Dynamic Analysis Report |
Classification: Dropper, Riskware, Downloader, Trojan, Ransomware |
46c8e192bb6e37452c1b8029987a7c05f64b7766ff692731b050c402d91baa93 (SHA256)
update.exe
Created at 2018-11-19 13:55:00
Notifications (2/5)
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
The overall sleep time of all monitored processes was truncated from "3 minutes" to "10 seconds" to reveal dormant functionality.
The operating system was rebooted during the analysis.
Remarks
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
This list contains only the embedded files and created files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\update.exe | Sample File | Binary |
Blacklisted
|
...
|
Severity |
Blacklisted
|
First Seen | 2018-11-17 18:34 (UTC+1) |
Last Seen | 2018-11-19 11:45 (UTC+1) |
Names | Win32.Trojan.Gandcrab |
Families | Gandcrab |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x40475e |
Size Of Code | 0x1c000 |
Size Of Initialized Data | 0x7b600 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2018-05-21 06:30:02+00:00 |
LegalCopyright | Copyright (C) 2018, aeyezsgisza |
InternalName | asdgeprg |
FileVersion | 1.0.0.1 |
ProductVersion | 1.0.0.1 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1bf68 | 0x1c000 | 0x400 | cnt_code, mem_execute, mem_read | 6.61 |
.data | 0x41d000 | 0x73b50 | 0x4ba00 | 0x1c400 | cnt_initialized_data, mem_read, mem_write | 5.2 |
.rsrc | 0x491000 | 0x7108 | 0x7200 | 0x67e00 | cnt_initialized_data, mem_read | 5.11 |
.reloc | 0x499000 | 0x1564 | 0x1600 | 0x6f000 | cnt_initialized_data, mem_discardable, mem_read | 5.65 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCurrentDirectoryW | 0x0 | 0x401008 | 0x1c550 | 0x1b950 | 0x1a8 |
FindFirstChangeNotificationA | 0x0 | 0x40100c | 0x1c554 | 0x1b954 | 0x11b |
AddAtomA | 0x0 | 0x401010 | 0x1c558 | 0x1b958 | 0x3 |
EnumTimeFormatsA | 0x0 | 0x401014 | 0x1c55c | 0x1b95c | 0xfb |
FindAtomA | 0x0 | 0x401018 | 0x1c560 | 0x1b960 | 0x117 |
CloseHandle | 0x0 | 0x40101c | 0x1c564 | 0x1b964 | 0x43 |
ExitProcess | 0x0 | 0x401020 | 0x1c568 | 0x1b968 | 0x104 |
GetTickCount | 0x0 | 0x401024 | 0x1c56c | 0x1b96c | 0x266 |
GetSystemTime | 0x0 | 0x401028 | 0x1c570 | 0x1b970 | 0x24d |
GetModuleHandleW | 0x0 | 0x40102c | 0x1c574 | 0x1b974 | 0x1f9 |
GetCommProperties | 0x0 | 0x401030 | 0x1c578 | 0x1b978 | 0x16c |
GetThreadSelectorEntry | 0x0 | 0x401034 | 0x1c57c | 0x1b97c | 0x263 |
GetCPInfo | 0x0 | 0x401038 | 0x1c580 | 0x1b980 | 0x15b |
GetSystemTimeAdjustment | 0x0 | 0x40103c | 0x1c584 | 0x1b984 | 0x24e |
GetProcAddress | 0x0 | 0x401040 | 0x1c588 | 0x1b988 | 0x220 |
GetLastError | 0x0 | 0x401044 | 0x1c58c | 0x1b98c | 0x1e6 |
GlobalAlloc | 0x0 | 0x401048 | 0x1c590 | 0x1b990 | 0x285 |
FatalExit | 0x0 | 0x40104c | 0x1c594 | 0x1b994 | 0x10d |
SetLastError | 0x0 | 0x401050 | 0x1c598 | 0x1b998 | 0x3ec |
CompareStringW | 0x0 | 0x401054 | 0x1c59c | 0x1b99c | 0x55 |
CompareStringA | 0x0 | 0x401058 | 0x1c5a0 | 0x1b9a0 | 0x52 |
GetLocaleInfoW | 0x0 | 0x40105c | 0x1c5a4 | 0x1b9a4 | 0x1ea |
HeapSize | 0x0 | 0x401060 | 0x1c5a8 | 0x1b9a8 | 0x2a6 |
GetProcessHeap | 0x0 | 0x401064 | 0x1c5ac | 0x1b9ac | 0x223 |
SetEndOfFile | 0x0 | 0x401068 | 0x1c5b0 | 0x1b9b0 | 0x3cd |
FlushFileBuffers | 0x0 | 0x40106c | 0x1c5b4 | 0x1b9b4 | 0x141 |
WriteConsoleW | 0x0 | 0x401070 | 0x1c5b8 | 0x1b9b8 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x401074 | 0x1c5bc | 0x1b9bc | 0x199 |
WriteConsoleA | 0x0 | 0x401078 | 0x1c5c0 | 0x1b9c0 | 0x482 |
GetTimeZoneInformation | 0x0 | 0x40107c | 0x1c5c4 | 0x1b9c4 | 0x26b |
LoadLibraryA | 0x0 | 0x401080 | 0x1c5c8 | 0x1b9c8 | 0x2f1 |
WriteConsoleOutputCharacterA | 0x0 | 0x401084 | 0x1c5cc | 0x1b9cc | 0x489 |
LocalFree | 0x0 | 0x401088 | 0x1c5d0 | 0x1b9d0 | 0x2fd |
InterlockedExchange | 0x0 | 0x40108c | 0x1c5d4 | 0x1b9d4 | 0x2bd |
FreeLibrary | 0x0 | 0x401090 | 0x1c5d8 | 0x1b9d8 | 0x14c |
GetCommandLineA | 0x0 | 0x401094 | 0x1c5dc | 0x1b9dc | 0x16f |
GetStartupInfoA | 0x0 | 0x401098 | 0x1c5e0 | 0x1b9e0 | 0x239 |
TerminateProcess | 0x0 | 0x40109c | 0x1c5e4 | 0x1b9e4 | 0x42d |
GetCurrentProcess | 0x0 | 0x4010a0 | 0x1c5e8 | 0x1b9e8 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x4010a4 | 0x1c5ec | 0x1b9ec | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x4010a8 | 0x1c5f0 | 0x1b9f0 | 0x415 |
IsDebuggerPresent | 0x0 | 0x4010ac | 0x1c5f4 | 0x1b9f4 | 0x2d1 |
HeapFree | 0x0 | 0x4010b0 | 0x1c5f8 | 0x1b9f8 | 0x2a1 |
InterlockedIncrement | 0x0 | 0x4010b4 | 0x1c5fc | 0x1b9fc | 0x2c0 |
InterlockedDecrement | 0x0 | 0x4010b8 | 0x1c600 | 0x1ba00 | 0x2bc |
GetACP | 0x0 | 0x4010bc | 0x1c604 | 0x1ba04 | 0x152 |
GetOEMCP | 0x0 | 0x4010c0 | 0x1c608 | 0x1ba08 | 0x213 |
IsValidCodePage | 0x0 | 0x4010c4 | 0x1c60c | 0x1ba0c | 0x2db |
TlsGetValue | 0x0 | 0x4010c8 | 0x1c610 | 0x1ba10 | 0x434 |
TlsAlloc | 0x0 | 0x4010cc | 0x1c614 | 0x1ba14 | 0x432 |
TlsSetValue | 0x0 | 0x4010d0 | 0x1c618 | 0x1ba18 | 0x435 |
TlsFree | 0x0 | 0x4010d4 | 0x1c61c | 0x1ba1c | 0x433 |
GetCurrentThreadId | 0x0 | 0x4010d8 | 0x1c620 | 0x1ba20 | 0x1ad |
GetCurrentThread | 0x0 | 0x4010dc | 0x1c624 | 0x1ba24 | 0x1ac |
HeapAlloc | 0x0 | 0x4010e0 | 0x1c628 | 0x1ba28 | 0x29d |
EnterCriticalSection | 0x0 | 0x4010e4 | 0x1c62c | 0x1ba2c | 0xd9 |
LeaveCriticalSection | 0x0 | 0x4010e8 | 0x1c630 | 0x1ba30 | 0x2ef |
SetHandleCount | 0x0 | 0x4010ec | 0x1c634 | 0x1ba34 | 0x3e8 |
GetStdHandle | 0x0 | 0x4010f0 | 0x1c638 | 0x1ba38 | 0x23b |
GetFileType | 0x0 | 0x4010f4 | 0x1c63c | 0x1ba3c | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x4010f8 | 0x1c640 | 0x1ba40 | 0xbe |
MultiByteToWideChar | 0x0 | 0x4010fc | 0x1c644 | 0x1ba44 | 0x31a |
ReadFile | 0x0 | 0x401100 | 0x1c648 | 0x1ba48 | 0x368 |
RtlUnwind | 0x0 | 0x401104 | 0x1c64c | 0x1ba4c | 0x392 |
Sleep | 0x0 | 0x401108 | 0x1c650 | 0x1ba50 | 0x421 |
WriteFile | 0x0 | 0x40110c | 0x1c654 | 0x1ba54 | 0x48d |
GetModuleFileNameA | 0x0 | 0x401110 | 0x1c658 | 0x1ba58 | 0x1f4 |
FreeEnvironmentStringsA | 0x0 | 0x401114 | 0x1c65c | 0x1ba5c | 0x14a |
GetEnvironmentStrings | 0x0 | 0x401118 | 0x1c660 | 0x1ba60 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x40111c | 0x1c664 | 0x1ba64 | 0x14b |
WideCharToMultiByte | 0x0 | 0x401120 | 0x1c668 | 0x1ba68 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x401124 | 0x1c66c | 0x1ba6c | 0x1c1 |
HeapCreate | 0x0 | 0x401128 | 0x1c670 | 0x1ba70 | 0x29f |
HeapDestroy | 0x0 | 0x40112c | 0x1c674 | 0x1ba74 | 0x2a0 |
VirtualFree | 0x0 | 0x401130 | 0x1c678 | 0x1ba78 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x401134 | 0x1c67c | 0x1ba7c | 0x354 |
GetCurrentProcessId | 0x0 | 0x401138 | 0x1c680 | 0x1ba80 | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x40113c | 0x1c684 | 0x1ba84 | 0x24f |
FatalAppExitA | 0x0 | 0x401140 | 0x1c688 | 0x1ba88 | 0x10b |
VirtualAlloc | 0x0 | 0x401144 | 0x1c68c | 0x1ba8c | 0x454 |
HeapReAlloc | 0x0 | 0x401148 | 0x1c690 | 0x1ba90 | 0x2a4 |
LCMapStringA | 0x0 | 0x40114c | 0x1c694 | 0x1ba94 | 0x2e1 |
LCMapStringW | 0x0 | 0x401150 | 0x1c698 | 0x1ba98 | 0x2e3 |
GetStringTypeA | 0x0 | 0x401154 | 0x1c69c | 0x1ba9c | 0x23d |
GetStringTypeW | 0x0 | 0x401158 | 0x1c6a0 | 0x1baa0 | 0x240 |
GetTimeFormatA | 0x0 | 0x40115c | 0x1c6a4 | 0x1baa4 | 0x268 |
GetDateFormatA | 0x0 | 0x401160 | 0x1c6a8 | 0x1baa8 | 0x1ae |
GetUserDefaultLCID | 0x0 | 0x401164 | 0x1c6ac | 0x1baac | 0x26d |
GetLocaleInfoA | 0x0 | 0x401168 | 0x1c6b0 | 0x1bab0 | 0x1e8 |
EnumSystemLocalesA | 0x0 | 0x40116c | 0x1c6b4 | 0x1bab4 | 0xf8 |
IsValidLocale | 0x0 | 0x401170 | 0x1c6b8 | 0x1bab8 | 0x2dd |
SetFilePointer | 0x0 | 0x401174 | 0x1c6bc | 0x1babc | 0x3df |
GetConsoleCP | 0x0 | 0x401178 | 0x1c6c0 | 0x1bac0 | 0x183 |
GetConsoleMode | 0x0 | 0x40117c | 0x1c6c4 | 0x1bac4 | 0x195 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x401180 | 0x1c6c8 | 0x1bac8 | 0x2b5 |
SetStdHandle | 0x0 | 0x401184 | 0x1c6cc | 0x1bacc | 0x3fc |
CreateFileA | 0x0 | 0x401188 | 0x1c6d0 | 0x1bad0 | 0x78 |
SetConsoleCtrlHandler | 0x0 | 0x40118c | 0x1c6d4 | 0x1bad4 | 0x3a7 |
SetEnvironmentVariableA | 0x0 | 0x401190 | 0x1c6d8 | 0x1bad8 | 0x3d0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PeekMessageA | 0x0 | 0x4011a0 | 0x1c6e8 | 0x1bae8 | 0x21b |
GetRawInputDeviceInfoA | 0x0 | 0x4011a4 | 0x1c6ec | 0x1baec | 0x160 |
ScrollWindowEx | 0x0 | 0x4011a8 | 0x1c6f0 | 0x1baf0 | 0x258 |
UpdateWindow | 0x0 | 0x4011ac | 0x1c6f4 | 0x1baf4 | 0x2e9 |
LoadIconW | 0x0 | 0x4011b0 | 0x1c6f8 | 0x1baf8 | 0x1d7 |
GetNextDlgTabItem | 0x0 | 0x4011b4 | 0x1c6fc | 0x1bafc | 0x153 |
GetMonitorInfoW | 0x0 | 0x4011b8 | 0x1c700 | 0x1bb00 | 0x150 |
BeginPaint | 0x0 | 0x4011bc | 0x1c704 | 0x1bb04 | 0xe |
GetParent | 0x0 | 0x4011c0 | 0x1c708 | 0x1bb08 | 0x155 |
SetThreadDesktop | 0x0 | 0x4011c4 | 0x1c70c | 0x1bb0c | 0x29d |
LookupIconIdFromDirectory | 0x0 | 0x4011c8 | 0x1c710 | 0x1bb10 | 0x1ea |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ReportEventW | 0x0 | 0x401000 | 0x1c548 | 0x1b948 | 0x289 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TransparentBlt | 0x0 | 0x401198 | 0x1c6e0 | 0x1bae0 | 0x3 |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\desktop.ini | Modified File | Stream |
Unknown
|
...
|
C:\Users\All Users\Microsoft\Network\Downloader\qmgr0.dat.INFOWAIT | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Stream |
Unknown
|
...
|
C:\ProgramData\Microsoft Help\MS.GRAPH.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\desktop.ini | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\nvyg\U0AZd0ivGrf _Re 2c.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\hT-SqtZX\c4-yyhR.ods | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\l8fJ\YeV-uPfMbHLLcGMe_f.odt | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rXoVxt3oiS\O5g4jLerSHDy3Pf8Z8r\2qDES9yWeof3.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\skaVx\EoZDJddZ6evy.pptx | Modified File | Stream |
Unknown
|
...
|
C:\ProgramData\Microsoft Help\MS.OUTLOOK.DEV.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\4fONS\zDJHX2UBtq2jNGLqtNRG.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\I_5X.xlsx | Modified File | Stream |
Unknown
|
...
|
C:\ProgramData\Adobe\ARM\Reader_10.0.0\AdbeRdrUpd10116_MUI.msp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\hT-SqtZX\U9tSiBmpae-S.ppt | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Saved Games\desktop.ini | Modified File | Stream |
Unknown
|
...
|
C:\ProgramData\Adobe\ARM\Reader_10.0.0\AdbeRdrSecUpd10111.msp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\ubh3Kx_A\_NTc8TO6LpPJ5zXjg.gif | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.INFOPATH.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\Dkb64er\r7-FdG2eJ6-ET_j.doc | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\n7JpqV\ZEsdNS.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\Dkb64er\hs9eu0cg_VHy7\shTUZEa.ppt | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.SETLANG.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.MSOUC.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\QaUjhe\8q988doXb.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\fpsQYKF MOi0MA.flv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Searches\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\n7JpqV\8ctUF06 2SC36xX7cR0\luqHM\l7-qaXxV0q.gif | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\Dkb64er\hs9eu0cg_VHy7\d8R9rMlCN.odp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\36USA68T\imagesrv.adition[1].xml | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Links\Downloads.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\FLEcvhR.xls | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\nvyg\5Lx3KHr.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.POWERPNT.DEV.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\skaVx\4xdI4OMOFBx3cqRfxwA0.xlsx | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.WINWORD.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.Lck.INFOWAIT | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\BflhCY_h.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.OUTLOOK.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\xsTHwcnuDqWQ9Jfwv\5NOeuuWGic W5vSvZ.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.H1D.INFOWAIT | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\rsqxo_hm.pptx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\86iUKOznOtmWr4FTVK.xlsx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\xsTHwcnuDqWQ9Jfwv\RCe6gFP9n8QcDK.gif | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\SNwh\2L5Mp4CJ.ods | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rXoVxt3oiS\O5g4jLerSHDy3Pf8Z8r\wlnli51d9s.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rXoVxt3oiS\CZRVI9TRu5syJMCnyOV.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\qRUUXSSNmlOJdjR 6U.flv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\r0_POyzPZT.pptx | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.GROOVE.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\4fONS\XRQKbLhwuLoes9nMF eV.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\unlt.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\_ERMKi.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rXoVxt3oiS\O5g4jLerSHDy3Pf8Z8r\P-MyT-xFsgCgO.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help{9DAA54E8-CD95-4107-8E7F-BA3F24732D95}.H1Q.INFOWAIT | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\Dkb64er\Kgbiq-5bFu_gdXcNS.csv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yvz8Ck.xls | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\q93T.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\O89VrUgck0WGUK_Y\g1B3M3.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\VmQaguirc.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\nvyg\pkWtVne.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\Dkb64er\hs9eu0cg_VHy7\pplpY8py2zNIuuEmOh7.pptx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\QVNDMBKO6iJXOO2h3\xjB5_nJ6.flv | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.INFOPATHEDITOR.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ztTnKYuZ\wKKlBy5ZmIsI.flv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\ubh3Kx_A\rtYIqoqrRvq.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.MSPUB.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\n7JpqV\8ctUF06 2SC36xX7cR0\FN7 jccu.png | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.VISIO.SHAPESHEET.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.WINPROJ.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.WINWORD.DEV.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\fWq7Sf.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Hy6vDgJFghnTAj77.xlsx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\-bVmT_XCtJmzFCE.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\hT-SqtZX\obgiME5jO2.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\QaUjhe\B-lTUwZlpVSP7x8c.gif | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\-3gHp4i8DBQd4Fi.pptx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\n7JpqV\cc0AC KvAZVVI8uX.gif | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\GkFwBZ26Jl.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\QVNDMBKO6iJXOO2h3\kuUk4.swf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.msi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\YzRpjUWu6VDm3TLDV.pptx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\skaVx\aI-hq-hLGIh9RDS.xls | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\CrDx78k.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\v7CbnDwOOLwRsSR.xlsx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\laJ7 XG6mvY9a4Oq.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\QVNDMBKO6iJXOO2h3\LcNIbb5Xdpy1cT0Voq.flv | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Adobe\ARM\Reader_10.0.0\AdbeRdrUpd10110_MUI.msp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\n7JpqV\8ctUF06 2SC36xX7cR0\4DWhN6RhpgdCQKemK.gif | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\ni0Jgy12uVbTOlRR.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Links\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\y1mkaun.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\jre1.7.0_45.msi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\SNwh\3-Cn.ods | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ztTnKYuZ\f 1Medb.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rXoVxt3oiS\O5g4jLerSHDy3Pf8Z8r\_Xt1XKuQQyohA.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\kDhx0.ods | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Mozilla\logs\maintenanceservice-install.log | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\Dkb64er\hs9eu0cg_VHy7\FIhr5H47kz.pptx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\QaUjhe\7FDM.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\OaJupVjMV.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.EXCEL.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\rRaXTMp.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\POzUPkpR60DTM.xlsx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\VGMTOI09\www.msn[1].xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\4fONS\8E9H31N.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Microsoft\OFFICE\MySite.ico.INFOWAIT | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\O89VrUgck0WGUK_Y\Hz-AF2m p5AxcZJOR.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ztTnKYuZ\JAPSpnBZPTk8W3utGB.flv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\mF_q7P7.swf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_AssetId.H1W.INFOWAIT | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\4fONS\kJFrd7NImQEQs.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rXoVxt3oiS\M3mvj.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\8oeI6XU5 vjIz.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\n7JpqV\IEv7z27qsVTekHpr.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\hT-SqtZX\tkO6bl.odp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\4fONS\0XQBmq5ckaU.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.POWERPNT.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.cab | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rXoVxt3oiS\O5g4jLerSHDy3Pf8Z8r\ya4k9CP4ga90mFZW.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ztTnKYuZ\SXoi3O7UHlm4-KqaOQbg.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\n7JpqV\8ctUF06 2SC36xX7cR0\luqHM\IMEhPArBi5zDx-qN3xQn.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\xsTHwcnuDqWQ9Jfwv\u8Rrvn5zJ.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\H2j6tPl2-Uy7a_CTb.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\QaUjhe\rGw15KQUy_H3LYwN5\8B9CArYYR-k5_6.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rXoVxt3oiS\O5g4jLerSHDy3Pf8Z8r\U eCzQsa89w8ys.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.VISIO_PRM.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Microsoft\Network\Downloader\qmgr1.dat.INFOWAIT | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\-x3FnD.avi | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.WINPROJ.DEV.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.OIS.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\Ukc9zVsmz.xlsx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\4fONS\NBd6m3qs3.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\QaUjhe\rGw15KQUy_H3LYwN5\4haF6sPbyW_.gif | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.VISIO_STD.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\y1w5ZZtxeCJCqVDGm8rd.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\QVNDMBKO6iJXOO2h3\5EP3zi8p1_ R.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Sun\Java\Java Update\jaureglist.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\YfljSHP679zr.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\4fONS\b ZEoraAV.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\O89VrUgck0WGUK_Y\Hq-306b65BqrHoqbR9.swf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\l8fJ\p2jEbzbiEY.odp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\QaUjhe\rGw15KQUy_H3LYwN5\k-DDYba4e9vKH.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact | Modified File | Stream |
Not Queried
|
...
|
C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\Dkb64er\hs9eu0cg_VHy7\FiwjPlFCBQK4Eudei\S6KMJ lP85NJg.ppt | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\3w7z.flv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\Dkb64er\C0QT-PiM3F.pps | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\Deployment\deployment.properties | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\QVNDMBKO6iJXOO2h3\6R9e9hJWmT-aPrPe.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Microsoft\OFFICE\MySharePoints.ico.INFOWAIT | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\frr7vMqqzTzgf.pptx | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.MSPUB.DEV.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MTOC_help.H1H.INFOWAIT | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LB1Vquw6 amP SWGL3zs.flv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\6G5yHmu-I-1.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\QaUjhe\rGw15KQUy_H3LYwN5\ni-jXUyMmKeOU4Zi2aIU.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rXoVxt3oiS\_PnpDAir3.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\nvyg\tEL2.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\skaVx\F0LyAv7a.xls | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.VISIO.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Links\RecentPlaces.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JfvP6S4i2D.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\hT-SqtZX\wLIFp9Xlr__Upjp5BWpB.xls | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\-Fn54ZOPOU2DZgY9Xjjc.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\QVNDMBKO6iJXOO2h3\l414QV7S1.swf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ztTnKYuZ\Tloxb4BEF.swf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\8HC y_m_mnm8.swf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\WBCuWSQzDcN3.xlsx | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\nslist.hxl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\32XcKJ-k MnUkqXRq.pptx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\Vynkb.flv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\4fONS\r7FR3hZryb5hq9Ud7NX.wav | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.ONENOTE.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\KCFGl8AGb.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\nJqpjpjhgkzg.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.EXCEL.DEV.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\Dkb64er\hs9eu0cg_VHy7\FiwjPlFCBQK4Eudei\4aIc13i42g6djkDS.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Au5gZJs3.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\A3o-tRWcczzg.png | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.MSACCESS.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\Dkb64er\pjRRywz moQN7y4K4.ots | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rXoVxt3oiS\O5g4jLerSHDy3Pf8Z8r\k7CM6LvXyF9LPZI6yh2.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rXoVxt3oiS\O5g4jLerSHDy3Pf8Z8r\GYnW7LZ.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Microsoft\OFFICE\AssetLibrary.ico.INFOWAIT | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.VISIO.DEV.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hjEoNe.swf | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.MSACCESS.DEV.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\O89VrUgck0WGUK_Y\8RjZdKR.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\4fONS\UrqJ.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rXoVxt3oiS\Lkq3 EjT.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Microsoft\OFFICE\DocumentRepository.ico.INFOWAIT | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\O89VrUgck0WGUK_Y\kpXaWD.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\gwCCr5SN1.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rXoVxt3oiS\O5g4jLerSHDy3Pf8Z8r\nxKQUQU2ESS.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Links\Desktop.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\n7JpqV\ZVtPiW.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\7UQS1.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\Dkb64er\hs9eu0cg_VHy7\6qkqye2rCRGlE5P.ppt | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\n7JpqV\EEWWiY3V3RdCY.gif | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Microsoft\IdentityCRL\ppcrlui.dll.INFOWAIT | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\baHs2DdbqE.swf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\yqgAGD0mq69zIZ\Dkb64er\hs9eu0cg_VHy7\MGAfBc25T.ots | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EXInUgGRa8IXEf\QVNDMBKO6iJXOO2h3\hCecQC2.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c30-G7I4Ib7Y-VxrTcg6\-l0TaG633wu CFDx3Y-.doc | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Downloads\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\nvyg\X8qNDeYP35alh231JX16.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1W.INFOWAIT | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\n7JpqV\8ctUF06 2SC36xX7cR0\luqHM\znFXRDcUkqphQAEI4ui.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\ProgramData\Microsoft Help\MS.MSTORE.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zu1 _on\QaUjhe\rGw15KQUy_H3LYwN5\2QiXDoa8V yuTWH7Q.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PSzsrL7.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\4fONS\Qj0Bxz9rAG9Fja0Mk.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Microsoft\MF\Active.GRL.INFOWAIT | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\w52qqQUsQntD6lz uu_3.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\script.ps1 | Created File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\544c4f6e-08e8-406f-ae98-d88505d8a2e3\update.exe | Created File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\ac0fced0-d42a-4728-a9f2-bdfd4590c238\1.exe | Created File | Binary |
Not Queried
|
...
|
Image Base | 0x400000 |
Entry Point | 0x4023f7 |
Size Of Code | 0xd400 |
Size Of Initialized Data | 0x20600 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2018-11-06 14:23:02+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xd2f5 | 0xd400 | 0x400 | cnt_code, mem_execute, mem_read | 6.61 |
.rdata | 0x40f000 | 0x6b32 | 0x6c00 | 0xd800 | cnt_initialized_data, mem_read | 4.79 |
.data | 0x416000 | 0x155c | 0xa00 | 0x14400 | cnt_initialized_data, mem_read, mem_write | 2.26 |
.rsrc | 0x418000 | 0x171e8 | 0x17200 | 0x14e00 | cnt_initialized_data, mem_read | 4.03 |
.reloc | 0x430000 | 0x1028 | 0x1200 | 0x2c000 | cnt_initialized_data, mem_discardable, mem_read | 6.2 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateFileA | 0x0 | 0x40f01c | 0x15358 | 0x13b58 | 0xc2 |
WriteFile | 0x0 | 0x40f020 | 0x1535c | 0x13b5c | 0x60a |
FlushFileBuffers | 0x0 | 0x40f024 | 0x15360 | 0x13b60 | 0x19d |
CloseHandle | 0x0 | 0x40f028 | 0x15364 | 0x13b64 | 0x86 |
CreateProcessA | 0x0 | 0x40f02c | 0x15368 | 0x13b68 | 0xdf |
lstrcpyW | 0x0 | 0x40f030 | 0x1536c | 0x13b6c | 0x62e |
CreateProcessW | 0x0 | 0x40f034 | 0x15370 | 0x13b70 | 0xe4 |
WaitForSingleObject | 0x0 | 0x40f038 | 0x15374 | 0x13b74 | 0x5cf |
CreateFileW | 0x0 | 0x40f03c | 0x15378 | 0x13b78 | 0xca |
lstrlenA | 0x0 | 0x40f040 | 0x1537c | 0x13b7c | 0x633 |
WideCharToMultiByte | 0x0 | 0x40f044 | 0x15380 | 0x13b80 | 0x5f6 |
MultiByteToWideChar | 0x0 | 0x40f048 | 0x15384 | 0x13b84 | 0x3e8 |
GetCommandLineW | 0x0 | 0x40f04c | 0x15388 | 0x13b88 | 0x1d5 |
WriteConsoleW | 0x0 | 0x40f050 | 0x1538c | 0x13b8c | 0x609 |
SetFilePointerEx | 0x0 | 0x40f054 | 0x15390 | 0x13b90 | 0x51b |
GetConsoleMode | 0x0 | 0x40f058 | 0x15394 | 0x13b94 | 0x1fa |
DeleteFileA | 0x0 | 0x40f05c | 0x15398 | 0x13b98 | 0x110 |
HeapReAlloc | 0x0 | 0x40f060 | 0x1539c | 0x13b9c | 0x348 |
HeapSize | 0x0 | 0x40f064 | 0x153a0 | 0x13ba0 | 0x34a |
GetProcessHeap | 0x0 | 0x40f068 | 0x153a4 | 0x13ba4 | 0x2b0 |
LCMapStringW | 0x0 | 0x40f06c | 0x153a8 | 0x13ba8 | 0x3ac |
GetStringTypeW | 0x0 | 0x40f070 | 0x153ac | 0x13bac | 0x2d3 |
GetFileType | 0x0 | 0x40f074 | 0x153b0 | 0x13bb0 | 0x24a |
SetStdHandle | 0x0 | 0x40f078 | 0x153b4 | 0x13bb4 | 0x542 |
lstrcatA | 0x0 | 0x40f07c | 0x153b8 | 0x13bb8 | 0x624 |
lstrcpyA | 0x0 | 0x40f080 | 0x153bc | 0x13bbc | 0x62d |
GetEnvironmentVariableA | 0x0 | 0x40f084 | 0x153c0 | 0x13bc0 | 0x234 |
GetShortPathNameA | 0x0 | 0x40f088 | 0x153c4 | 0x13bc4 | 0x2c8 |
GetModuleFileNameA | 0x0 | 0x40f08c | 0x153c8 | 0x13bc8 | 0x26f |
GetConsoleCP | 0x0 | 0x40f090 | 0x153cc | 0x13bcc | 0x1e8 |
SetLastError | 0x0 | 0x40f094 | 0x153d0 | 0x13bd0 | 0x52a |
FreeEnvironmentStringsW | 0x0 | 0x40f098 | 0x153d4 | 0x13bd4 | 0x1a8 |
GetEnvironmentStringsW | 0x0 | 0x40f09c | 0x153d8 | 0x13bd8 | 0x233 |
GetCommandLineA | 0x0 | 0x40f0a0 | 0x153dc | 0x13bdc | 0x1d4 |
GetCPInfo | 0x0 | 0x40f0a4 | 0x153e0 | 0x13be0 | 0x1bf |
GetOEMCP | 0x0 | 0x40f0a8 | 0x153e4 | 0x13be4 | 0x293 |
IsValidCodePage | 0x0 | 0x40f0ac | 0x153e8 | 0x13be8 | 0x386 |
UnhandledExceptionFilter | 0x0 | 0x40f0b0 | 0x153ec | 0x13bec | 0x5a5 |
SetUnhandledExceptionFilter | 0x0 | 0x40f0b4 | 0x153f0 | 0x13bf0 | 0x565 |
GetCurrentProcess | 0x0 | 0x40f0b8 | 0x153f4 | 0x13bf4 | 0x215 |
TerminateProcess | 0x0 | 0x40f0bc | 0x153f8 | 0x13bf8 | 0x584 |
IsProcessorFeaturePresent | 0x0 | 0x40f0c0 | 0x153fc | 0x13bfc | 0x381 |
QueryPerformanceCounter | 0x0 | 0x40f0c4 | 0x15400 | 0x13c00 | 0x446 |
GetCurrentProcessId | 0x0 | 0x40f0c8 | 0x15404 | 0x13c04 | 0x216 |
GetCurrentThreadId | 0x0 | 0x40f0cc | 0x15408 | 0x13c08 | 0x21a |
GetSystemTimeAsFileTime | 0x0 | 0x40f0d0 | 0x1540c | 0x13c0c | 0x2e5 |
InitializeSListHead | 0x0 | 0x40f0d4 | 0x15410 | 0x13c10 | 0x35e |
IsDebuggerPresent | 0x0 | 0x40f0d8 | 0x15414 | 0x13c14 | 0x37a |
GetStartupInfoW | 0x0 | 0x40f0dc | 0x15418 | 0x13c18 | 0x2cc |
GetModuleHandleW | 0x0 | 0x40f0e0 | 0x1541c | 0x13c1c | 0x274 |
RtlUnwind | 0x0 | 0x40f0e4 | 0x15420 | 0x13c20 | 0x4cb |
RaiseException | 0x0 | 0x40f0e8 | 0x15424 | 0x13c24 | 0x45b |
GetLastError | 0x0 | 0x40f0ec | 0x15428 | 0x13c28 | 0x25d |
EncodePointer | 0x0 | 0x40f0f0 | 0x1542c | 0x13c2c | 0x12b |
EnterCriticalSection | 0x0 | 0x40f0f4 | 0x15430 | 0x13c30 | 0x12f |
LeaveCriticalSection | 0x0 | 0x40f0f8 | 0x15434 | 0x13c34 | 0x3b8 |
DeleteCriticalSection | 0x0 | 0x40f0fc | 0x15438 | 0x13c38 | 0x10e |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40f100 | 0x1543c | 0x13c3c | 0x35a |
TlsAlloc | 0x0 | 0x40f104 | 0x15440 | 0x13c40 | 0x596 |
TlsGetValue | 0x0 | 0x40f108 | 0x15444 | 0x13c44 | 0x598 |
TlsSetValue | 0x0 | 0x40f10c | 0x15448 | 0x13c48 | 0x599 |
TlsFree | 0x0 | 0x40f110 | 0x1544c | 0x13c4c | 0x597 |
FreeLibrary | 0x0 | 0x40f114 | 0x15450 | 0x13c50 | 0x1a9 |
GetProcAddress | 0x0 | 0x40f118 | 0x15454 | 0x13c54 | 0x2aa |
LoadLibraryExW | 0x0 | 0x40f11c | 0x15458 | 0x13c58 | 0x3be |
GetStdHandle | 0x0 | 0x40f120 | 0x1545c | 0x13c5c | 0x2ce |
GetModuleFileNameW | 0x0 | 0x40f124 | 0x15460 | 0x13c60 | 0x270 |
ExitProcess | 0x0 | 0x40f128 | 0x15464 | 0x13c64 | 0x15c |
GetModuleHandleExW | 0x0 | 0x40f12c | 0x15468 | 0x13c68 | 0x273 |
GetACP | 0x0 | 0x40f130 | 0x1546c | 0x13c6c | 0x1b0 |
HeapAlloc | 0x0 | 0x40f134 | 0x15470 | 0x13c70 | 0x341 |
HeapFree | 0x0 | 0x40f138 | 0x15474 | 0x13c74 | 0x345 |
FindClose | 0x0 | 0x40f13c | 0x15478 | 0x13c78 | 0x173 |
FindFirstFileExW | 0x0 | 0x40f140 | 0x1547c | 0x13c7c | 0x179 |
FindNextFileW | 0x0 | 0x40f144 | 0x15480 | 0x13c80 | 0x18a |
DecodePointer | 0x0 | 0x40f148 | 0x15484 | 0x13c84 | 0x107 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyExW | 0x0 | 0x40f000 | 0x1533c | 0x13b3c | 0x28c |
RegCloseKey | 0x0 | 0x40f004 | 0x15340 | 0x13b40 | 0x25b |
RegCreateKeyExW | 0x0 | 0x40f008 | 0x15344 | 0x13b44 | 0x264 |
SetSecurityDescriptorDacl | 0x0 | 0x40f00c | 0x15348 | 0x13b48 | 0x2e8 |
InitializeSecurityDescriptor | 0x0 | 0x40f010 | 0x1534c | 0x13b4c | 0x18f |
RegSetValueExW | 0x0 | 0x40f014 | 0x15350 | 0x13b50 | 0x2a9 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteExW | 0x0 | 0x40f150 | 0x1548c | 0x13c8c | 0x1b7 |
SHGetFolderPathW | 0x0 | 0x40f154 | 0x15490 | 0x13c90 | 0x159 |
CommandLineToArgvW | 0x0 | 0x40f158 | 0x15494 | 0x13c94 | 0x7 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathAppendW | 0x0 | 0x40f160 | 0x1549c | 0x13c9c | 0x37 |
PathFileExistsA | 0x0 | 0x40f164 | 0x154a0 | 0x13ca0 | 0x47 |
PathRemoveFileSpecW | 0x0 | 0x40f168 | 0x154a4 | 0x13ca4 | 0x8f |
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\ac0fced0-d42a-4728-a9f2-bdfd4590c238\updatewin.exe | Created File | Binary |
Not Queried
|
...
|
Image Base | 0x400000 |
Entry Point | 0x401a9b |
Size Of Code | 0xb400 |
Size Of Initialized Data | 0x15600 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2018-11-07 15:49:36+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xb357 | 0xb400 | 0x400 | cnt_code, mem_execute, mem_read | 6.63 |
.rdata | 0x40d000 | 0x5f30 | 0x6000 | 0xb800 | cnt_initialized_data, mem_read | 4.9 |
.data | 0x413000 | 0x1458 | 0x800 | 0x11800 | cnt_initialized_data, mem_read, mem_write | 2.0 |
.rsrc | 0x415000 | 0xcfb0 | 0xd000 | 0x12000 | cnt_initialized_data, mem_read | 5.07 |
.reloc | 0x422000 | 0xeec | 0x1000 | 0x1f000 | cnt_initialized_data, mem_discardable, mem_read | 6.36 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FlushFileBuffers | 0x0 | 0x40d028 | 0x12624 | 0x10e24 | 0x19d |
HeapReAlloc | 0x0 | 0x40d02c | 0x12628 | 0x10e28 | 0x348 |
HeapSize | 0x0 | 0x40d030 | 0x1262c | 0x10e2c | 0x34a |
GetProcessHeap | 0x0 | 0x40d034 | 0x12630 | 0x10e30 | 0x2b0 |
LCMapStringW | 0x0 | 0x40d038 | 0x12634 | 0x10e34 | 0x3ac |
GetConsoleCP | 0x0 | 0x40d03c | 0x12638 | 0x10e38 | 0x1e8 |
GetStringTypeW | 0x0 | 0x40d040 | 0x1263c | 0x10e3c | 0x2d3 |
GetFileType | 0x0 | 0x40d044 | 0x12640 | 0x10e40 | 0x24a |
SetStdHandle | 0x0 | 0x40d048 | 0x12644 | 0x10e44 | 0x542 |
FreeEnvironmentStringsW | 0x0 | 0x40d04c | 0x12648 | 0x10e48 | 0x1a8 |
GetEnvironmentStringsW | 0x0 | 0x40d050 | 0x1264c | 0x10e4c | 0x233 |
GetCommandLineW | 0x0 | 0x40d054 | 0x12650 | 0x10e50 | 0x1d5 |
GetCommandLineA | 0x0 | 0x40d058 | 0x12654 | 0x10e54 | 0x1d4 |
GetCPInfo | 0x0 | 0x40d05c | 0x12658 | 0x10e58 | 0x1bf |
GetOEMCP | 0x0 | 0x40d060 | 0x1265c | 0x10e5c | 0x293 |
IsValidCodePage | 0x0 | 0x40d064 | 0x12660 | 0x10e60 | 0x386 |
GetConsoleMode | 0x0 | 0x40d068 | 0x12664 | 0x10e64 | 0x1fa |
SetFilePointerEx | 0x0 | 0x40d06c | 0x12668 | 0x10e68 | 0x51b |
CreateFileW | 0x0 | 0x40d070 | 0x1266c | 0x10e6c | 0xca |
CloseHandle | 0x0 | 0x40d074 | 0x12670 | 0x10e70 | 0x86 |
WriteConsoleW | 0x0 | 0x40d078 | 0x12674 | 0x10e74 | 0x609 |
Sleep | 0x0 | 0x40d07c | 0x12678 | 0x10e78 | 0x575 |
lstrlenW | 0x0 | 0x40d080 | 0x1267c | 0x10e7c | 0x634 |
GetLastError | 0x0 | 0x40d084 | 0x12680 | 0x10e80 | 0x25d |
CreateThread | 0x0 | 0x40d088 | 0x12684 | 0x10e84 | 0xf1 |
FindNextFileW | 0x0 | 0x40d08c | 0x12688 | 0x10e88 | 0x18a |
UnhandledExceptionFilter | 0x0 | 0x40d090 | 0x1268c | 0x10e8c | 0x5a5 |
SetUnhandledExceptionFilter | 0x0 | 0x40d094 | 0x12690 | 0x10e90 | 0x565 |
GetCurrentProcess | 0x0 | 0x40d098 | 0x12694 | 0x10e94 | 0x215 |
TerminateProcess | 0x0 | 0x40d09c | 0x12698 | 0x10e98 | 0x584 |
IsProcessorFeaturePresent | 0x0 | 0x40d0a0 | 0x1269c | 0x10e9c | 0x381 |
QueryPerformanceCounter | 0x0 | 0x40d0a4 | 0x126a0 | 0x10ea0 | 0x446 |
GetCurrentProcessId | 0x0 | 0x40d0a8 | 0x126a4 | 0x10ea4 | 0x216 |
GetCurrentThreadId | 0x0 | 0x40d0ac | 0x126a8 | 0x10ea8 | 0x21a |
GetSystemTimeAsFileTime | 0x0 | 0x40d0b0 | 0x126ac | 0x10eac | 0x2e5 |
InitializeSListHead | 0x0 | 0x40d0b4 | 0x126b0 | 0x10eb0 | 0x35e |
IsDebuggerPresent | 0x0 | 0x40d0b8 | 0x126b4 | 0x10eb4 | 0x37a |
GetStartupInfoW | 0x0 | 0x40d0bc | 0x126b8 | 0x10eb8 | 0x2cc |
GetModuleHandleW | 0x0 | 0x40d0c0 | 0x126bc | 0x10ebc | 0x274 |
RtlUnwind | 0x0 | 0x40d0c4 | 0x126c0 | 0x10ec0 | 0x4cb |
SetLastError | 0x0 | 0x40d0c8 | 0x126c4 | 0x10ec4 | 0x52a |
EnterCriticalSection | 0x0 | 0x40d0cc | 0x126c8 | 0x10ec8 | 0x12f |
LeaveCriticalSection | 0x0 | 0x40d0d0 | 0x126cc | 0x10ecc | 0x3b8 |
DeleteCriticalSection | 0x0 | 0x40d0d4 | 0x126d0 | 0x10ed0 | 0x10e |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40d0d8 | 0x126d4 | 0x10ed4 | 0x35a |
TlsAlloc | 0x0 | 0x40d0dc | 0x126d8 | 0x10ed8 | 0x596 |
TlsGetValue | 0x0 | 0x40d0e0 | 0x126dc | 0x10edc | 0x598 |
TlsSetValue | 0x0 | 0x40d0e4 | 0x126e0 | 0x10ee0 | 0x599 |
TlsFree | 0x0 | 0x40d0e8 | 0x126e4 | 0x10ee4 | 0x597 |
FreeLibrary | 0x0 | 0x40d0ec | 0x126e8 | 0x10ee8 | 0x1a9 |
GetProcAddress | 0x0 | 0x40d0f0 | 0x126ec | 0x10eec | 0x2aa |
LoadLibraryExW | 0x0 | 0x40d0f4 | 0x126f0 | 0x10ef0 | 0x3be |
RaiseException | 0x0 | 0x40d0f8 | 0x126f4 | 0x10ef4 | 0x45b |
GetStdHandle | 0x0 | 0x40d0fc | 0x126f8 | 0x10ef8 | 0x2ce |
WriteFile | 0x0 | 0x40d100 | 0x126fc | 0x10efc | 0x60a |
GetModuleFileNameW | 0x0 | 0x40d104 | 0x12700 | 0x10f00 | 0x270 |
MultiByteToWideChar | 0x0 | 0x40d108 | 0x12704 | 0x10f04 | 0x3e8 |
WideCharToMultiByte | 0x0 | 0x40d10c | 0x12708 | 0x10f08 | 0x5f6 |
ExitProcess | 0x0 | 0x40d110 | 0x1270c | 0x10f0c | 0x15c |
GetModuleHandleExW | 0x0 | 0x40d114 | 0x12710 | 0x10f10 | 0x273 |
GetACP | 0x0 | 0x40d118 | 0x12714 | 0x10f14 | 0x1b0 |
HeapAlloc | 0x0 | 0x40d11c | 0x12718 | 0x10f18 | 0x341 |
HeapFree | 0x0 | 0x40d120 | 0x1271c | 0x10f1c | 0x345 |
FindClose | 0x0 | 0x40d124 | 0x12720 | 0x10f20 | 0x173 |
FindFirstFileExW | 0x0 | 0x40d128 | 0x12724 | 0x10f24 | 0x179 |
DecodePointer | 0x0 | 0x40d12c | 0x12728 | 0x10f28 | 0x107 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetDesktopWindow | 0x0 | 0x40d134 | 0x12730 | 0x10f30 | 0x142 |
InvalidateRect | 0x0 | 0x40d138 | 0x12734 | 0x10f34 | 0x210 |
wsprintfW | 0x0 | 0x40d13c | 0x12738 | 0x10f38 | 0x3d5 |
DrawIcon | 0x0 | 0x40d140 | 0x1273c | 0x10f3c | 0xd5 |
FillRect | 0x0 | 0x40d144 | 0x12740 | 0x10f40 | 0x10f |
SendMessageW | 0x0 | 0x40d148 | 0x12744 | 0x10f44 | 0x30d |
GetDlgItem | 0x0 | 0x40d14c | 0x12748 | 0x10f48 | 0x149 |
PostQuitMessage | 0x0 | 0x40d150 | 0x1274c | 0x10f4c | 0x2a9 |
EndPaint | 0x0 | 0x40d154 | 0x12750 | 0x10f50 | 0xf3 |
BeginPaint | 0x0 | 0x40d158 | 0x12754 | 0x10f54 | 0x10 |
DefWindowProcW | 0x0 | 0x40d15c | 0x12758 | 0x10f58 | 0xa8 |
DestroyWindow | 0x0 | 0x40d160 | 0x1275c | 0x10f5c | 0xb5 |
DialogBoxParamW | 0x0 | 0x40d164 | 0x12760 | 0x10f60 | 0xba |
MoveWindow | 0x0 | 0x40d168 | 0x12764 | 0x10f64 | 0x28b |
GetClientRect | 0x0 | 0x40d16c | 0x12768 | 0x10f68 | 0x130 |
CreateDialogParamW | 0x0 | 0x40d170 | 0x1276c | 0x10f6c | 0x68 |
UpdateWindow | 0x0 | 0x40d174 | 0x12770 | 0x10f70 | 0x3b2 |
ShowWindow | 0x0 | 0x40d178 | 0x12774 | 0x10f74 | 0x378 |
SetWindowPos | 0x0 | 0x40d17c | 0x12778 | 0x10f78 | 0x367 |
CreateWindowExW | 0x0 | 0x40d180 | 0x1277c | 0x10f7c | 0x73 |
RegisterClassExW | 0x0 | 0x40d184 | 0x12780 | 0x10f80 | 0x2d5 |
LoadCursorW | 0x0 | 0x40d188 | 0x12784 | 0x10f84 | 0x244 |
DispatchMessageW | 0x0 | 0x40d18c | 0x12788 | 0x10f88 | 0xbd |
TranslateMessage | 0x0 | 0x40d190 | 0x1278c | 0x10f8c | 0x398 |
TranslateAcceleratorW | 0x0 | 0x40d194 | 0x12790 | 0x10f90 | 0x396 |
GetMessageW | 0x0 | 0x40d198 | 0x12794 | 0x10f94 | 0x183 |
LoadAcceleratorsW | 0x0 | 0x40d19c | 0x12798 | 0x10f98 | 0x23e |
LoadStringW | 0x0 | 0x40d1a0 | 0x1279c | 0x10f9c | 0x253 |
LoadIconW | 0x0 | 0x40d1a4 | 0x127a0 | 0x10fa0 | 0x246 |
GetMonitorInfoW | 0x0 | 0x40d1a8 | 0x127a4 | 0x10fa4 | 0x185 |
MonitorFromWindow | 0x0 | 0x40d1ac | 0x127a8 | 0x10fa8 | 0x28a |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TextOutW | 0x0 | 0x40d008 | 0x12604 | 0x10e04 | 0x38d |
SetBkMode | 0x0 | 0x40d00c | 0x12608 | 0x10e08 | 0x352 |
SelectObject | 0x0 | 0x40d010 | 0x1260c | 0x10e0c | 0x34a |
CreateFontW | 0x0 | 0x40d014 | 0x12610 | 0x10e10 | 0x44 |
DeleteObject | 0x0 | 0x40d018 | 0x12614 | 0x10e14 | 0x16d |
CreateSolidBrush | 0x0 | 0x40d01c | 0x12618 | 0x10e18 | 0x59 |
SetTextAlign | 0x0 | 0x40d020 | 0x1261c | 0x10e1c | 0x378 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InitCommonControlsEx | 0x0 | 0x40d000 | 0x125fc | 0x10dfc | 0x7b |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
timeGetTime | 0x0 | 0x40d1b4 | 0x127b0 | 0x10fb0 | 0x94 |
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\ac0fced0-d42a-4728-a9f2-bdfd4590c238\2.exe | Created File | Binary |
Not Queried
|
...
|
Image Base | 0x400000 |
Entry Point | 0x402350 |
Size Of Code | 0xd200 |
Size Of Initialized Data | 0x20e00 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2018-11-07 09:31:02+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xd09f | 0xd200 | 0x400 | cnt_code, mem_execute, mem_read | 6.61 |
.rdata | 0x40f000 | 0x74a2 | 0x7600 | 0xd600 | cnt_initialized_data, mem_read | 4.98 |
.data | 0x417000 | 0x1544 | 0xa00 | 0x14c00 | cnt_initialized_data, mem_read, mem_write | 2.25 |
.rsrc | 0x419000 | 0x17200 | 0x17200 | 0x15600 | cnt_initialized_data, mem_read | 4.03 |
.reloc | 0x431000 | 0xff4 | 0x1000 | 0x2c800 | cnt_initialized_data, mem_discardable, mem_read | 6.52 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateFileW | 0x0 | 0x40f000 | 0x15e64 | 0x14464 | 0xca |
GetFileSize | 0x0 | 0x40f004 | 0x15e68 | 0x14468 | 0x247 |
SetFilePointer | 0x0 | 0x40f008 | 0x15e6c | 0x1446c | 0x51a |
WriteFile | 0x0 | 0x40f00c | 0x15e70 | 0x14470 | 0x60a |
CloseHandle | 0x0 | 0x40f010 | 0x15e74 | 0x14474 | 0x86 |
WriteConsoleW | 0x0 | 0x40f014 | 0x15e78 | 0x14478 | 0x609 |
SetFilePointerEx | 0x0 | 0x40f018 | 0x15e7c | 0x1447c | 0x51b |
GetConsoleMode | 0x0 | 0x40f01c | 0x15e80 | 0x14480 | 0x1fa |
GetConsoleCP | 0x0 | 0x40f020 | 0x15e84 | 0x14484 | 0x1e8 |
FlushFileBuffers | 0x0 | 0x40f024 | 0x15e88 | 0x14488 | 0x19d |
HeapReAlloc | 0x0 | 0x40f028 | 0x15e8c | 0x1448c | 0x348 |
HeapSize | 0x0 | 0x40f02c | 0x15e90 | 0x14490 | 0x34a |
GetProcessHeap | 0x0 | 0x40f030 | 0x15e94 | 0x14494 | 0x2b0 |
LCMapStringW | 0x0 | 0x40f034 | 0x15e98 | 0x14498 | 0x3ac |
GetStringTypeW | 0x0 | 0x40f038 | 0x15e9c | 0x1449c | 0x2d3 |
GetFileType | 0x0 | 0x40f03c | 0x15ea0 | 0x144a0 | 0x24a |
SetStdHandle | 0x0 | 0x40f040 | 0x15ea4 | 0x144a4 | 0x542 |
FreeEnvironmentStringsW | 0x0 | 0x40f044 | 0x15ea8 | 0x144a8 | 0x1a8 |
GetEnvironmentStringsW | 0x0 | 0x40f048 | 0x15eac | 0x144ac | 0x233 |
UnhandledExceptionFilter | 0x0 | 0x40f04c | 0x15eb0 | 0x144b0 | 0x5a5 |
SetUnhandledExceptionFilter | 0x0 | 0x40f050 | 0x15eb4 | 0x144b4 | 0x565 |
GetCurrentProcess | 0x0 | 0x40f054 | 0x15eb8 | 0x144b8 | 0x215 |
TerminateProcess | 0x0 | 0x40f058 | 0x15ebc | 0x144bc | 0x584 |
IsProcessorFeaturePresent | 0x0 | 0x40f05c | 0x15ec0 | 0x144c0 | 0x381 |
QueryPerformanceCounter | 0x0 | 0x40f060 | 0x15ec4 | 0x144c4 | 0x446 |
GetCurrentProcessId | 0x0 | 0x40f064 | 0x15ec8 | 0x144c8 | 0x216 |
GetCurrentThreadId | 0x0 | 0x40f068 | 0x15ecc | 0x144cc | 0x21a |
GetSystemTimeAsFileTime | 0x0 | 0x40f06c | 0x15ed0 | 0x144d0 | 0x2e5 |
InitializeSListHead | 0x0 | 0x40f070 | 0x15ed4 | 0x144d4 | 0x35e |
IsDebuggerPresent | 0x0 | 0x40f074 | 0x15ed8 | 0x144d8 | 0x37a |
GetStartupInfoW | 0x0 | 0x40f078 | 0x15edc | 0x144dc | 0x2cc |
GetModuleHandleW | 0x0 | 0x40f07c | 0x15ee0 | 0x144e0 | 0x274 |
RtlUnwind | 0x0 | 0x40f080 | 0x15ee4 | 0x144e4 | 0x4cb |
RaiseException | 0x0 | 0x40f084 | 0x15ee8 | 0x144e8 | 0x45b |
GetLastError | 0x0 | 0x40f088 | 0x15eec | 0x144ec | 0x25d |
SetLastError | 0x0 | 0x40f08c | 0x15ef0 | 0x144f0 | 0x52a |
EncodePointer | 0x0 | 0x40f090 | 0x15ef4 | 0x144f4 | 0x12b |
EnterCriticalSection | 0x0 | 0x40f094 | 0x15ef8 | 0x144f8 | 0x12f |
LeaveCriticalSection | 0x0 | 0x40f098 | 0x15efc | 0x144fc | 0x3b8 |
DeleteCriticalSection | 0x0 | 0x40f09c | 0x15f00 | 0x14500 | 0x10e |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40f0a0 | 0x15f04 | 0x14504 | 0x35a |
TlsAlloc | 0x0 | 0x40f0a4 | 0x15f08 | 0x14508 | 0x596 |
TlsGetValue | 0x0 | 0x40f0a8 | 0x15f0c | 0x1450c | 0x598 |
TlsSetValue | 0x0 | 0x40f0ac | 0x15f10 | 0x14510 | 0x599 |
TlsFree | 0x0 | 0x40f0b0 | 0x15f14 | 0x14514 | 0x597 |
FreeLibrary | 0x0 | 0x40f0b4 | 0x15f18 | 0x14518 | 0x1a9 |
GetProcAddress | 0x0 | 0x40f0b8 | 0x15f1c | 0x1451c | 0x2aa |
LoadLibraryExW | 0x0 | 0x40f0bc | 0x15f20 | 0x14520 | 0x3be |
GetStdHandle | 0x0 | 0x40f0c0 | 0x15f24 | 0x14524 | 0x2ce |
GetModuleFileNameW | 0x0 | 0x40f0c4 | 0x15f28 | 0x14528 | 0x270 |
MultiByteToWideChar | 0x0 | 0x40f0c8 | 0x15f2c | 0x1452c | 0x3e8 |
WideCharToMultiByte | 0x0 | 0x40f0cc | 0x15f30 | 0x14530 | 0x5f6 |
ExitProcess | 0x0 | 0x40f0d0 | 0x15f34 | 0x14534 | 0x15c |
GetModuleHandleExW | 0x0 | 0x40f0d4 | 0x15f38 | 0x14538 | 0x273 |
GetACP | 0x0 | 0x40f0d8 | 0x15f3c | 0x1453c | 0x1b0 |
HeapAlloc | 0x0 | 0x40f0dc | 0x15f40 | 0x14540 | 0x341 |
HeapFree | 0x0 | 0x40f0e0 | 0x15f44 | 0x14544 | 0x345 |
FindClose | 0x0 | 0x40f0e4 | 0x15f48 | 0x14548 | 0x173 |
FindFirstFileExW | 0x0 | 0x40f0e8 | 0x15f4c | 0x1454c | 0x179 |
FindNextFileW | 0x0 | 0x40f0ec | 0x15f50 | 0x14550 | 0x18a |
IsValidCodePage | 0x0 | 0x40f0f0 | 0x15f54 | 0x14554 | 0x386 |
GetOEMCP | 0x0 | 0x40f0f4 | 0x15f58 | 0x14558 | 0x293 |
GetCPInfo | 0x0 | 0x40f0f8 | 0x15f5c | 0x1455c | 0x1bf |
GetCommandLineA | 0x0 | 0x40f0fc | 0x15f60 | 0x14560 | 0x1d4 |
GetCommandLineW | 0x0 | 0x40f100 | 0x15f64 | 0x14564 | 0x1d5 |
DecodePointer | 0x0 | 0x40f104 | 0x15f68 | 0x14568 | 0x107 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x40f11c | 0x15f80 | 0x14580 | 0x27e |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetFolderPathW | 0x0 | 0x40f10c | 0x15f70 | 0x14570 | 0x159 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathAppendW | 0x0 | 0x40f114 | 0x15f78 | 0x14578 | 0x37 |