Dynamic Analysis Report |
Classification: Riskware, Ransomware |
7a06c328733d43e19debcd3c045d35eed48538415de5f21c66885a4994eeadca (SHA256)
tzbtqw.exe
Created at 2019-03-01 21:19:00
Notifications (2/4)
Some extracted files may be missing in the report since the total file extraction size limit was reached during the analysis. You can increase the limit in the configuration settings.
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
The operating system was rebooted during the analysis.
Remarks
Some extracted files may be missing in the report since the total file extraction size limit was reached during the analysis. You can increase the limit in the configuration settings.
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
This list contains only the embedded files and created files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tzbtqw.exe | Sample File | Binary |
Unknown
|
...
|
Image Base | 0x400000 |
Entry Point | 0x409f20 |
Size Of Initialized Data | 0xc200 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2018-04-02 16:47:20+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.rdata | 0x401000 | 0xd088 | 0xd200 | 0x400 | cnt_initialized_data, mem_execute, mem_read, mem_write | 6.04 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetFilePointerEx | 0x0 | 0x401024 | 0xcb54 | 0xbf54 | 0x467 |
CloseHandle | 0x0 | 0x401028 | 0xcb58 | 0xbf58 | 0x52 |
lstrlenW | 0x0 | 0x40102c | 0xcb5c | 0xbf5c | 0x54e |
CreateFileW | 0x0 | 0x401030 | 0xcb60 | 0xbf60 | 0x8f |
HeapCreate | 0x0 | 0x401034 | 0xcb64 | 0xbf64 | 0x2cd |
GetCurrentProcess | 0x0 | 0x401038 | 0xcb68 | 0xbf68 | 0x1c0 |
ExitProcess | 0x0 | 0x40103c | 0xcb6c | 0xbf6c | 0x119 |
CreateThread | 0x0 | 0x401040 | 0xcb70 | 0xbf70 | 0xb5 |
GetCurrentThread | 0x0 | 0x401044 | 0xcb74 | 0xbf74 | 0x1c4 |
SetThreadPriority | 0x0 | 0x401048 | 0xcb78 | 0xbf78 | 0x499 |
WaitForMultipleObjects | 0x0 | 0x40104c | 0xcb7c | 0xbf7c | 0x4f7 |
Sleep | 0x0 | 0x401050 | 0xcb80 | 0xbf80 | 0x4b2 |
GetLogicalDrives | 0x0 | 0x401054 | 0xcb84 | 0xbf84 | 0x209 |
SetFilePointer | 0x0 | 0x401058 | 0xcb88 | 0xbf88 | 0x466 |
FindClose | 0x0 | 0x40105c | 0xcb8c | 0xbf8c | 0x12e |
lstrcmpiA | 0x0 | 0x401060 | 0xcb90 | 0xbf90 | 0x544 |
lstrcmpiW | 0x0 | 0x401064 | 0xcb94 | 0xbf94 | 0x545 |
lstrcpyA | 0x0 | 0x401068 | 0xcb98 | 0xbf98 | 0x547 |
ReadFile | 0x0 | 0x40106c | 0xcb9c | 0xbf9c | 0x3c0 |
lstrcatW | 0x0 | 0x401070 | 0xcba0 | 0xbfa0 | 0x53f |
GetModuleFileNameW | 0x0 | 0x401074 | 0xcba4 | 0xbfa4 | 0x214 |
CreateProcessW | 0x0 | 0x401078 | 0xcba8 | 0xbfa8 | 0xa8 |
GetEnvironmentVariableW | 0x0 | 0x40107c | 0xcbac | 0xbfac | 0x1dc |
GetDriveTypeA | 0x0 | 0x401080 | 0xcbb0 | 0xbfb0 | 0x1d2 |
GetTempPathW | 0x0 | 0x401084 | 0xcbb4 | 0xbfb4 | 0x285 |
GetTempFileNameW | 0x0 | 0x401088 | 0xcbb8 | 0xbfb8 | 0x283 |
SetFileAttributesW | 0x0 | 0x40108c | 0xcbbc | 0xbfbc | 0x461 |
GetFileAttributesW | 0x0 | 0x401090 | 0xcbc0 | 0xbfc0 | 0x1ea |
FindFirstFileW | 0x0 | 0x401094 | 0xcbc4 | 0xbfc4 | 0x139 |
FindNextFileW | 0x0 | 0x401098 | 0xcbc8 | 0xbfc8 | 0x145 |
CopyFileW | 0x0 | 0x40109c | 0xcbcc | 0xbfcc | 0x75 |
MoveFileExW | 0x0 | 0x4010a0 | 0xcbd0 | 0xbfd0 | 0x360 |
SetPriorityClass | 0x0 | 0x4010a4 | 0xcbd4 | 0xbfd4 | 0x47d |
MultiByteToWideChar | 0x0 | 0x4010a8 | 0xcbd8 | 0xbfd8 | 0x367 |
WideCharToMultiByte | 0x0 | 0x4010ac | 0xcbdc | 0xbfdc | 0x511 |
CompareStringA | 0x0 | 0x4010b0 | 0xcbe0 | 0xbfe0 | 0x61 |
WriteFile | 0x0 | 0x4010b4 | 0xcbe4 | 0xbfe4 | 0x525 |
GetFileSizeEx | 0x0 | 0x4010b8 | 0xcbe8 | 0xbfe8 | 0x1f1 |
GetLastError | 0x0 | 0x4010bc | 0xcbec | 0xbfec | 0x202 |
lstrlenA | 0x0 | 0x4010c0 | 0xcbf0 | 0xbff0 | 0x54d |
GetProcessHeap | 0x0 | 0x4010c4 | 0xcbf4 | 0xbff4 | 0x24a |
HeapFree | 0x0 | 0x4010c8 | 0xcbf8 | 0xbff8 | 0x2cf |
HeapReAlloc | 0x0 | 0x4010cc | 0xcbfc | 0xbffc | 0x2d2 |
lstrcpyW | 0x0 | 0x4010d0 | 0xcc00 | 0xc000 | 0x548 |
HeapAlloc | 0x0 | 0x4010d4 | 0xcc04 | 0xc004 | 0x2cb |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExW | 0x0 | 0x401000 | 0xcb30 | 0xbf30 | 0x26e |
RegOpenKeyExW | 0x0 | 0x401004 | 0xcb34 | 0xbf34 | 0x261 |
RegCreateKeyExW | 0x0 | 0x401008 | 0xcb38 | 0xbf38 | 0x239 |
RegCloseKey | 0x0 | 0x40100c | 0xcb3c | 0xbf3c | 0x230 |
CryptGenRandom | 0x0 | 0x401010 | 0xcb40 | 0xbf40 | 0xc1 |
CryptReleaseContext | 0x0 | 0x401014 | 0xcb44 | 0xbf44 | 0xcb |
CryptAcquireContextW | 0x0 | 0x401018 | 0xcb48 | 0xbf48 | 0xb1 |
RegSetValueExW | 0x0 | 0x40101c | 0xcb4c | 0xbf4c | 0x27e |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHChangeNotify | 0x0 | 0x4010dc | 0xcc0c | 0xc00c | 0x7f |
ShellExecuteExW | 0x0 | 0x4010e0 | 0xcc10 | 0xc010 | 0x121 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindFileNameW | 0x0 | 0x4010e8 | 0xcc18 | 0xc018 | 0x49 |
PathRemoveFileSpecW | 0x0 | 0x4010ec | 0xcc1c | 0xc01c | 0x8b |
PathAddBackslashW | 0x0 | 0x4010f0 | 0xcc20 | 0xc020 | 0x30 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_aulldiv | 0x0 | 0x4010f8 | 0xcc28 | 0xc028 | 0x4fe |
_alldiv | 0x0 | 0x4010fc | 0xcc2c | 0xc02c | 0x4f6 |
_allrem | 0x0 | 0x401100 | 0xcc30 | 0xc030 | 0x4fa |
_chkstk | 0x0 | 0x401104 | 0xcc34 | 0xc034 | 0x502 |
RtlUnwind | 0x0 | 0x401108 | 0xcc38 | 0xc038 | 0x396 |
NtQueryVirtualMemory | 0x0 | 0x40110c | 0xcc3c | 0xc03c | 0x135 |
C:\Users\All Users\Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\vc_runtimeAdditional_x86.msi.SATANA | Modified File | Stream |
Unknown
|
...
|
C:\Users\All Users\Package Cache\{3c3aafc8-d898-43ec-998f-965ffdae065a}\state.rsm.SATANA | Modified File | Stream |
Unknown
|
...
|
C:\Users\All Users\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages\vcRuntimeMinimum_x86\vc_runtimeMinimum_x86.msi.SATANA | Modified File | Stream |
Unknown
|
...
|
C:\Users\All Users\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages\vcRuntimeMinimum_amd64\cab1.cab.SATANA | Modified File | Stream |
Unknown
|
...
|
C:\Users\Public\Desktop\Mozilla Firefox.lnk | Modified File | Stream |
Unknown
|
...
|
C:\Users\Default\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Stream |
Unknown
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN.url | Modified File | Stream |
Unknown
|
...
|
C:\Users\Public\Music\Sample Music\desktop.ini | Modified File | Stream |
Unknown
|
...
|
C:\Users\All Users\Package Cache\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}v12.0.21005\packages\vcRuntimeMinimum_amd64\vc_runtimeMinimum_x64.msi.SATANA | Modified File | Stream |
Unknown
|
...
|
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms | Modified File | Stream |
Unknown
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg | Modified File | Stream |
Unknown
|
...
|
C:\Users\All Users\Package Cache\{e52a6842-b0ac-476e-b48f-378a97a67346}\VC_redist.x64.exe.SATANA | Modified File | Stream |
Unknown
|
...
|
C:\Users\Default\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Stream |
Unknown
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN Sports.url | Modified File | Stream |
Unknown
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg | Modified File | Stream |
Unknown
|
...
|
C:\Users\All Users\Package Cache\{929FBD26-9020-399B-9A7A-751D61F0B942}v12.0.21005\packages\vcRuntimeAdditional_amd64\vc_runtimeAdditional_x64.msi.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}v12.0.21005\packages\vcRuntimeMinimum_amd64\cab1.cab.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Windows Live\Get Windows Live.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\54050A5F8AE7F0C56E553F0090146C17A1D2BF8D\packages\Patch\x64\Windows6.1-KB2999226-x64.msu.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{e6e75766-da0f-4ba2-9788-6ea593ce702d}\state.rsm.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Mozilla\logs\maintenanceservice-install.log.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\cab1.cab.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Music\Sample Music\Kalimba.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Windows Live\Windows Live Gallery.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{E512788E-C50B-3858-A4B9-73AD5F3F9E93}v14.10.25017\packages\vcRuntimeAdditional_amd64\cab1.cab.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Desktop\Adobe Reader X.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages\vcRuntimeAdditional_x86\vc_runtimeAdditional_x86.msi.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{3c3aafc8-d898-43ec-998f-965ffdae065a}\vcredist_x64.exe.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{68306422-7C57-373F-8860-D26CE4BA2A15}v14.10.25017\packages\vcRuntimeAdditional_x86\cab1.cab.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{e52a6842-b0ac-476e-b48f-378a97a67346}\state.rsm.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{E512788E-C50B-3858-A4B9-73AD5F3F9E93}v14.10.25017\packages\vcRuntimeAdditional_amd64\vc_runtimeAdditional_x64.msi.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\vc_runtimeMinimum_x86.msi.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Recorded TV\Sample Media\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{8D4F7A6D-6B81-3DC8-9C21-6008E4866727}v14.10.25017\packages\vcRuntimeMinimum_amd64\cab1.cab.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Adobe\ARM\Reader_10.0.0\AdbeRdrUpd10116_MUI.msp.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{f325f05b-f963-4640-a43b-c8a494cdda0f}\VC_redist.x86.exe.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{8D4F7A6D-6B81-3DC8-9C21-6008E4866727}v14.10.25017\packages\vcRuntimeMinimum_amd64\vc_runtimeMinimum_x64.msi.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages\vcRuntimeMinimum_x86\cab1.cab.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Music\Sample Music\Sleep Away.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Windows Live\Windows Live Spaces.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{68306422-7C57-373F-8860-D26CE4BA2A15}v14.10.25017\packages\vcRuntimeAdditional_x86\vc_runtimeAdditional_x86.msi.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{929FBD26-9020-399B-9A7A-751D61F0B942}v12.0.21005\packages\vcRuntimeAdditional_amd64\cab1.cab.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages\vcRuntimeMinimum_amd64\vc_runtimeMinimum_x64.msi.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\cab1.cab.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Sun\Java\Java Update\jaureglist.xml.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Desktop\Google Chrome.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{582EA838-9199-3518-A05C-DB09462F68EC}v14.10.25017\packages\vcRuntimeMinimum_x86\cab1.cab.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\IconCache.db | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{f325f05b-f963-4640-a43b-c8a494cdda0f}\state.rsm.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Videos\Sample Videos\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\42D5BEC7DDFBD49E76467529CBC2868987BF8460\packages\Patch\x64\Windows6.1-KB2999226-x64.msu.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Saved Games\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSNBC News.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Recorded TV\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Libraries\RecordedTV.library-ms | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Searches\Everywhere.search-ms | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Adobe\ARM\Reader_10.0.0\AdbeRdrUpd10110_MUI.msp.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Adobe\ARM\Reader_10.0.0\AdbeRdrSecUpd10111.msp.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64\vc_runtimeAdditional_x64.msi.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages\vcRuntimeAdditional_x86\cab1.cab.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Windows Live\Windows Live Mail.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN Autos.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{e6e75766-da0f-4ba2-9788-6ea593ce702d}\vcredist_x86.exe.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN Money.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{582EA838-9199-3518-A05C-DB09462F68EC}v14.10.25017\packages\vcRuntimeMinimum_x86\vc_runtimeMinimum_x86.msi.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Searches\Indexed Locations.search-ms | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Links\Web Slice Gallery.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Links\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\All Users\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64\cab1.cab.SATANA | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Contacts\Administrator.contact | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Links\RecentPlaces.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\tzbtqw.exe | Created File | Unknown |
Not Queried
|
...
|
C:\Users\Public\0A643CC0B2786E0182A9C297C25EDEEB6DD44BB0E8EAA993679B4A37C364560A | Created File | Text |
Not Queried
|
...
|