService | 0x0 | 0x140050068 | 0x66e40 | 0x65c40 | 0xec |
ControlService | 0x0 | 0x140050070 | 0x66e48 | 0x65c48 | 0x6a |
StartServiceW | 0x0 | 0x140050078 | 0x66e50 | 0x65c50 | 0x2fb |
CryptCreateHash | 0x0 | 0x140050080 | 0x66e58 | 0x65c58 | 0xc4 |
CryptHashData | 0x0 | 0x140050088 | 0x66e60 | 0x65c60 | 0xd9 |
CryptDestroyHash | 0x0 | 0x140050090 | 0x66e68 | 0x65c68 | 0xc7 |
CryptGetHashParam | 0x0 | 0x140050098 | 0x66e70 | 0x65c70 | 0xd5 |
CryptDestroyKey | 0x0 | 0x1400500a0 | 0x66e78 | 0x65c78 | 0xc8 |
CryptAcquireContextW | 0x0 | 0x1400500a8 | 0x66e80 | 0x65c80 | 0xc2 |
CryptEncrypt | 0x0 | 0x1400500b0 | 0x66e88 | 0x65c88 | 0xcb |
SHELL32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHEmptyRecycleBinW | 0x0 | 0x1400504d0 | 0x672a8 | 0x660a8 | 0x13a |
ShellExecuteExW | 0x0 | 0x1400504d8 | 0x672b0 | 0x660b0 | 0x1b6 |
ShellExecuteW | 0x0 | 0x1400504e0 | 0x672b8 | 0x660b8 | 0x1b7 |
SHGetKnownFolderPath | 0x0 | 0x1400504e8 | 0x672c0 | 0x660c0 | 0x162 |
CommandLineToArgvW | 0x0 | 0x1400504f0 | 0x672c8 | 0x660c8 | 0x7 |
ole32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoUninitialize | 0x0 | 0x140050588 | 0x67360 | 0x66160 | 0x90 |
CoCreateInstance | 0x0 | 0x140050590 | 0x67368 | 0x66168 | 0x2b |
CoInitializeSecurity | 0x0 | 0x140050598 | 0x67370 | 0x66170 | 0x62 |
CoInitializeEx | 0x0 | 0x1400505a0 | 0x67378 | 0x66178 | 0x61 |
CoTaskMemFree | 0x0 | 0x1400505a8 | 0x67380 | 0x66180 | 0x8c |
OLEAUT32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantClear | 0x9 | 0x1400504b0 | 0x67288 | 0x66088 | - |
SysFreeString | 0x6 | 0x1400504b8 | 0x67290 | 0x66090 | - |
SysAllocString | 0x2 | 0x1400504c0 | 0x67298 | 0x66098 | - |
NETAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareEnum | 0x0 | 0x140050498 | 0x67270 | 0x66070 | 0xde |
NetApiBufferFree | 0x0 | 0x1400504a0 | 0x67278 | 0x66078 | 0x51 |
IPHLPAPI.DLL (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetAdaptersInfo | 0x0 | 0x1400500d0 | 0x66ea8 | 0x65ca8 | 0x44 |
IcmpSendEcho2 | 0x0 | 0x1400500d8 | 0x66eb0 | 0x65cb0 | 0x9a |
IcmpParseReplies | 0x0 | 0x1400500e0 | 0x66eb8 | 0x65cb8 | 0x98 |
IcmpCloseHandle | 0x0 | 0x1400500e8 | 0x66ec0 | 0x65cc0 | 0x96 |
IcmpCreateFile | 0x0 | 0x1400500f0 | 0x66ec8 | 0x65cc8 | 0x97 |
IcmpSendEcho | 0x0 | 0x1400500f8 | 0x66ed0 | 0x65cd0 | 0x99 |
WS2_32.dll (13)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
connect | 0x4 | 0x140050518 | 0x672f0 | 0x660f0 | - |
getaddrinfo | 0x0 | 0x140050520 | 0x672f8 | 0x660f8 | 0xa5 |
closesocket | 0x3 | 0x140050528 | 0x67300 | 0x66100 | - |
select | 0x12 | 0x140050530 | 0x67308 | 0x66108 | - |
shutdown | 0x16 | 0x140050538 | 0x67310 | 0x66110 | - |
WSAStartup | 0x73 | 0x140050540 | 0x67318 | 0x66118 | - |
send | 0x13 | 0x140050548 | 0x67320 | 0x66120 | - |
socket | 0x17 | 0x140050550 | 0x67328 | 0x66128 | - |
WSACleanup | 0x74 | 0x140050558 | 0x67330 | 0x66130 | - |
recv | 0x10 | 0x140050560 | 0x67338 | 0x66138 | - |
WSAGetLastError | 0x6f | 0x140050568 | 0x67340 | 0x66140 | - |
freeaddrinfo | 0x0 | 0x140050570 | 0x67348 | 0x66148 | 0xa4 |
inet_addr | 0xb | 0x140050578 | 0x67350 | 0x66150 | - |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
quyn8szwnxaqf4vu.exe | 1 | 0x13F490000 | 0x13F501FFF | Relevant Image | 64-bit | 0x13F4C0A58 |
...
|
|||
quyn8szwnxaqf4vu.exe | 1 | 0x13F490000 | 0x13F501FFF | Final Dump | 64-bit | - |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.34327466 |
Malicious
|
C:\Boot\en-US\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\ja-JP\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\pl-PL\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\nb-NO\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\sv-SE\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer\ie8props.propdesc.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Internet Explorer\ie8props.propdesc.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\Fonts\cht_boot.ttf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\freebl3.chk.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\nssdbm3.chk.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.EXCEL.14.1033.hxn.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\Fonts\jpn_boot.ttf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\DVD Maker\directshowtap.ax.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\DVD Maker\offset.ax.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\DVD Maker\rtstreamsink.ax.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\DVD Maker\rtstreamsource.ax.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\DVD Maker\soniccolorconverter.ax.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.MSOUC.14.1033.hxn.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.MSPUB.DEV.14.1033.hxn.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\Fonts\wgl4_boot.ttf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.MSTORE.14.1033.hxn.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.SETLANG.14.1033.hxn.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.VISIO.DEV.14.1033.hxn.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.VISIO_STD.14.1033.hxn.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.WINWORD.DEV.14.1033.hxn.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\precomplete.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\ehome\ehRecvr.exe.config.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\ehome\ehshell.exe.config.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\8514fix.fon.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\8514oem.fon.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\8514oemr.fon.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\8514oemt.fon.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\8514sys.fon.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\8514syse.fon.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\af9035bda.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\8514sysr.fon.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\AppPatch\sysmain.sdb.pandemic | Dropped File | Binary |
Unknown
|
...
|
»
C:\Windows\inf\amdsbs.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\85855.fon.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\85f1256.fon.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\angel64.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\atiilhag.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\ehome\malgunmc.ttf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\averfx2swtv_noavin_x64.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\85s1256.fon.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\avmx64c.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\brmfcmdm.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\ANTQUAB.TTF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\aparajb.ttf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\aparaji.ttf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\app855.fon.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\app866.fon.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\L2Schemas\LAN_policy_v1.xsd.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\cxfalcon_ibv64.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\app932.fon.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\app936.fon.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\L2Schemas\OneX_v1.xsd.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\ding.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\ir_end.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\cxraptor_fm1216mk5_ibv64.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\notify.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\dc21x4vm.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Panther\cbs_unattend.log.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Panther\Contents1.dir.pandemic | Dropped File | Binary |
Unknown
|
...
|
»
C:\Windows\Media\ringout.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\disk.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\arialbd.ttf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\Speech Disambiguation.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\Speech On.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\ehome\WTVGOTHIC-R.ttc.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\ARIALN.TTF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\Speech Sleep.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Panther\setup.etl.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Panther\setupact.log.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\ARIALNB.TTF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Fonts\ARIALNBI.TTF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\town.mid.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Panther\setupinfo.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\faxcn002.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\Windows Battery Critical.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\hcw72b64.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\hcw85b64.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\Windows Default.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\hidirkbd.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\Windows Feed Discovered.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\hidserv.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\Windows Hardware Remove.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\Windows Information Bar.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\Windows Navigation Start.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\AddRemovePrograms.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\AppCompat.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\Windows Print complete.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Media\Windows Shutdown.wav.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\Biometrics.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\ControlPanel.admx.pandemic | Dropped File | Binary |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\Cpls.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\CredUI.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\DCOM.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\keyboard.PNF.pandemic | Dropped File | Binary |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\DeviceInstallation.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\DiskDiagnostic.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\DiskQuota.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\kscaptur.PNF.pandemic | Dropped File | Binary |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\DnsClient.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\ksfilter.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\lsi_fc.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\EnhancedStorage.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\lsi_sas.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\EventLog.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\EventViewer.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\fthsvc.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\mcx2.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\mdm5674a.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\mdmagm64.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\ICM.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Prefetch\ADDINUTIL.EXE-8F48E508.pf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\mdmairte.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\mdmaiwa3.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Prefetch\BCSSYNC.EXE-861DE060.pf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\mdmaiwa4.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Prefetch\BCSSYNC.EXE-E11E559D.pf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Prefetch\BOOTSTRAP_X86_64.EXE-B4992A3A.pf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Services\verisign.bmp.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\mdmar1.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Prefetch\CLEAN_NET_64.EXE-4AB4B238.pf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Prefetch\CLEAN_NET_64.EXE-98AE464C.pf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\mdmaus.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\mdmboca.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\iSCSI.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\mdmbr004.PNF.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Prefetch\DINOTIFY.EXE-06EB7C61.pf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Prefetch\DLLHOST.EXE-71214090.pf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Prefetch\DLLHOST.EXE-893DDF55.pf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\Kerberos.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\LinkLayerTopologyDiscovery.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Prefetch\EXCEL.EXE-DA46ABE4.pf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\MMCSnapins.admx.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Prefetch\FLASHPLAYER11_2R202_233_WINAX-361B57A6.pf.pandemic | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\inf\mdmbw561.PNF.pandemic | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Windows\Prefetch\FUNKY MEMORIES.EXE-6735C7FD.pf.pandemic | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Windows\inf\mdmcdp.PNF.pandemic | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Windows\PolicyDefinitions\MSDT.admx.pandemic | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Windows\Prefetch\JAVACPL.EXE-2F6C67E0.pf.pandemic | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Boot\cs-CZ\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\de-DE\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\da-DK\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\el-GR\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\en-US\memtest.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\es-ES\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\fr-FR\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\fi-FI\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\hu-HU\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\it-IT\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\ko-KR\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\pt-BR\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\nl-NL\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Fonts\chs_boot.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\ru-RU\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\pt-PT\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\zh-CN\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\DtcInstall.log.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\zh-HK\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\zh-TW\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\tr-TR\bootmgr.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Professional.xml.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\setupact.log.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\TSSysprep.log.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\WindowsShell.Manifest.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\WindowsUpdate.log.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\dependentlibs.list.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\WMSysPr9.prx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\install.log.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\DVD Maker\audiodepthconverter.ax.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\MSBuild\Microsoft.Office.InfoPath.targets.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\DVD Maker\bod_r.TTF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\Hx.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.EXCEL.DEV.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\DVD Maker\Eurosti.TTF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\DVD Maker\fieldswitch.ax.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\DVD Maker\SecretST.TTF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\DVD Maker\sonicsptransform.ax.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.GRAPH.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.GROOVE.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.INFOPATH.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.INFOPATHEDITOR.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.MSACCESS.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.MSACCESS.DEV.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Fonts\kor_boot.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.MSPUB.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.OIS.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.ONENOTE.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.OUTLOOK.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.OUTLOOK.DEV.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\omni.ja.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.POWERPNT.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.POWERPNT.DEV.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.VISIO.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.VISIO.SHAPESHEET.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.VISIO_PRM.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.WINPROJ.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.WINPROJ.DEV.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\MS.WINWORD.14.1033.hxn.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft Help\nslist.hxl.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\removed-files.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\softokn3.chk.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG1.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\debug\sammui.log.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\addins\FXSEXT.ecf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\AppPatch\drvmain.sdb.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\ehcir.ird.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\ehexthost.exe.config.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\ehRec.exe.config.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\AppPatch\msimain.sdb.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\ehSched.exe.config.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\AppPatch\pcamain.sdb.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\en-US\bfsvc.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\luttx43.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\1394.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\luttx83.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\61883.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\en-US\explorer.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\en-US\fveupdate.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\en-US\helppane.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\8514fixe.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\8514fixg.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\acpi.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\8514fixr.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\8514fixt.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\acpipmi.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\en-US\hh.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\8514oeme.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\8514oemg.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\en-US\notepad.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\adp94xx.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\adpahci.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\en-US\regedit.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\en-US\twain_32.dll.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\adpu320.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\en-US\winhlp32.exe.mui.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\8514sysg.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\amdsata.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\8514syst.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\85775.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\angel264.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\85f1255.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\angelu64.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\85f1257.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\arcsas.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\atiriol6.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\avc.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\85f874.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\averfx2hbh826d_noaverir_x64.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\85s1255.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\averfx2hbtv_x64.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\averfx2swtv_x64.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\averhbh826_noaverir_x64.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\85s1257.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\85s874.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\battery.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\AGENCYB.TTF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\AGENCYR.TTF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\ahronbd.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\bda.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\blbdrive.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\ALGER.TTF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\andlso.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\mcetuningoverrides.xml.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\brmfcmf.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\angsa.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\angsab.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\angsai.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\angsau.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\angsaub.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\angsaui.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\mcskin.wmz.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\mcsrchPH.propdesc.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\MediaCenterWebLauncher.exe.manifest.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\brmfcsto.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\brmfcumd.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\brmfcwia.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\angsauz.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\angsaz.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\segmcr.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\segmcsb.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\ANTQUABI.TTF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\brmfport.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\ANTQUAI.TTF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\aparaj.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\segoemcl.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\SS2.dvr-ms.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\bthmtpenum.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\bthpan.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\SS51.dvr-ms.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\bthprint.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\bthspp.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\aparajbi.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\cdrom.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\app775.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\circlass.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\compositebus.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\cpu.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\app850.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\app852.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\app857.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\crcdisk.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\L2Schemas\LAN_profile_v1.xsd.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\chimes.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\L2Schemas\WLANAP_profile_v1.xsd.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\chord.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\L2Schemas\WLAN_policy_v1.xsd.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\app949.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\flourish.mid.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\ir_begin.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\cxfalpal_ibv64.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\app950.fon.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\L2Schemas\WLAN_profile_v1.xsd.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\ir_inter.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\L2Schemas\WWAN_profile_v1.xsd.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\onestop.mid.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\cxraptor_fm1236mk5_ibv64.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\recycle.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\arabtype.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\cxraptor_philipstuv1236d_ibv64.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Panther\cbs.log.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Panther\Contents0.dir.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Panther\DDACLSys.log.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\arial.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\digitalmediadevice.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\display.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Panther\diagerr.xml.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\divacx64.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\dot4.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Speech Misrecognition.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Panther\diagwrn.xml.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\arialbi.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Speech Off.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Panther\MainQueueOnline0.que.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\dot4prt.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\eaphost.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\ariali.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Panther\MainQueueOnline1.que.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\ehstorcertdrv.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\ehstorpwddrv.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\elxstor.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\tada.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Balloon.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Panther\setuperr.log.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Panther\unattend.xml.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\faxca003.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\faxcn001.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\ARIALNI.TTF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\flpydisk.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\gameport.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\hal.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Battery Low.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Critical Stop.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\hcw85c64.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\hdaudbus.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\hdaudio.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Ding.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\hdaudss.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\hidbth.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\hiddigi.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\hidir.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Error.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Exclamation.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Hardware Fail.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\hpoa1nd.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Hardware Insert.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\hpoa1sd.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Logoff Sound.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\hpoa1so.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Logon Sound.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Menu Command.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\hpoa1ss.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Minimize.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Notify.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Pop-up Blocked.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\ActiveXInstallService.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\AttachmentManager.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\AutoPlay.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\hpsamd.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\iastorv.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Recycle.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Restore.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\igdlh.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\iirsp.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\iirsp2.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\image.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Ringin.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Ringout.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows Startup.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Media\Windows User Account Control.wav.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\Bits.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\CEIPEnable.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\CipherSuiteOrder.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\input.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\COM.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\WTVGOTHIC-RB.ttc.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\Conf.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\ipmidrv.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\ControlPanelDisplay.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\CredentialProviders.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\CredSsp.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\iscsi.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\CtrlAltDel.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\Desktop.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\DeviceRedirection.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\DFS.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\DigitalLocker.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\DiskNVCache.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\ks.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\DistributedLinkTracking.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\DWM.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\EncryptFilesonMove.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\lltdio.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\ErrorReporting.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\EventForwarding.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\lsi_sas2.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\lsi_scsi.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\machine.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\Explorer.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\FileRecovery.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\FileSys.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\FolderRedirection.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\FramePanes.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mchgr.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdm3com.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\GameExplorer.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\Globalization.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\GroupPolicy.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\Help.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmadc.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\HelpAndSupport.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\HotStart.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\3DFTP.EXE-ABEF5C88.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\IIS.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmags64.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmaiwa.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\ADDINUTIL.EXE-AF83E25A.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\ADOBEARM.EXE-E8E973DD.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\ehome\WTVGOTHIC-S.ttc.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\AUDIODG.EXE-D0D776AC.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmaiwa5.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\CHROME.EXE-5FE9909D.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmaiwat.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\ARIALUNI.TTF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\CLEANMGR.EXE-B508FB28.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmarch.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmarn.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmati.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\CLEAN_NET_64.EXE-AC3CFA5D.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\CMD.EXE-89305D47.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmatm2k.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\COMPMGMTLAUNCHER.EXE-0BF80059.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\CONHOST.EXE-3218E401.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\CONSENT.EXE-65F6206D.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\inetres.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\CONTROL.EXE-9459D5A0.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\CSC.EXE-6F2C7122.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\CVTRES.EXE-6280F3A8.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\DEFRAG.EXE-738093E8.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\DFRGUI.EXE-E344E070.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\InkWatson.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmbr002.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\InputPersonalization.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\DLLHOST.EXE-10C3CA32.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\DLLHOST.EXE-7D2183B8.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmbr005.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmbr006.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\LanmanServer.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\LeakDiagnostic.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\DLLHOST.EXE-AAD0E997.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\DLLHOST.EXE-C5C55E89.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\DLLHOST.EXE-EF479C03.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmbr007.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmbr008.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\DLLHOST.EXE-FF915DF9.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\DRVINST.EXE-5F8E77CD.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\EN_OFFICE_PROFESSIONAL_PLUS_2-E7418694.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\ariblk.ttf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmbr00a.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmbsb.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmbtmdm.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\Logon.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\MediaCenter.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\MMC.admx.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\ARLRDBD.TTF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Fonts\BASKVILL.TTF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmbug3.PNF.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\EXCEL.EXE-F0766CF1.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\Prefetch\EXPLORER.EXE-7A3328DA.pf.pandemic | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\inf\mdmc26a.PNF.pandemic | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Windows\Prefetch\FLASHPLAYERUPDATESERVICE.EXE-41B177B8.pf.pandemic | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Windows\Prefetch\FLOWER_IT_NAMED.EXE-B7871171.pf.pandemic | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\MobilePCMobilityCenter.admx.pandemic | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Windows\PolicyDefinitions\MobilePCPresentationSettings.admx.pandemic | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Windows\Prefetch\IEXPLORE.EXE-1B894AFB.pf.pandemic | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Windows\Prefetch\IEXPLORE.EXE-F6A52C86.pf.pandemic | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Windows\Prefetch\INSTALLFLASHPLAYER.EXE-D17794CE.pf.pandemic | Dropped File | Unknown |
Not Queried
|
...
|
»