Dynamic Analysis Report |
Classification: |
Dropper
Ransomware
|
Threat Names: |
Dharma
Trojan.GenericKD.43693405
Gen:Variant.Ransom.Phobos.62
...
|
unS.exe
Created at 2020-08-21T06:39:00
Remarks (2/2)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "3 minutes, 27 seconds" to "50 seconds" to reveal dormant functionality.
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
Severity |
Blacklisted
|
Names | Mal/Generic-S |
Image Base | 0x400000 |
Entry Point | 0x46280e |
Size Of Code | 0x60a00 |
Size Of Initialized Data | 0xa00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-08-19 12:21:06+00:00 |
Assembly Version | 34.31.0.0 |
Comments | Crystal Lagoons Lake |
CompanyName | Rancho Mirage |
FileDescription | Crystal Lagoons |
FileVersion | 34.31.0.0 |
InternalName | unS.exe |
LegalCopyright | Rancho Mirage 2021 |
LegalTrademarks | Crystal Lagoons |
OriginalFilename | unS.exe |
ProductName | Crystal Lagoons |
ProductVersion | 34.31.0.0 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x60814 | 0x60a00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.37 |
.rsrc | 0x464000 | 0x618 | 0x800 | 0x60c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.47 |
.reloc | 0x466000 | 0xc | 0x200 | 0x61400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x627e0 | 0x609e0 | 0x0 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
uns.exe | 1 | 0x00F90000 | 0x00FF7FFF | Relevant Image | 32-bit | - |
...
|
|||
buffer | 1 | 0x01870400 | 0x0188E9FF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x01870178 | 0x0187017F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x018701A0 | 0x018701A7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x018701C8 | 0x018701CF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x018701F0 | 0x018701F7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x01870218 | 0x0187021F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F35E | 0x0188F368 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F352 | 0x0188F35C | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188EA00 | 0x0188EA47 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F36C | 0x0188F36F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F390 | 0x0188F397 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F398 | 0x0188F39B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F39C | 0x0188F3A3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3A4 | 0x0188F3A7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3A8 | 0x0188F3AB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3AC | 0x0188F3AF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3B0 | 0x0188F3B7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3B8 | 0x0188F3BB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3BC | 0x0188F3C3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3C4 | 0x0188F3C7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3C8 | 0x0188F3CB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3CC | 0x0188F3D3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3D4 | 0x0188F3D7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3D8 | 0x0188F3DB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3DC | 0x0188F3E3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3E4 | 0x0188F3E7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3E8 | 0x0188F3EB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3EC | 0x0188F3F3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3F4 | 0x0188F3F7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3F8 | 0x0188F3FB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F3FC | 0x0188F3FF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F400 | 0x0188F407 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F408 | 0x0188F40B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F40C | 0x0188F40F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F410 | 0x0188F417 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F418 | 0x0188F41B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x0188F41C | 0x0188F41F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 2 | 0x00400000 | 0x00412FFF | First Execution | 32-bit | 0x00402E94 |
...
|
|||
uns.exe | 2 | 0x00D60000 | 0x00DC7FFF | Relevant Image | 32-bit | - |
...
|
|||
buffer | 2 | 0x00400000 | 0x00412FFF | Content Changed | 32-bit | 0x0040731B |
...
|
|||
buffer | 2 | 0x00400000 | 0x00412FFF | Content Changed | 32-bit | 0x004059F4 |
...
|
|||
uns.exe | 1 | 0x00F90000 | 0x00FF7FFF | Process Termination | 32-bit | - |
...
|
|||
uns.exe | 1 | 0x00F90000 | 0x00FF7FFF | Final Dump | 32-bit | - |
...
|
|||
uns.exe | 2 | 0x00D60000 | 0x00DC7FFF | Final Dump | 32-bit | - |
...
|
|||
uns.exe | 3 | 0x00D70000 | 0x00DD7FFF | Relevant Image | 32-bit | - |
...
|
|||
uns.exe | 7 | 0x00620000 | 0x00687FFF | Relevant Image | 32-bit | - |
...
|
|||
uns.exe | 8 | 0x005F0000 | 0x00657FFF | Relevant Image | 32-bit | - |
...
|
|||
buffer | 8 | 0x04830400 | 0x0484E9FF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026A0400 | 0x026BE9FF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x04830178 | 0x0483017F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x048301A0 | 0x048301A7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x048301C8 | 0x048301CF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x048301F0 | 0x048301F7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x04830218 | 0x0483021F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F35E | 0x0484F368 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F352 | 0x0484F35C | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484EA00 | 0x0484EA47 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F36C | 0x0484F36F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F390 | 0x0484F397 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F398 | 0x0484F39B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F39C | 0x0484F3A3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3A4 | 0x0484F3A7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3A8 | 0x0484F3AB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3AC | 0x0484F3AF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3B0 | 0x0484F3B7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3B8 | 0x0484F3BB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3BC | 0x0484F3C3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3C4 | 0x0484F3C7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3C8 | 0x0484F3CB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3CC | 0x0484F3D3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3D4 | 0x0484F3D7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3D8 | 0x0484F3DB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3DC | 0x0484F3E3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3E4 | 0x0484F3E7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3E8 | 0x0484F3EB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3EC | 0x0484F3F3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3F4 | 0x0484F3F7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3F8 | 0x0484F3FB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F3FC | 0x0484F3FF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F400 | 0x0484F407 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F408 | 0x0484F40B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F40C | 0x0484F40F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F410 | 0x0484F417 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F418 | 0x0484F41B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 8 | 0x0484F41C | 0x0484F41F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026A0178 | 0x026A017F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026A01A0 | 0x026A01A7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026A01C8 | 0x026A01CF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026A01F0 | 0x026A01F7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026A0218 | 0x026A021F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF35E | 0x026BF368 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF352 | 0x026BF35C | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BEA00 | 0x026BEA47 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF36C | 0x026BF36F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF390 | 0x026BF397 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF398 | 0x026BF39B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF39C | 0x026BF3A3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3A4 | 0x026BF3A7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3A8 | 0x026BF3AB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3AC | 0x026BF3AF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3B0 | 0x026BF3B7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3B8 | 0x026BF3BB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3BC | 0x026BF3C3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3C4 | 0x026BF3C7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3C8 | 0x026BF3CB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3CC | 0x026BF3D3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3D4 | 0x026BF3D7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3D8 | 0x026BF3DB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3DC | 0x026BF3E3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3E4 | 0x026BF3E7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3E8 | 0x026BF3EB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3EC | 0x026BF3F3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3F4 | 0x026BF3F7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3F8 | 0x026BF3FB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF3FC | 0x026BF3FF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF400 | 0x026BF407 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF408 | 0x026BF40B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF40C | 0x026BF40F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF410 | 0x026BF417 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF418 | 0x026BF41B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 7 | 0x026BF41C | 0x026BF41F | Marked Executable | 32-bit | - |
...
|
|||
uns.exe | 9 | 0x00480000 | 0x004E7FFF | Relevant Image | 32-bit | - |
...
|
|||
uns.exe | 8 | 0x005F0000 | 0x00657FFF | Process Termination | 32-bit | - |
...
|
|||
uns.exe | 10 | 0x00E40000 | 0x00EA7FFF | Relevant Image | 32-bit | - |
...
|
|||
uns.exe | 7 | 0x00620000 | 0x00687FFF | Process Termination | 32-bit | - |
...
|
|||
uns.exe | 11 | 0x009D0000 | 0x00A37FFF | Relevant Image | 32-bit | - |
...
|
|||
buffer | 11 | 0x029D0400 | 0x029EE9FF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029D0178 | 0x029D017F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029D01A0 | 0x029D01A7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029D01C8 | 0x029D01CF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029D01F0 | 0x029D01F7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029D0218 | 0x029D021F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF35E | 0x029EF368 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF352 | 0x029EF35C | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EEA00 | 0x029EEA47 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF36C | 0x029EF36F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF390 | 0x029EF397 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF398 | 0x029EF39B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF39C | 0x029EF3A3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3A4 | 0x029EF3A7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3A8 | 0x029EF3AB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3AC | 0x029EF3AF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3B0 | 0x029EF3B7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3B8 | 0x029EF3BB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3BC | 0x029EF3C3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3C4 | 0x029EF3C7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3C8 | 0x029EF3CB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3CC | 0x029EF3D3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3D4 | 0x029EF3D7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3D8 | 0x029EF3DB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3DC | 0x029EF3E3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3E4 | 0x029EF3E7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3E8 | 0x029EF3EB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3EC | 0x029EF3F3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3F4 | 0x029EF3F7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3F8 | 0x029EF3FB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF3FC | 0x029EF3FF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF400 | 0x029EF407 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF408 | 0x029EF40B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF40C | 0x029EF40F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF410 | 0x029EF417 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF418 | 0x029EF41B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 11 | 0x029EF41C | 0x029EF41F | Marked Executable | 32-bit | - |
...
|
|||
uns.exe | 14 | 0x008D0000 | 0x00937FFF | Relevant Image | 32-bit | - |
...
|
|||
uns.exe | 11 | 0x009D0000 | 0x00A37FFF | Process Termination | 32-bit | - |
...
|
|||
uns.exe | 9 | 0x00480000 | 0x004E7FFF | Final Dump | 32-bit | - |
...
|
|||
uns.exe | 10 | 0x00E40000 | 0x00EA7FFF | Final Dump | 32-bit | - |
...
|
|||
uns.exe | 14 | 0x008D0000 | 0x00937FFF | Final Dump | 32-bit | - |
...
|
Threat Name | Severity |
---|---|
Trojan.GenericKD.43693405 |
Malicious
|
\\?\C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini | Modified File | Stream |
Whitelisted
|
...
|
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\1033\SetupResources.dll | Modified File | Stream |
Whitelisted
|
...
|
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\1041\SetupResources.dll | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\1042\SetupResources.dll | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Text |
Whitelisted
|
...
|
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\1049\SetupResources.dll | Modified File | Binary |
Whitelisted
|
...
|
Severity |
Whitelisted
|
Image Base | 0x10000000 |
Size Of Initialized Data | 0x2c00 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2010-03-18 11:22:44+00:00 |
CompanyName | Корпорация Майкрософт |
FileDescription | Вспомогательная DLL-библиотека ресурсов установки |
FileVersion | 10.0.30319.1 built by: RTMRel |
InternalName | SetupResources.dll |
LegalCopyright | © Корпорация Майкрософт (Microsoft Corp.). Все права защищены. |
OriginalFilename | SetupResources.dll |
ProductName | Microsoft® .NET Framework |
ProductVersion | 10.0.30319.1 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x10001000 | 0x47 | 0x200 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.94 |
.rsrc | 0x10002000 | 0x3000 | 0x2a00 | 0x600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.19 |
Issued by | Microsoft Corporation |
Parent Certificate | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2009-12-07 22:40:29+00:00 |
Valid Until | 2011-03-07 22:40:29+00:00 |
Algorithm | sha1_rsa |
Serial Number | 61 01 CF 3E 00 00 00 00 00 0F |
Thumbprint | 96 17 09 4A 1C FB 59 AE 7C 1F 7D FD B6 73 9E 4E 7C 40 50 8F |
Issued by | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2007-08-22 22:31:02+00:00 |
Valid Until | 2012-08-25 07:00:00+00:00 |
Algorithm | sha1_rsa |
Serial Number | 2E AB 11 DC 50 FF 5C 9D CB C0 |
Thumbprint | 30 36 E3 B2 5B 88 A5 5B 86 FC 90 E6 E9 EA AD 50 81 44 51 66 |
\\?\C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Whitelisted
|
...
|
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\3076\SetupResources.dll | Modified File | Stream |
Whitelisted
|
...
|
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Whitelisted
|
...
|
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Whitelisted
|
...
|
Severity |
Whitelisted
|
\\?\C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\sqmapi.dll | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Whitelisted
|
...
|
Severity |
Whitelisted
|
\\?\C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Whitelisted
|
...
|
Severity |
Whitelisted
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Caches\cversions.3.db | Modified File | Stream |
Whitelisted
|
...
|
Severity |
Whitelisted
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Explorer\iconcache_custom_stream.db | Modified File | Stream |
Whitelisted
|
...
|
Severity |
Whitelisted
|
\\?\C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\DataStore\Data\nouser1\120712-0049\DBStore\spartan.edb | Modified File | Stream |
Whitelisted
|
...
|
Severity |
Whitelisted
|
\\?\C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\MediaDb.v1.sqlite | Modified File | Stream |
Whitelisted
|
...
|
\\?\C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZLIB.ACCDE | Dropped File | Stream |
Whitelisted
|
...
|
\\?\C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1030\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\netfx_Extended_x64.msi | Modified File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Unknown
|
...
|
c:\users\fd1hvy\appdata\roaming\microsoft\windows\recent\automaticdestinations\f01b4d95cf55d32a.automaticdestinations-ms | Modified File | OLE Compound |
Unknown
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000031.db | Modified File | Stream |
Unknown
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000020.db | Modified File | Stream |
Unknown
|
...
|
c:\users\fd1hvy\appdata\roaming\microsoft\windows\recent\automaticdestinations\f01b4d95cf55d32a.automaticdestinations-ms | Modified File | OLE Compound |
Unknown
|
...
|
\\?\C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\$GetCurrent\SafeOS\preoobe.cmd.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Binary |
Unknown
|
...
|
\\?\C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1025\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1028\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1028\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1029\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1029\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1031\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Binary |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1031\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1032\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1033\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1036\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1037\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1037\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1037\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1041\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1042\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1042\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1044\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1044\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1044\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1045\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1045\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1046\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1053\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\1055\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\2052\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\2070\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\3082\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\3082\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\DHtmlHeader.html.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\Extended\UiInfo.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\Rotate2.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\Rotate3.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\Rotate6.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\Rotate4.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\Rotate8.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\Save.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\Setup.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\stop.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\netfx_Core_x64.msi.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\netfx_Extended.mzz.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\netfx_Extended_x64.msi.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\netfx_Extended_x86.msi.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\Setup.exe.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\SetupUi.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\SplashScreen.bmp.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\sqmapi.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\UiInfo.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\watermark.bmp.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\HardwareEvents.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Internet Explorer.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
C:\Users\FD1HVy\AppData\Local\Temp\B4197730 | Dropped File | Binary |
Unknown
|
...
|
Image Base | 0x400000 |
Entry Point | 0x401000 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 1970-01-01 00:00:00+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x32f | 0x32f | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 2.74 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitProcess | 0x0 | 0x4010d0 | 0x10e8 | 0x2e8 | 0x0 |
CreateProcessW | 0x0 | 0x4010d8 | 0x10f0 | 0x2f0 | 0x0 |
\\?\C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-Store%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Security.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Setup.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Internet Explorer\Indexed DB\AppQuota.edb.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Explorer\iconcache_1280.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Explorer\iconcache_sr.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\MediaDb.v1.sqlite.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Unknown
|
...
|
C:\Users\FD1HVy\AppData\Local\Temp\B4197730 | Dropped File | Binary |
Unknown
|
...
|
Image Base | 0x400000 |
Entry Point | 0x401000 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 1970-01-01 00:00:00+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x32f | 0x32f | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 2.91 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitProcess | 0x0 | 0x4010d0 | 0x10e8 | 0x2e8 | 0x0 |
CreateProcessW | 0x0 | 0x4010d8 | 0x10f0 | 0x2f0 | 0x0 |
\\?\C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Batch |
Not Queried
|
...
|
\\?\C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Not Queried
|
...
|
\\?\C:\$GetCurrent\SafeOS\SetupComplete.cmd | Modified File | Batch |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1037\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1032\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1055\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1044\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\3076\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1036\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\SetupEngine.dll | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Setup.exe | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\SetupUtility.exe | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\SetupUi.dll | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Internet Explorer\Indexed DB\AppQuota.edb | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Caches\{2B16BD47-B905-4D30-88C9-B63C603DA134}.3.ver0x0000000000000001.db | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000032.db | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000021.db | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Mozilla\Firefox\Profiles\w7cr0hor.default\OfflineCache\index.sqlite | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AppData\User\Default\Indexed DB\IndexedDB.edb | Modified File | Stream |
Not Queried
|
...
|
c:\users\fd1hvy\appdata\roaming\microsoft\windows\recent\automaticdestinations\f01b4d95cf55d32a.automaticdestinations-ms | Modified File | OLE Compound |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\IndexedDB.edb | Modified File | Stream |
Not Queried
|
...
|
\\?\C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\$Recycle.Bin\S-1-5-18\desktop.ini.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1025\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1025\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1028\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\$GetCurrent\SafeOS\SetupComplete.cmd.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1030\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1029\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1030\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1030\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1032\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1031\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1032\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1033\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1035\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1033\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1035\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1036\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1035\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1036\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1038\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Office\root\Office16\1033\DBSAMPLE.MDB | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Office\root\Office16\1033\DBSAMPLE.MDB.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1038\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1038\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1040\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZLIB.ACCDE.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1040\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1040\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1041\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1042\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1041\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1043\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1043\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1043\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1045\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1046\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1046\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1049\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1053\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1053\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1055\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\1055\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\2052\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\2052\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\2070\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\2070\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\3076\eula.rtf.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\3076\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\3076\SetupResources.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\3082\LocalizedData.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Client\Parameterinfo.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Client\UiInfo.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\DisplayIcon.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Extended\Parameterinfo.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\Rotate1.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\Print.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\Rotate5.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\Rotate7.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\SysReqMet.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\warn.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\header.bmp.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\netfx_Core.mzz.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\netfx_Core_x86.msi.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\ParameterInfo.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\RGB9RAST_x64.msi.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\RGB9Rast_x86.msi.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\SetupEngine.dll.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\SetupUi.xsd.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\SetupUtility.exe.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Strings.xml.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Application.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Key Management Service.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-International%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\System.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Logs\Windows PowerShell.evtx.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\IconCache.db | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\IconCache.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\previews_opt_out.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Caches\cversions.1.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Caches\cversions.3.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Caches\{2B16BD47-B905-4D30-88C9-B63C603DA134}.3.ver0x0000000000000001.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000031.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000032.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000020.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000021.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Explorer\iconcache_1920.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Explorer\iconcache_2560.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Explorer\iconcache_768.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Explorer\iconcache_96.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Explorer\iconcache_custom_stream.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Explorer\iconcache_exif.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Explorer\iconcache_wide.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Explorer\iconcache_wide_alternate.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Mozilla\Firefox\Profiles\w7cr0hor.default\OfflineCache\index.sqlite.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\DataStore\Data\nouser1\120712-0049\DBStore\spartan.edb.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|
\\?\C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AppData\User\Default\Indexed DB\IndexedDB.edb.id[B4197730-2275].[helprecover@foxmail.com].help | Dropped File | Stream |
Not Queried
|
...
|