VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Wiper, Trojan |
cprogramdatamicrosoftwindowsstart menuprogramsstartup1saas.exe12.exe
Windows Exe (x86-32)
Created at 2019-06-27T18:45:00
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cprogramdatamicrosoftwindowsstart menuprogramsstartup1saas.exe12.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-06-12 19:04 (UTC+2) |
Last Seen | 2019-06-16 21:54 (UTC+2) |
Names | Win32.Trojan.Phobos |
Families | Phobos |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x406652 |
Size Of Code | 0x9c00 |
Size Of Initialized Data | 0x4600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-05-14 10:57:04+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x9a08 | 0x9c00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.51 |
.rdata | 0x40b000 | 0x25e0 | 0x2600 | 0xa000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.9 |
.data | 0x40e000 | 0x1e44 | 0x1200 | 0xc600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.22 |
.rsrc | 0x410000 | 0x1b4 | 0x200 | 0xd800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.09 |
.reloc | 0x411000 | 0xa8e | 0xc00 | 0xda00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.23 |
.cdata | 0x412000 | 0x34bc | 0x3600 | 0xe600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.89 |
Imports (6)
»
MPR.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetOpenEnumW | 0x0 | 0x40b1b8 | 0xcd40 | 0xbd40 | 0x3d |
WNetEnumResourceW | 0x0 | 0x40b1bc | 0xcd44 | 0xbd44 | 0x1c |
WNetCloseEnum | 0x0 | 0x40b1c0 | 0xcd48 | 0xbd48 | 0x10 |
WS2_32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
htonl | 0x8 | 0x40b1dc | 0xcd64 | 0xbd64 | - |
KERNEL32.dll (94)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WaitForMultipleObjects | 0x0 | 0x40b03c | 0xcbc4 | 0xbbc4 | 0x4f7 |
CloseHandle | 0x0 | 0x40b040 | 0xcbc8 | 0xbbc8 | 0x52 |
CreateThread | 0x0 | 0x40b044 | 0xcbcc | 0xbbcc | 0xb5 |
SetEvent | 0x0 | 0x40b048 | 0xcbd0 | 0xbbd0 | 0x459 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40b04c | 0xcbd4 | 0xbbd4 | 0x2e3 |
LeaveCriticalSection | 0x0 | 0x40b050 | 0xcbd8 | 0xbbd8 | 0x339 |
EnterCriticalSection | 0x0 | 0x40b054 | 0xcbdc | 0xbbdc | 0xee |
ResetEvent | 0x0 | 0x40b058 | 0xcbe0 | 0xbbe0 | 0x40f |
CreateEventW | 0x0 | 0x40b05c | 0xcbe4 | 0xbbe4 | 0x85 |
DeleteCriticalSection | 0x0 | 0x40b060 | 0xcbe8 | 0xbbe8 | 0xd1 |
CreateMutexW | 0x0 | 0x40b064 | 0xcbec | 0xbbec | 0x9e |
CreateProcessW | 0x0 | 0x40b068 | 0xcbf0 | 0xbbf0 | 0xa8 |
GetCurrentProcess | 0x0 | 0x40b06c | 0xcbf4 | 0xbbf4 | 0x1c0 |
SetHandleInformation | 0x0 | 0x40b070 | 0xcbf8 | 0xbbf8 | 0x470 |
OpenProcess | 0x0 | 0x40b074 | 0xcbfc | 0xbbfc | 0x380 |
GetLocaleInfoW | 0x0 | 0x40b078 | 0xcc00 | 0xbc00 | 0x206 |
TerminateProcess | 0x0 | 0x40b07c | 0xcc04 | 0xbc04 | 0x4c0 |
OpenMutexW | 0x0 | 0x40b080 | 0xcc08 | 0xbc08 | 0x37d |
GetProcAddress | 0x0 | 0x40b084 | 0xcc0c | 0xbc0c | 0x245 |
Process32FirstW | 0x0 | 0x40b088 | 0xcc10 | 0xbc10 | 0x396 |
GetExitCodeThread | 0x0 | 0x40b08c | 0xcc14 | 0xbc14 | 0x1e0 |
CreatePipe | 0x0 | 0x40b090 | 0xcc18 | 0xbc18 | 0xa1 |
CreateFileW | 0x0 | 0x40b094 | 0xcc1c | 0xbc1c | 0x8f |
GetModuleHandleA | 0x0 | 0x40b098 | 0xcc20 | 0xbc20 | 0x215 |
CreateToolhelp32Snapshot | 0x0 | 0x40b09c | 0xcc24 | 0xbc24 | 0xbe |
ReleaseMutex | 0x0 | 0x40b0a0 | 0xcc28 | 0xbc28 | 0x3fa |
GetVersion | 0x0 | 0x40b0a4 | 0xcc2c | 0xbc2c | 0x2a2 |
GetVolumeInformationW | 0x0 | 0x40b0a8 | 0xcc30 | 0xbc30 | 0x2a7 |
ExpandEnvironmentStringsW | 0x0 | 0x40b0ac | 0xcc34 | 0xbc34 | 0x11d |
GetModuleFileNameW | 0x0 | 0x40b0b0 | 0xcc38 | 0xbc38 | 0x214 |
FindClose | 0x0 | 0x40b0b4 | 0xcc3c | 0xbc3c | 0x12e |
FindNextFileW | 0x0 | 0x40b0b8 | 0xcc40 | 0xbc40 | 0x145 |
FindFirstFileW | 0x0 | 0x40b0bc | 0xcc44 | 0xbc44 | 0x139 |
SetEndOfFile | 0x0 | 0x40b0c0 | 0xcc48 | 0xbc48 | 0x453 |
SetFilePointerEx | 0x0 | 0x40b0c4 | 0xcc4c | 0xbc4c | 0x467 |
GetFileAttributesW | 0x0 | 0x40b0c8 | 0xcc50 | 0xbc50 | 0x1ea |
ReadFile | 0x0 | 0x40b0cc | 0xcc54 | 0xbc54 | 0x3c0 |
GetFileSizeEx | 0x0 | 0x40b0d0 | 0xcc58 | 0xbc58 | 0x1f1 |
MoveFileW | 0x0 | 0x40b0d4 | 0xcc5c | 0xbc5c | 0x363 |
DeleteFileW | 0x0 | 0x40b0d8 | 0xcc60 | 0xbc60 | 0xd6 |
SetFileAttributesW | 0x0 | 0x40b0dc | 0xcc64 | 0xbc64 | 0x461 |
IsDebuggerPresent | 0x0 | 0x40b0e0 | 0xcc68 | 0xbc68 | 0x300 |
CopyFileW | 0x0 | 0x40b0e4 | 0xcc6c | 0xbc6c | 0x75 |
Sleep | 0x0 | 0x40b0e8 | 0xcc70 | 0xbc70 | 0x4b2 |
TerminateThread | 0x0 | 0x40b0ec | 0xcc74 | 0xbc74 | 0x4c1 |
HeapSize | 0x0 | 0x40b0f0 | 0xcc78 | 0xbc78 | 0x2d4 |
WriteFile | 0x0 | 0x40b0f4 | 0xcc7c | 0xbc7c | 0x525 |
GetTickCount | 0x0 | 0x40b0f8 | 0xcc80 | 0xbc80 | 0x293 |
GetLogicalDrives | 0x0 | 0x40b0fc | 0xcc84 | 0xbc84 | 0x209 |
GetComputerNameW | 0x0 | 0x40b100 | 0xcc88 | 0xbc88 | 0x18f |
WaitForSingleObject | 0x0 | 0x40b104 | 0xcc8c | 0xbc8c | 0x4f9 |
LoadLibraryW | 0x0 | 0x40b108 | 0xcc90 | 0xbc90 | 0x33f |
MultiByteToWideChar | 0x0 | 0x40b10c | 0xcc94 | 0xbc94 | 0x367 |
RtlUnwind | 0x0 | 0x40b110 | 0xcc98 | 0xbc98 | 0x418 |
Process32NextW | 0x0 | 0x40b114 | 0xcc9c | 0xbc9c | 0x398 |
UnhandledExceptionFilter | 0x0 | 0x40b118 | 0xcca0 | 0xbca0 | 0x4d3 |
GetSystemTimeAsFileTime | 0x0 | 0x40b11c | 0xcca4 | 0xbca4 | 0x279 |
GetLastError | 0x0 | 0x40b120 | 0xcca8 | 0xbca8 | 0x202 |
HeapFree | 0x0 | 0x40b124 | 0xccac | 0xbcac | 0x2cf |
HeapAlloc | 0x0 | 0x40b128 | 0xccb0 | 0xbcb0 | 0x2cb |
HeapReAlloc | 0x0 | 0x40b12c | 0xccb4 | 0xbcb4 | 0x2d2 |
GetCommandLineA | 0x0 | 0x40b130 | 0xccb8 | 0xbcb8 | 0x186 |
HeapSetInformation | 0x0 | 0x40b134 | 0xccbc | 0xbcbc | 0x2d3 |
GetStartupInfoW | 0x0 | 0x40b138 | 0xccc0 | 0xbcc0 | 0x263 |
HeapCreate | 0x0 | 0x40b13c | 0xccc4 | 0xbcc4 | 0x2cd |
GetModuleHandleW | 0x0 | 0x40b140 | 0xccc8 | 0xbcc8 | 0x218 |
ExitProcess | 0x0 | 0x40b144 | 0xcccc | 0xbccc | 0x119 |
DecodePointer | 0x0 | 0x40b148 | 0xccd0 | 0xbcd0 | 0xca |
GetStdHandle | 0x0 | 0x40b14c | 0xccd4 | 0xbcd4 | 0x264 |
EncodePointer | 0x0 | 0x40b150 | 0xccd8 | 0xbcd8 | 0xea |
TlsAlloc | 0x0 | 0x40b154 | 0xccdc | 0xbcdc | 0x4c5 |
TlsGetValue | 0x0 | 0x40b158 | 0xcce0 | 0xbce0 | 0x4c7 |
TlsSetValue | 0x0 | 0x40b15c | 0xcce4 | 0xbce4 | 0x4c8 |
TlsFree | 0x0 | 0x40b160 | 0xcce8 | 0xbce8 | 0x4c6 |
InterlockedIncrement | 0x0 | 0x40b164 | 0xccec | 0xbcec | 0x2ef |
SetLastError | 0x0 | 0x40b168 | 0xccf0 | 0xbcf0 | 0x473 |
GetCurrentThreadId | 0x0 | 0x40b16c | 0xccf4 | 0xbcf4 | 0x1c5 |
InterlockedDecrement | 0x0 | 0x40b170 | 0xccf8 | 0xbcf8 | 0x2eb |
IsProcessorFeaturePresent | 0x0 | 0x40b174 | 0xccfc | 0xbcfc | 0x304 |
GetCPInfo | 0x0 | 0x40b178 | 0xcd00 | 0xbd00 | 0x172 |
GetACP | 0x0 | 0x40b17c | 0xcd04 | 0xbd04 | 0x168 |
GetOEMCP | 0x0 | 0x40b180 | 0xcd08 | 0xbd08 | 0x237 |
IsValidCodePage | 0x0 | 0x40b184 | 0xcd0c | 0xbd0c | 0x30a |
LCMapStringW | 0x0 | 0x40b188 | 0xcd10 | 0xbd10 | 0x32d |
GetStringTypeW | 0x0 | 0x40b18c | 0xcd14 | 0xbd14 | 0x269 |
SetUnhandledExceptionFilter | 0x0 | 0x40b190 | 0xcd18 | 0xbd18 | 0x4a5 |
GetModuleFileNameA | 0x0 | 0x40b194 | 0xcd1c | 0xbd1c | 0x213 |
FreeEnvironmentStringsW | 0x0 | 0x40b198 | 0xcd20 | 0xbd20 | 0x161 |
WideCharToMultiByte | 0x0 | 0x40b19c | 0xcd24 | 0xbd24 | 0x511 |
GetEnvironmentStringsW | 0x0 | 0x40b1a0 | 0xcd28 | 0xbd28 | 0x1da |
SetHandleCount | 0x0 | 0x40b1a4 | 0xcd2c | 0xbd2c | 0x46f |
GetFileType | 0x0 | 0x40b1a8 | 0xcd30 | 0xbd30 | 0x1f3 |
QueryPerformanceCounter | 0x0 | 0x40b1ac | 0xcd34 | 0xbd34 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x40b1b0 | 0xcd38 | 0xbd38 | 0x1c1 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetShellWindow | 0x0 | 0x40b1d0 | 0xcd58 | 0xbd58 | 0x179 |
GetWindowThreadProcessId | 0x0 | 0x40b1d4 | 0xcd5c | 0xbd5c | 0x1a4 |
ADVAPI32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DuplicateTokenEx | 0x0 | 0x40b000 | 0xcb88 | 0xbb88 | 0xdf |
CryptDecrypt | 0x0 | 0x40b004 | 0xcb8c | 0xbb8c | 0xb4 |
CryptDestroyKey | 0x0 | 0x40b008 | 0xcb90 | 0xbb90 | 0xb7 |
CryptEncrypt | 0x0 | 0x40b00c | 0xcb94 | 0xbb94 | 0xba |
CryptImportKey | 0x0 | 0x40b010 | 0xcb98 | 0xbb98 | 0xca |
CryptGenRandom | 0x0 | 0x40b014 | 0xcb9c | 0xbb9c | 0xc1 |
CryptSetKeyParam | 0x0 | 0x40b018 | 0xcba0 | 0xbba0 | 0xcd |
CryptAcquireContextW | 0x0 | 0x40b01c | 0xcba4 | 0xbba4 | 0xb1 |
RegSetValueExW | 0x0 | 0x40b020 | 0xcba8 | 0xbba8 | 0x27e |
RegCloseKey | 0x0 | 0x40b024 | 0xcbac | 0xbbac | 0x230 |
RegOpenKeyExW | 0x0 | 0x40b028 | 0xcbb0 | 0xbbb0 | 0x261 |
RegQueryValueExW | 0x0 | 0x40b02c | 0xcbb4 | 0xbbb4 | 0x26e |
GetTokenInformation | 0x0 | 0x40b030 | 0xcbb8 | 0xbbb8 | 0x15a |
OpenProcessToken | 0x0 | 0x40b034 | 0xcbbc | 0xbbbc | 0x1f7 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteExW | 0x0 | 0x40b1c8 | 0xcd50 | 0xbd50 | 0x121 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
cprogramdatamicrosoftwindowsstart menuprogramsstartup1saas.exe12.exe | 1 | 0x012A0000 | 0x012B5FFF | Relevant Image | - | 32-bit | - |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Ulise.36831 |
Malicious
|
\\?\C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\BOOTSTAT.DAT.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\BOOTSECT.BAK.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\ADO210.CHM.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\README.HTM.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUI.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUISet.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\ExcelMUI.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\GrooveMUI.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\InfoPathMUI.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\BRANDING.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUI.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUISet.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSCONFIG.CHM.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10O.CHM.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10R.CHM.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OCT.CHM.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\Office32MUI.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.WW\Office32WW.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\OneNoteMUI.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.CHM.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\OutlookMUI.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\PowerPointMUI.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\PrjProrWW.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.en\Proof.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.fr\Proof.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.es\Proof.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\Proofing.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\ProPlusrWW.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\PublisherMUI.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\VisioMUI.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\VisiorWW.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\WordMUI.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\MCABOUT.HTM.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\DATES.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\PHONE.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\TIME.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\BASMLA.XSL.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.DAT.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\PREVIEW.GIF.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\THMBNAIL.PNG.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\SETUP.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\ProjectMUI.XML.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Stationery\Desktop.ini.id[9C354B42-1096].[lockhelp@qq.com].acute | Dropped File | Stream |
Not Queried
|
...
|
»