VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
uvulko.exe
Windows Exe (x86-32)
Created at 2020-01-06T02:29:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-12-24 05:59 (UTC+1) |
Last Seen | 2019-12-28 03:12 (UTC+1) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x401570 |
Size Of Code | 0x22600 |
Size Of Initialized Data | 0x509400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-08-28 22:35:26+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x22460 | 0x22600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.29 |
.rdata | 0x424000 | 0xdda1 | 0xde00 | 0x22a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.42 |
.data | 0x432000 | 0x4e72a8 | 0x3400 | 0x30800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.62 |
.tls | 0x91a000 | 0x9 | 0x200 | 0x33c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x91b000 | 0xd2a0 | 0xd400 | 0x33e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.57 |
.reloc | 0x929000 | 0x6a0a | 0x6c00 | 0x41200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 2.48 |
Imports (1)
»
KERNEL32.dll (95)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCPInfo | 0x0 | 0x424000 | 0x314bc | 0x2febc | 0x15b |
UpdateResourceA | 0x0 | 0x424004 | 0x314c0 | 0x2fec0 | 0x449 |
GetNumberOfConsoleMouseButtons | 0x0 | 0x424008 | 0x314c4 | 0x2fec4 | 0x212 |
GetSystemWindowsDirectoryW | 0x0 | 0x42400c | 0x314c8 | 0x2fec8 | 0x252 |
SetEvent | 0x0 | 0x424010 | 0x314cc | 0x2fecc | 0x3d3 |
FreeEnvironmentStringsA | 0x0 | 0x424014 | 0x314d0 | 0x2fed0 | 0x14a |
GetModuleHandleW | 0x0 | 0x424018 | 0x314d4 | 0x2fed4 | 0x1f9 |
GetTickCount | 0x0 | 0x42401c | 0x314d8 | 0x2fed8 | 0x266 |
CreateActCtxW | 0x0 | 0x424020 | 0x314dc | 0x2fedc | 0x68 |
InitializeCriticalSection | 0x0 | 0x424024 | 0x314e0 | 0x2fee0 | 0x2b4 |
AddRefActCtx | 0x0 | 0x424028 | 0x314e4 | 0x2fee4 | 0x9 |
GetStringTypeExW | 0x0 | 0x42402c | 0x314e8 | 0x2fee8 | 0x23f |
WriteConsoleW | 0x0 | 0x424030 | 0x314ec | 0x2feec | 0x48c |
EnumDateFormatsExW | 0x0 | 0x424034 | 0x314f0 | 0x2fef0 | 0xe2 |
TerminateProcess | 0x0 | 0x424038 | 0x314f4 | 0x2fef4 | 0x42d |
GetOverlappedResult | 0x0 | 0x42403c | 0x314f8 | 0x2fef8 | 0x214 |
lstrlenW | 0x0 | 0x424040 | 0x314fc | 0x2fefc | 0x4b6 |
GetLogicalDriveStringsA | 0x0 | 0x424044 | 0x31500 | 0x2ff00 | 0x1eb |
GetLastError | 0x0 | 0x424048 | 0x31504 | 0x2ff04 | 0x1e6 |
LocalAlloc | 0x0 | 0x42404c | 0x31508 | 0x2ff08 | 0x2f9 |
CreateEventW | 0x0 | 0x424050 | 0x3150c | 0x2ff0c | 0x75 |
QueryDosDeviceW | 0x0 | 0x424054 | 0x31510 | 0x2ff10 | 0x34e |
VirtualProtect | 0x0 | 0x424058 | 0x31514 | 0x2ff14 | 0x45a |
GetCurrentThreadId | 0x0 | 0x42405c | 0x31518 | 0x2ff18 | 0x1ad |
IsBadWritePtr | 0x0 | 0x424060 | 0x3151c | 0x2ff1c | 0x2cb |
FindFirstChangeNotificationW | 0x0 | 0x424064 | 0x31520 | 0x2ff20 | 0x11c |
GetCommandLineA | 0x0 | 0x424068 | 0x31524 | 0x2ff24 | 0x16f |
GetStartupInfoA | 0x0 | 0x42406c | 0x31528 | 0x2ff28 | 0x239 |
HeapValidate | 0x0 | 0x424070 | 0x3152c | 0x2ff2c | 0x2a9 |
IsBadReadPtr | 0x0 | 0x424074 | 0x31530 | 0x2ff30 | 0x2c8 |
RaiseException | 0x0 | 0x424078 | 0x31534 | 0x2ff34 | 0x35a |
GetCurrentProcess | 0x0 | 0x42407c | 0x31538 | 0x2ff38 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x424080 | 0x3153c | 0x2ff3c | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x424084 | 0x31540 | 0x2ff40 | 0x415 |
IsDebuggerPresent | 0x0 | 0x424088 | 0x31544 | 0x2ff44 | 0x2d1 |
GetModuleFileNameW | 0x0 | 0x42408c | 0x31548 | 0x2ff48 | 0x1f5 |
EnterCriticalSection | 0x0 | 0x424090 | 0x3154c | 0x2ff4c | 0xd9 |
LeaveCriticalSection | 0x0 | 0x424094 | 0x31550 | 0x2ff50 | 0x2ef |
DeleteCriticalSection | 0x0 | 0x424098 | 0x31554 | 0x2ff54 | 0xbe |
QueryPerformanceCounter | 0x0 | 0x42409c | 0x31558 | 0x2ff58 | 0x354 |
GetCurrentProcessId | 0x0 | 0x4240a0 | 0x3155c | 0x2ff5c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x4240a4 | 0x31560 | 0x2ff60 | 0x24f |
Sleep | 0x0 | 0x4240a8 | 0x31564 | 0x2ff64 | 0x421 |
InterlockedIncrement | 0x0 | 0x4240ac | 0x31568 | 0x2ff68 | 0x2c0 |
InterlockedDecrement | 0x0 | 0x4240b0 | 0x3156c | 0x2ff6c | 0x2bc |
GetProcAddress | 0x0 | 0x4240b4 | 0x31570 | 0x2ff70 | 0x220 |
ExitProcess | 0x0 | 0x4240b8 | 0x31574 | 0x2ff74 | 0x104 |
GetModuleFileNameA | 0x0 | 0x4240bc | 0x31578 | 0x2ff78 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x4240c0 | 0x3157c | 0x2ff7c | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x4240c4 | 0x31580 | 0x2ff80 | 0x14b |
WideCharToMultiByte | 0x0 | 0x4240c8 | 0x31584 | 0x2ff84 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x4240cc | 0x31588 | 0x2ff88 | 0x1c1 |
SetHandleCount | 0x0 | 0x4240d0 | 0x3158c | 0x2ff8c | 0x3e8 |
GetStdHandle | 0x0 | 0x4240d4 | 0x31590 | 0x2ff90 | 0x23b |
GetFileType | 0x0 | 0x4240d8 | 0x31594 | 0x2ff94 | 0x1d7 |
TlsGetValue | 0x0 | 0x4240dc | 0x31598 | 0x2ff98 | 0x434 |
TlsAlloc | 0x0 | 0x4240e0 | 0x3159c | 0x2ff9c | 0x432 |
TlsSetValue | 0x0 | 0x4240e4 | 0x315a0 | 0x2ffa0 | 0x435 |
TlsFree | 0x0 | 0x4240e8 | 0x315a4 | 0x2ffa4 | 0x433 |
SetLastError | 0x0 | 0x4240ec | 0x315a8 | 0x2ffa8 | 0x3ec |
HeapDestroy | 0x0 | 0x4240f0 | 0x315ac | 0x2ffac | 0x2a0 |
HeapCreate | 0x0 | 0x4240f4 | 0x315b0 | 0x2ffb0 | 0x29f |
HeapFree | 0x0 | 0x4240f8 | 0x315b4 | 0x2ffb4 | 0x2a1 |
VirtualFree | 0x0 | 0x4240fc | 0x315b8 | 0x2ffb8 | 0x457 |
WriteFile | 0x0 | 0x424100 | 0x315bc | 0x2ffbc | 0x48d |
HeapAlloc | 0x0 | 0x424104 | 0x315c0 | 0x2ffc0 | 0x29d |
HeapSize | 0x0 | 0x424108 | 0x315c4 | 0x2ffc4 | 0x2a6 |
HeapReAlloc | 0x0 | 0x42410c | 0x315c8 | 0x2ffc8 | 0x2a4 |
VirtualAlloc | 0x0 | 0x424110 | 0x315cc | 0x2ffcc | 0x454 |
GetACP | 0x0 | 0x424114 | 0x315d0 | 0x2ffd0 | 0x152 |
GetOEMCP | 0x0 | 0x424118 | 0x315d4 | 0x2ffd4 | 0x213 |
IsValidCodePage | 0x0 | 0x42411c | 0x315d8 | 0x2ffd8 | 0x2db |
SetFilePointer | 0x0 | 0x424120 | 0x315dc | 0x2ffdc | 0x3df |
GetConsoleCP | 0x0 | 0x424124 | 0x315e0 | 0x2ffe0 | 0x183 |
GetConsoleMode | 0x0 | 0x424128 | 0x315e4 | 0x2ffe4 | 0x195 |
DebugBreak | 0x0 | 0x42412c | 0x315e8 | 0x2ffe8 | 0xb4 |
OutputDebugStringA | 0x0 | 0x424130 | 0x315ec | 0x2ffec | 0x33a |
OutputDebugStringW | 0x0 | 0x424134 | 0x315f0 | 0x2fff0 | 0x33b |
LoadLibraryW | 0x0 | 0x424138 | 0x315f4 | 0x2fff4 | 0x2f4 |
MultiByteToWideChar | 0x0 | 0x42413c | 0x315f8 | 0x2fff8 | 0x31a |
RtlUnwind | 0x0 | 0x424140 | 0x315fc | 0x2fffc | 0x392 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x424144 | 0x31600 | 0x30000 | 0x2b5 |
LoadLibraryA | 0x0 | 0x424148 | 0x31604 | 0x30004 | 0x2f1 |
LCMapStringA | 0x0 | 0x42414c | 0x31608 | 0x30008 | 0x2e1 |
LCMapStringW | 0x0 | 0x424150 | 0x3160c | 0x3000c | 0x2e3 |
GetStringTypeA | 0x0 | 0x424154 | 0x31610 | 0x30010 | 0x23d |
GetStringTypeW | 0x0 | 0x424158 | 0x31614 | 0x30014 | 0x240 |
GetLocaleInfoA | 0x0 | 0x42415c | 0x31618 | 0x30018 | 0x1e8 |
SetStdHandle | 0x0 | 0x424160 | 0x3161c | 0x3001c | 0x3fc |
WriteConsoleA | 0x0 | 0x424164 | 0x31620 | 0x30020 | 0x482 |
GetConsoleOutputCP | 0x0 | 0x424168 | 0x31624 | 0x30024 | 0x199 |
FlushFileBuffers | 0x0 | 0x42416c | 0x31628 | 0x30028 | 0x141 |
CreateFileA | 0x0 | 0x424170 | 0x3162c | 0x3002c | 0x78 |
CloseHandle | 0x0 | 0x424174 | 0x31630 | 0x30030 | 0x43 |
GetModuleHandleA | 0x0 | 0x424178 | 0x31634 | 0x30034 | 0x1f6 |
Exports (2)
»
Api name | EAT Address | Ordinal |
---|---|---|
@jdukfylyi@0 | 0x1c480 | 0x1 |
@sdxfgjy@4 | 0x1c470 | 0x2 |
Memory Dumps (13)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
uvulko.exe | 1 | 0x00400000 | 0x0092FFFF | Relevant Image | - | 32-bit | - |
...
|
||
buffer | 1 | 0x00BF1BE8 | 0x00BF5929 | Marked Executable | - | 32-bit | 0x00BF1BE8 |
...
|
||
buffer | 1 | 0x00030000 | 0x00036FFF | First Execution | - | 32-bit | 0x00030000 |
...
|
||
uvulko.exe | 1 | 0x00400000 | 0x0092FFFF | Content Changed | - | 32-bit | 0x004033C0 |
...
|
||
uvulko.exe | 1 | 0x00400000 | 0x0092FFFF | Content Changed | - | 32-bit | 0x00402AC0 |
...
|
||
uvulko.exe | 1 | 0x00400000 | 0x0092FFFF | Content Changed | - | 32-bit | 0x00403303 |
...
|
||
uvulko.exe | 1 | 0x00400000 | 0x0092FFFF | Final Dump | - | 32-bit | - |
...
|
||
uvulko.exe | 1 | 0x00400000 | 0x0092FFFF | Content Changed | - | 32-bit | 0x0040236D |
...
|
||
uvulko.exe | 1 | 0x00400000 | 0x0092FFFF | Content Changed | - | 32-bit | 0x00401426 |
...
|
||
uvulko.exe | 1 | 0x00400000 | 0x0092FFFF | Content Changed | - | 32-bit | 0x004024E0 |
...
|
||
uvulko.exe | 1 | 0x00400000 | 0x0092FFFF | Content Changed | - | 32-bit | 0x00401680 |
...
|
||
uvulko.exe | 1 | 0x00400000 | 0x0092FFFF | Content Changed | - | 32-bit | 0x004024E0 |
...
|
||
uvulko.exe | 1 | 0x00400000 | 0x0092FFFF | Content Changed | - | 32-bit | 0x0040246D |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Midie.69133 |
Malicious
|
\\?\C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\GetCurrentRollback.ini_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\SetupComplete.cmd_r00t_{3sXlE5}.njkwe | Dropped File | Batch |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\LocalizedData.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\LocalizedData.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\SetupResources.dll_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\LocalizedData.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\SetupResources.dll_r00t_{3sXlE5}.njkwe | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\LocalizedData.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\SetupResources.dll_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\LocalizedData.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\LocalizedData.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\SetupResources.dll_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\LocalizedData.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\SetupResources.dll_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\LocalizedData.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\SetupResources.dll_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\LocalizedData.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\SetupResources.dll_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\LocalizedData.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\SetupResources.dll_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\LocalizedData.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\SetupResources.dll_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\LocalizedData.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\DHtmlHeader.html_r00t_{3sXlE5}.njkwe | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\DisplayIcon.ico_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Print.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate1.ico_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate2.ico_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate4.ico_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate7.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\warn.ico_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core_x64.msi_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core_x86.msi_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended_x64.msi_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\ParameterInfo.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUi.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUtility.exe | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\watermark.bmp_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\BOOTNXT_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Internet Explorer.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Known Folders API Service.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-MUI%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-MUI%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Store%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\$WINRE_BACKUP_PARTITION.MARKER | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\SetupResources.dll_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\SetupResources.dll_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\eula.rtf_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\SetupResources.dll_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\LocalizedData.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\UiInfo.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\header.bmp_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core.mzz_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Setup.exe_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupEngine.dll_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\sqmapi.dll_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\UiInfo.xml_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Application.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\HardwareEvents.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Key Management Service.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx_r00t_{3sXlE5}.njkwe | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\taridd | Dropped File | Text |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\---==%$$$OPEN_ME_UP$$$==---.txt | Dropped File | Text |
Not Queried
|
...
|
»