Dynamic Analysis Report |
Classification: Riskware, Ransomware |
539b0b5d54757e8a2b754ecdc2939eb7cf9db0ed1728e0eca407500222668505 (SHA256)
fcr.exe
Created at 2018-09-23 19:12:00
Notifications (2/3)
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The overall sleep time of all monitored processes was truncated from "1 minute" to "20 seconds" to reveal dormant functionality.
The operating system was rebooted during the analysis.
Remarks
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
This list contains only the embedded files and created files
Filters: |
There are no files for this filter
Filename | Category | Type | Severity | Actions |
---|
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3388679973-3930757225-3770151564-1000\fda992c8d564f97e48410a19a2e459f6_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f | Created File | Stream |
Whitelisted
|
...
|
Severity |
Whitelisted
|
First Seen | 2015-04-08 12:52 (UTC+2) |
Last Seen | 2018-05-20 10:45 (UTC+2) |
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fcr.exe | Sample File | Binary |
Unknown
|
...
|
Image Base | 0x400000 |
Entry Point | 0x401000 |
Size Of Code | 0x1200 |
Size Of Initialized Data | 0x1a00 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2018-09-21 08:54:13+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x10d4 | 0x1200 | 0x400 | cnt_code, mem_execute, mem_read | 5.58 |
.rdata | 0x403000 | 0x4cc | 0x600 | 0x1600 | cnt_initialized_data, mem_read | 4.33 |
.data | 0x404000 | 0x1390 | 0xc00 | 0x1c00 | cnt_initialized_data, mem_read, mem_write | 7.93 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlZeroMemory | 0x0 | 0x403040 | 0x313c | 0x173c | 0x258 |
SetFileAttributesW | 0x0 | 0x403044 | 0x3140 | 0x1740 | 0x284 |
SetFilePointerEx | 0x0 | 0x403048 | 0x3144 | 0x1744 | 0x286 |
SetThreadPriority | 0x0 | 0x40304c | 0x3148 | 0x1748 | 0x2a9 |
Sleep | 0x0 | 0x403050 | 0x314c | 0x174c | 0x2b7 |
UnmapViewOfFile | 0x0 | 0x403054 | 0x3150 | 0x1750 | 0x2cf |
WriteFile | 0x0 | 0x403058 | 0x3154 | 0x1754 | 0x2f7 |
RtlMoveMemory | 0x0 | 0x40305c | 0x3158 | 0x1758 | 0x256 |
lstrcmpW | 0x0 | 0x403060 | 0x315c | 0x175c | 0x312 |
lstrcmpiA | 0x0 | 0x403064 | 0x3160 | 0x1760 | 0x313 |
lstrcmpiW | 0x0 | 0x403068 | 0x3164 | 0x1764 | 0x314 |
lstrcpyW | 0x0 | 0x40306c | 0x3168 | 0x1768 | 0x316 |
lstrlenA | 0x0 | 0x403070 | 0x316c | 0x176c | 0x319 |
lstrlenW | 0x0 | 0x403074 | 0x3170 | 0x1770 | 0x31a |
MultiByteToWideChar | 0x0 | 0x403078 | 0x3174 | 0x1774 | 0x20b |
MoveFileW | 0x0 | 0x40307c | 0x3178 | 0x1778 | 0x207 |
MapViewOfFile | 0x0 | 0x403080 | 0x317c | 0x177c | 0x200 |
GlobalMemoryStatus | 0x0 | 0x403084 | 0x3180 | 0x1780 | 0x1b1 |
GlobalFree | 0x0 | 0x403088 | 0x3184 | 0x1784 | 0x1ac |
GlobalAlloc | 0x0 | 0x40308c | 0x3188 | 0x1788 | 0x1a5 |
GetModuleFileNameA | 0x0 | 0x403090 | 0x318c | 0x178c | 0x132 |
GetFileAttributesW | 0x0 | 0x403094 | 0x3190 | 0x1790 | 0x11a |
GetEnvironmentVariableA | 0x0 | 0x403098 | 0x3194 | 0x1794 | 0x113 |
CreateThread | 0x0 | 0x40309c | 0x3198 | 0x1798 | 0x56 |
CreateFileW | 0x0 | 0x4030a0 | 0x319c | 0x179c | 0x40 |
CreateFileMappingA | 0x0 | 0x4030a4 | 0x31a0 | 0x17a0 | 0x3e |
CreateFileA | 0x0 | 0x4030a8 | 0x31a4 | 0x17a4 | 0x3d |
CopyFileA | 0x0 | 0x4030ac | 0x31a8 | 0x17a8 | 0x2e |
lstrcatW | 0x0 | 0x4030b0 | 0x31ac | 0x17ac | 0x310 |
CloseHandle | 0x0 | 0x4030b4 | 0x31b0 | 0x17b0 | 0x23 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExA | 0x0 | 0x403000 | 0x30fc | 0x16fc | 0x1da |
RegOpenKeyExA | 0x0 | 0x403004 | 0x3100 | 0x1700 | 0x1d0 |
RegCloseKey | 0x0 | 0x403008 | 0x3104 | 0x1704 | 0x1b7 |
OpenProcessToken | 0x0 | 0x40300c | 0x3108 | 0x1708 | 0x198 |
LookupPrivilegeValueA | 0x0 | 0x403010 | 0x310c | 0x170c | 0x141 |
CryptReleaseContext | 0x0 | 0x403014 | 0x3110 | 0x1710 | 0x98 |
CryptImportKey | 0x0 | 0x403018 | 0x3114 | 0x1714 | 0x97 |
CryptGenKey | 0x0 | 0x40301c | 0x3118 | 0x1718 | 0x8d |
CryptExportKey | 0x0 | 0x403020 | 0x311c | 0x171c | 0x8c |
CryptEncrypt | 0x0 | 0x403024 | 0x3120 | 0x1720 | 0x87 |
CryptDestroyKey | 0x0 | 0x403028 | 0x3124 | 0x1724 | 0x84 |
CryptDecrypt | 0x0 | 0x40302c | 0x3128 | 0x1728 | 0x81 |
CryptAcquireContextA | 0x0 | 0x403030 | 0x312c | 0x172c | 0x7d |
AdjustTokenPrivileges | 0x0 | 0x403034 | 0x3130 | 0x1730 | 0x19 |
RegSetValueExA | 0x0 | 0x403038 | 0x3134 | 0x1734 | 0x1e7 |
\\?\C:\ProgramData\Sun\Java\Java Update\jaureglist.xml id-bry0hIIfVldG0S8v.BDKR | Modified File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Common Files\constitute_appropriate_sorry.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Unknown
|
...
|
\\?\C:\Program Files\Windows Mail\sims.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\LtrqqbP.mkv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\f8Ro3n.pptx id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\17OCGHFRMI5H.jpg id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hUrKRx28Hz-Nx\Tly1NB.mkv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Adobe\Reader 10.0\IrakHau.htm id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Unknown
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\Office14\AUTHZAX.DLL id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Z9nkSGY0laIlN\JwY69bt7Heb.flv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\1 82DV\8xX2fIJi.swf id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Microsoft\OFFICE\AssetLibrary.ico id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\1 82DV\ArpKK-QGNbVoL.flv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Unknown
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\69-LUmry m-.bmp id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Unknown
|
...
|
\\?\C:\BOOTSECT.BAK id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Unknown
|
...
|
\\?\C:\ProgramData\Microsoft\MF\Active.GRL id-bry0hIIfVldG0S8v.BDKR | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\GxY9j-YD0CfIAbkw0.png id-bry0hIIfVldG0S8v.BDKR | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Adobe\Reader 10.0\Berime.htm id-bry0hIIfVldG0S8v.BDKR | Modified File | Stream |
Not Queried
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3388679973-3930757225-3770151564-1000\fda992c8d564f97e48410a19a2e459f6_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Mozilla\logs\maintenanceservice-install.log id-bry0hIIfVldG0S8v.BDKR | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdf id-bry0hIIfVldG0S8v.BDKR | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\IdentityCRL\ppcrlconfig.dll id-bry0hIIfVldG0S8v.BDKR | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf id-bry0hIIfVldG0S8v.BDKR | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Office\Office14\3082\MSO.ACL id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\D3kKjfyCTl.avi id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\58.0.3029.110.manifest id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Windows Media Player\sentence-arrive-unnecessary.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4JBCyaw.csv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Windows Defender\picking separated lib.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Internet Explorer\SIGNUP\install.ins id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Adobe\Reader 10.0\Benioku.htm id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\3_jeQviZoYNlnOtMBcq.png id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\GcQTiaw8mWqp.mp3 id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Searches\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\6wzmOUQs0Tg8egP.jpg id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\MSBuild\moore-encouraging-percent.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Office\Stationery\1033\CURRENCY.GIF id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Java\jre7\COPYRIGHT id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\0cdYs09W.xlsx id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\d-NecsGi8.bmp id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{1D1DBF3A-752F-47E2-BE70-D848D4A9AFB0} id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Java\jewel.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.msi id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\8oa0-m3WJaKwnSuLh9e\6 6JppDDb.m4a id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\82U1GLPSN4SRNIud.gif id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Color\ACECache11.lst id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\regulationspublishers.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Boot\BOOTSTAT.DAT id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\HhuwU2FyuyIkneVE0.m4a id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Synchronization Services\hourunexpected.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\DESIGNER\MSADDNDR.DLL id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\microsoft shared\Help\Hx.HxC id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Videos\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\BDLjWOroke8o.swf id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\microsoft shared\Portal\1033\PortalConnect.dll id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\Office14\BCSLaunch.dll id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\MSBuild\Microsoft.Office.InfoPath.targets id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Desktop\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Internet Explorer\mysimon.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5M5 seT-5vd_voX\aYtHQeH.rtf id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\8oa0-m3WJaKwnSuLh9e\4t-7-GHSbfJZ.wav id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\microsoft shared\Help\HxRuntime.HxS id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Synchronization Services\ADO.NET\v1.0\Microsoft.Synchronization.Data.Server.dll id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\6cHawfktiEZ.wav id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\h-HTnXxEnveIM20.m4a id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\1 82DV\lp0OA0hCWhhS.mp4 id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\b2ut2.avi id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Adobe\Acrobat\10.0\Replicate\Security\directories.acrodata id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Uninstall Information\vampire criterion.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Windows Sidebar\settings.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Windows Defender\finds_lingerie_candy.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\WOUo-AhtDHZS.mp3 id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Synchronization Services\ADO.NET\v1.0\Microsoft.Synchronization.Data.SqlServerCe.dll id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3388679973-3930757225-3770151564-1000\fda992c8d564f97e48410a19a2e459f6_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Windows Sidebar\settings.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ISzELKWmrU6cLqu\mXRNnT5\1805vjPgt2k9.mp4 id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\8oa0-m3WJaKwnSuLh9e\iJ-ZpQPb5YO5-LGM1KVt.m4a id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\h84ce25Cd2e.csv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Mozilla Firefox\AccessibleMarshal.dll id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.Tools.Applications.Project.dll id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ISzELKWmrU6cLqu\fWCi8GqHv.flv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\microsoft shared\Stationery\Desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\7pTl.mkv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\iAeOeT.jpg id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Z9nkSGY0laIlN\8YBa.mkv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\024823B39FBEACCDB5C06426A8168E99_6D5CAB161A1C65362A913D29BE09D91B id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\microsoft shared\Help\Hx.HxT id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Z9nkSGY0laIlN\wP80jSXk-sTG.mkv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\ReaderMessages id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Searches\Indexed Locations.search-ms id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Pictures\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.CNT id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Lhdb7FgPQ1J3_Q8MQ.jpg id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\9NWJiKv80-C.jpg id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\1 82DV\CouoxFa1.flv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\kTM8.mp3 id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveLR.cab id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Downloads\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AagfwO5FfrKxIJ.gif id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Synchronization Services\sword.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aTwMt9g.mp4 id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\qUPt7PlaxE1RY9rpDm.m4a id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5M5 seT-5vd_voX\33UdZO u-6J7rJrw.pptx id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\dJjV63BFqSdhoi-qlwb4.swf id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Windows Photo Viewer\motorola spank thomas.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.msi id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\microsoft shared\Help\NamedURLs.HxK id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\YYxxAR3wBsO-qZ5.wav id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\EURO\MSOEURO.DLL id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\BBn5CvTVgKWX.wav id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Microsoft.NET\browser accredited mil.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Uninstall Information\traditions.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\QQm9 JXI33bPKtzQI.m4a id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\qMoHu7gI.flv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\6SgVBsYZdT.swf id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Desktop\Google Chrome.lnk id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\HQDxBZD6HlJy7LLor.m4a id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\Desktop.lnk id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\microsoft shared\VSTO\ActionsPane3.xsd id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\MF\Pending.GRL id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft SQL Server Compact Edition\cat.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\vlkjgqIMwZdhJeRkz.mp3 id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Microsoft.NET\RedistList\AssemblyList_4_client.xml id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\bVC-tf9cuKZd9WIKBbf.gif id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Unknown.Log id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\PublicAssemblies\Microsoft.VisualStudio.Tools.Applications.Adapter.dll id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xml id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\6tU1DrgevnlBIXwjA.mp3 id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Downloads\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Windows Sidebar\mold.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\8oa0-m3WJaKwnSuLh9e\90gCcG7fd.mp3 id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\c1M5lwW.bmp id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Desktop\Adobe Reader X.lnk id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ghoVSrE2rI.png id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hUrKRx28Hz-Nx\IEaKhwDUaCNJ5.mkv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\Common Files\microsoft shared\Help\Keywords.HxK id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.msi id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Saved Games\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Synchronization Services\ADO.NET\v1.0\Microsoft.Synchronization.Data.dll id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5M5 seT-5vd_voX\3giUFeu.csv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\8hzaVpqj7b2yZS4hQQX8.m4a id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\BXRrb4wqQer.jpg id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\KU8coeDggn.gif id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\zkHjeCw.swf id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.msi id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\H4rg2nkN_C8pmo9n.jpg id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ISzELKWmrU6cLqu\82NPkSzIwNQa.mp4 id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\jLfOoXctrtajuOXkJWbB.gif id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\cQRffh50TJ.png id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\ET-7EbrfGtKuwqVif3Bz.m4a id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ISzELKWmrU6cLqu\uvT3U1eLcUuXN33LX1.flv id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\8oa0-m3WJaKwnSuLh9e\9Q08f8qI8-EUS1ATwKx.mp3 id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\FBIBLIO.DLL id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\Help_CValidator.H1D id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Music\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\8oa0-m3WJaKwnSuLh9e\0TuiOM62.m4a id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3388679973-3930757225-3770151564-1000\fda992c8d564f97e48410a19a2e459f6_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.msi id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\as80.xsl id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Common Files\palmer still equations.exe id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Cj O Dl60Ws_W.ots id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0q-Q_imoU.swf id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\Recorded TV\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Z9nkSGY0laIlN\bc3GSd9GTrIuC8yT.avi id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Internet Explorer\SIGNUP\install.ins id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\69q9P8O1O.docx id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\F7hYN.ots id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\be8uU4s7v.bmp id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\DuvSsdgB.png id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\Public\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\Ja5mOI9ZMBy.m4a id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\G_LitrMcKt.wav id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hUrKRx28Hz-Nx\lMHvIe3HLUK9sBCYE5a.swf id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\024823B39FBEACCDB5C06426A8168E99_6D5CAB161A1C65362A913D29BE09D91B id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\KQeyWfmit_woScYM.mp3 id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Searches\Everywhere.search-ms id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\desktop.ini id-bry0hIIfVldG0S8v.BDKR | Created File | Stream |
Not Queried
|
...
|