Dynamic Analysis Report |
Classification: Downloader, Ransomware |
d77378dcc42b912e514d3bd4466cdda050dda9b57799a6c97f70e8489dd8c8d0 (SHA256)
o.exe
Created at 2018-09-24 10:34:00
Notifications (2/3)
Due to a reputation service error, no query could be made to determine the reputation status of file hashes.
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The operating system was rebooted during the analysis.
Remarks
Due to a reputation service error, no query could be made to determine the reputation status of file hashes.
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 bytes |
...
|
This list contains only the embedded files and created files
Filters: |
There are no files for this filter
Filename | Category | Type | Severity | Actions |
---|
Image Base | 0x400000 |
Entry Point | 0x406314 |
Size Of Code | 0x13600 |
Size Of Initialized Data | 0x1c000 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2018-09-24 07:47:02+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x13474 | 0x13600 | 0x400 | cnt_code, mem_execute, mem_read | 6.57 |
.rdata | 0x415000 | 0x6ee0 | 0x7000 | 0x13a00 | cnt_initialized_data, mem_read | 4.59 |
.data | 0x41c000 | 0x138f4 | 0x11c00 | 0x1aa00 | cnt_initialized_data, mem_read, mem_write | 4.86 |
.rsrc | 0x430000 | 0x1e0 | 0x200 | 0x2c600 | cnt_initialized_data, mem_read | 4.7 |
.reloc | 0x431000 | 0x13b4 | 0x1400 | 0x2c800 | cnt_initialized_data, mem_discardable, mem_read | 6.65 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x415094 | 0x1af54 | 0x19954 | 0x11a |
VirtualUnlock | 0x0 | 0x415098 | 0x1af58 | 0x19958 | 0x4f3 |
OpenMutexW | 0x0 | 0x41509c | 0x1af5c | 0x1995c | 0x37d |
GetSystemInfo | 0x0 | 0x4150a0 | 0x1af60 | 0x19960 | 0x273 |
WaitForMultipleObjects | 0x0 | 0x4150a4 | 0x1af64 | 0x19964 | 0x4f7 |
lstrcmpiW | 0x0 | 0x4150a8 | 0x1af68 | 0x19968 | 0x545 |
GetUserDefaultUILanguage | 0x0 | 0x4150ac | 0x1af6c | 0x1996c | 0x29e |
DeleteCriticalSection | 0x0 | 0x4150b0 | 0x1af70 | 0x19970 | 0xd1 |
GetShortPathNameW | 0x0 | 0x4150b4 | 0x1af74 | 0x19974 | 0x261 |
GetWindowsDirectoryW | 0x0 | 0x4150b8 | 0x1af78 | 0x19978 | 0x2af |
GetVolumeInformationW | 0x0 | 0x4150bc | 0x1af7c | 0x1997c | 0x2a7 |
CreateThread | 0x0 | 0x4150c0 | 0x1af80 | 0x19980 | 0xb5 |
lstrcpyA | 0x0 | 0x4150c4 | 0x1af84 | 0x19984 | 0x547 |
ExpandEnvironmentStringsW | 0x0 | 0x4150c8 | 0x1af88 | 0x19988 | 0x11d |
GetTickCount | 0x0 | 0x4150cc | 0x1af8c | 0x1998c | 0x293 |
lstrcmpiA | 0x0 | 0x4150d0 | 0x1af90 | 0x19990 | 0x544 |
Process32FirstW | 0x0 | 0x4150d4 | 0x1af94 | 0x19994 | 0x396 |
Process32NextW | 0x0 | 0x4150d8 | 0x1af98 | 0x19998 | 0x398 |
CreateToolhelp32Snapshot | 0x0 | 0x4150dc | 0x1af9c | 0x1999c | 0xbe |
LeaveCriticalSection | 0x0 | 0x4150e0 | 0x1afa0 | 0x199a0 | 0x339 |
EnterCriticalSection | 0x0 | 0x4150e4 | 0x1afa4 | 0x199a4 | 0xee |
VirtualLock | 0x0 | 0x4150e8 | 0x1afa8 | 0x199a8 | 0x4ee |
FindFirstFileExW | 0x0 | 0x4150ec | 0x1afac | 0x199ac | 0x134 |
WideCharToMultiByte | 0x0 | 0x4150f0 | 0x1afb0 | 0x199b0 | 0x511 |
lstrcmpW | 0x0 | 0x4150f4 | 0x1afb4 | 0x199b4 | 0x542 |
MoveFileW | 0x0 | 0x4150f8 | 0x1afb8 | 0x199b8 | 0x363 |
FindClose | 0x0 | 0x4150fc | 0x1afbc | 0x199bc | 0x12e |
FindNextFileW | 0x0 | 0x415100 | 0x1afc0 | 0x199c0 | 0x145 |
GetSystemTime | 0x0 | 0x415104 | 0x1afc4 | 0x199c4 | 0x277 |
GetNativeSystemInfo | 0x0 | 0x415108 | 0x1afc8 | 0x199c8 | 0x225 |
GetDriveTypeW | 0x0 | 0x41510c | 0x1afcc | 0x199cc | 0x1d3 |
GetDiskFreeSpaceW | 0x0 | 0x415110 | 0x1afd0 | 0x199d0 | 0x1cf |
GetModuleFileNameW | 0x0 | 0x415114 | 0x1afd4 | 0x199d4 | 0x214 |
VerSetConditionMask | 0x0 | 0x415118 | 0x1afd8 | 0x199d8 | 0x4e4 |
VerifyVersionInfoW | 0x0 | 0x41511c | 0x1afdc | 0x199dc | 0x4e8 |
SetLastError | 0x0 | 0x415120 | 0x1afe0 | 0x199e0 | 0x473 |
LoadLibraryA | 0x0 | 0x415124 | 0x1afe4 | 0x199e4 | 0x33c |
LocalAlloc | 0x0 | 0x415128 | 0x1afe8 | 0x199e8 | 0x344 |
GetModuleHandleA | 0x0 | 0x41512c | 0x1afec | 0x199ec | 0x215 |
LocalFree | 0x0 | 0x415130 | 0x1aff0 | 0x199f0 | 0x348 |
GlobalAlloc | 0x0 | 0x415134 | 0x1aff4 | 0x199f4 | 0x2b3 |
MulDiv | 0x0 | 0x415138 | 0x1aff8 | 0x199f8 | 0x366 |
GetTempPathW | 0x0 | 0x41513c | 0x1affc | 0x199fc | 0x285 |
GlobalFree | 0x0 | 0x415140 | 0x1b000 | 0x19a00 | 0x2ba |
FindFirstFileW | 0x0 | 0x415144 | 0x1b004 | 0x19a04 | 0x139 |
ConnectNamedPipe | 0x0 | 0x415148 | 0x1b008 | 0x19a08 | 0x65 |
CreateNamedPipeW | 0x0 | 0x41514c | 0x1b00c | 0x19a0c | 0xa0 |
CreateEventW | 0x0 | 0x415150 | 0x1b010 | 0x19a10 | 0x85 |
GetCurrentProcessId | 0x0 | 0x415154 | 0x1b014 | 0x19a14 | 0x1c1 |
GetFullPathNameW | 0x0 | 0x415158 | 0x1b018 | 0x19a18 | 0x1fb |
SetStdHandle | 0x0 | 0x41515c | 0x1b01c | 0x19a1c | 0x487 |
GetConsoleMode | 0x0 | 0x415160 | 0x1b020 | 0x19a20 | 0x1ac |
GetConsoleCP | 0x0 | 0x415164 | 0x1b024 | 0x19a24 | 0x19a |
FlushFileBuffers | 0x0 | 0x415168 | 0x1b028 | 0x19a28 | 0x157 |
OutputDebugStringW | 0x0 | 0x41516c | 0x1b02c | 0x19a2c | 0x38a |
HeapAlloc | 0x0 | 0x415170 | 0x1b030 | 0x19a30 | 0x2cb |
RtlUnwind | 0x0 | 0x415174 | 0x1b034 | 0x19a34 | 0x418 |
TerminateProcess | 0x0 | 0x415178 | 0x1b038 | 0x19a38 | 0x4c0 |
OpenProcess | 0x0 | 0x41517c | 0x1b03c | 0x19a3c | 0x380 |
InitializeCriticalSection | 0x0 | 0x415180 | 0x1b040 | 0x19a40 | 0x2e2 |
GetDriveTypeA | 0x0 | 0x415184 | 0x1b044 | 0x19a44 | 0x1d2 |
GetCommandLineA | 0x0 | 0x415188 | 0x1b048 | 0x19a48 | 0x186 |
VirtualAlloc | 0x0 | 0x41518c | 0x1b04c | 0x19a4c | 0x4e9 |
GetProcessHeap | 0x0 | 0x415190 | 0x1b050 | 0x19a50 | 0x24a |
GetComputerNameW | 0x0 | 0x415194 | 0x1b054 | 0x19a54 | 0x18f |
WaitForSingleObject | 0x0 | 0x415198 | 0x1b058 | 0x19a58 | 0x4f9 |
SetErrorMode | 0x0 | 0x41519c | 0x1b05c | 0x19a5c | 0x458 |
GetSystemDefaultUILanguage | 0x0 | 0x4151a0 | 0x1b060 | 0x19a60 | 0x26e |
CreateMutexW | 0x0 | 0x4151a4 | 0x1b064 | 0x19a64 | 0x9e |
ExitProcess | 0x0 | 0x4151a8 | 0x1b068 | 0x19a68 | 0x119 |
GetSystemDefaultLangID | 0x0 | 0x4151ac | 0x1b06c | 0x19a6c | 0x26c |
lstrcpyW | 0x0 | 0x4151b0 | 0x1b070 | 0x19a70 | 0x548 |
lstrcatW | 0x0 | 0x4151b4 | 0x1b074 | 0x19a74 | 0x53f |
GetProcAddress | 0x0 | 0x4151b8 | 0x1b078 | 0x19a78 | 0x245 |
GetLastError | 0x0 | 0x4151bc | 0x1b07c | 0x19a7c | 0x202 |
LoadLibraryW | 0x0 | 0x4151c0 | 0x1b080 | 0x19a80 | 0x33f |
GetSystemDirectoryW | 0x0 | 0x4151c4 | 0x1b084 | 0x19a84 | 0x270 |
GetModuleHandleW | 0x0 | 0x4151c8 | 0x1b088 | 0x19a88 | 0x218 |
GetCurrentProcess | 0x0 | 0x4151cc | 0x1b08c | 0x19a8c | 0x1c0 |
LoadLibraryExW | 0x0 | 0x4151d0 | 0x1b090 | 0x19a90 | 0x33e |
VirtualQuery | 0x0 | 0x4151d4 | 0x1b094 | 0x19a94 | 0x4f1 |
MultiByteToWideChar | 0x0 | 0x4151d8 | 0x1b098 | 0x19a98 | 0x367 |
VirtualFree | 0x0 | 0x4151dc | 0x1b09c | 0x19a9c | 0x4ec |
lstrlenA | 0x0 | 0x4151e0 | 0x1b0a0 | 0x19aa0 | 0x54d |
CloseHandle | 0x0 | 0x4151e4 | 0x1b0a4 | 0x19aa4 | 0x52 |
lstrlenW | 0x0 | 0x4151e8 | 0x1b0a8 | 0x19aa8 | 0x54e |
CreateFileW | 0x0 | 0x4151ec | 0x1b0ac | 0x19aac | 0x8f |
ReadFile | 0x0 | 0x4151f0 | 0x1b0b0 | 0x19ab0 | 0x3c0 |
Sleep | 0x0 | 0x4151f4 | 0x1b0b4 | 0x19ab4 | 0x4b2 |
WriteFile | 0x0 | 0x4151f8 | 0x1b0b8 | 0x19ab8 | 0x525 |
LockFile | 0x0 | 0x4151fc | 0x1b0bc | 0x19abc | 0x352 |
UnlockFile | 0x0 | 0x415200 | 0x1b0c0 | 0x19ac0 | 0x4d4 |
SetFilePointerEx | 0x0 | 0x415204 | 0x1b0c4 | 0x19ac4 | 0x467 |
GetStdHandle | 0x0 | 0x415208 | 0x1b0c8 | 0x19ac8 | 0x264 |
LCMapStringW | 0x0 | 0x41520c | 0x1b0cc | 0x19acc | 0x32d |
IsDebuggerPresent | 0x0 | 0x415210 | 0x1b0d0 | 0x19ad0 | 0x300 |
TlsSetValue | 0x0 | 0x415214 | 0x1b0d4 | 0x19ad4 | 0x4c8 |
TlsGetValue | 0x0 | 0x415218 | 0x1b0d8 | 0x19ad8 | 0x4c7 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41521c | 0x1b0dc | 0x19adc | 0x2e3 |
SetUnhandledExceptionFilter | 0x0 | 0x415220 | 0x1b0e0 | 0x19ae0 | 0x4a5 |
UnhandledExceptionFilter | 0x0 | 0x415224 | 0x1b0e4 | 0x19ae4 | 0x4d3 |
GetStringTypeW | 0x0 | 0x415228 | 0x1b0e8 | 0x19ae8 | 0x269 |
HeapFree | 0x0 | 0x41522c | 0x1b0ec | 0x19aec | 0x2cf |
GetModuleHandleExW | 0x0 | 0x415230 | 0x1b0f0 | 0x19af0 | 0x217 |
DecodePointer | 0x0 | 0x415234 | 0x1b0f4 | 0x19af4 | 0xca |
EncodePointer | 0x0 | 0x415238 | 0x1b0f8 | 0x19af8 | 0xea |
GetCurrentThreadId | 0x0 | 0x41523c | 0x1b0fc | 0x19afc | 0x1c5 |
GetCPInfo | 0x0 | 0x415240 | 0x1b100 | 0x19b00 | 0x172 |
GetOEMCP | 0x0 | 0x415244 | 0x1b104 | 0x19b04 | 0x237 |
IsProcessorFeaturePresent | 0x0 | 0x415248 | 0x1b108 | 0x19b08 | 0x304 |
IsValidCodePage | 0x0 | 0x41524c | 0x1b10c | 0x19b0c | 0x30a |
GetACP | 0x0 | 0x415250 | 0x1b110 | 0x19b10 | 0x168 |
WriteConsoleW | 0x0 | 0x415254 | 0x1b114 | 0x19b14 | 0x524 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DrawTextW | 0x0 | 0x415298 | 0x1b158 | 0x19b58 | 0xd0 |
FillRect | 0x0 | 0x41529c | 0x1b15c | 0x19b5c | 0xf6 |
wsprintfA | 0x0 | 0x4152a0 | 0x1b160 | 0x19b60 | 0x332 |
GetDC | 0x0 | 0x4152a4 | 0x1b164 | 0x19b64 | 0x121 |
wsprintfW | 0x0 | 0x4152a8 | 0x1b168 | 0x19b68 | 0x333 |
CreateWindowStationW | 0x0 | 0x4152ac | 0x1b16c | 0x19b6c | 0x70 |
SetProcessWindowStation | 0x0 | 0x4152b0 | 0x1b170 | 0x19b70 | 0x2aa |
SystemParametersInfoW | 0x0 | 0x4152b4 | 0x1b174 | 0x19b74 | 0x2ec |
GetForegroundWindow | 0x0 | 0x4152b8 | 0x1b178 | 0x19b78 | 0x12d |
DrawTextA | 0x0 | 0x4152bc | 0x1b17c | 0x19b7c | 0xcd |
ReleaseDC | 0x0 | 0x4152c0 | 0x1b180 | 0x19b80 | 0x265 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetTextColor | 0x0 | 0x41504c | 0x1af0c | 0x1990c | 0x2a6 |
DeleteDC | 0x0 | 0x415050 | 0x1af10 | 0x19910 | 0xe3 |
GetDeviceCaps | 0x0 | 0x415054 | 0x1af14 | 0x19914 | 0x1cb |
GetDIBits | 0x0 | 0x415058 | 0x1af18 | 0x19918 | 0x1ca |
SetBkColor | 0x0 | 0x41505c | 0x1af1c | 0x1991c | 0x27e |
SetPixel | 0x0 | 0x415060 | 0x1af20 | 0x19920 | 0x29b |
DeleteObject | 0x0 | 0x415064 | 0x1af24 | 0x19924 | 0xe6 |
SelectObject | 0x0 | 0x415068 | 0x1af28 | 0x19928 | 0x277 |
CreateCompatibleDC | 0x0 | 0x41506c | 0x1af2c | 0x1992c | 0x30 |
CreateCompatibleBitmap | 0x0 | 0x415070 | 0x1af30 | 0x19930 | 0x2f |
CreateFontW | 0x0 | 0x415074 | 0x1af34 | 0x19934 | 0x41 |
GetPixel | 0x0 | 0x415078 | 0x1af38 | 0x19938 | 0x204 |
GetStockObject | 0x0 | 0x41507c | 0x1af3c | 0x1993c | 0x20d |
GetBitmapBits | 0x0 | 0x415080 | 0x1af40 | 0x19940 | 0x1a7 |
SetBitmapBits | 0x0 | 0x415084 | 0x1af44 | 0x19944 | 0x27c |
CreateBitmap | 0x0 | 0x415088 | 0x1af48 | 0x19948 | 0x29 |
GetObjectW | 0x0 | 0x41508c | 0x1af4c | 0x1994c | 0x1fd |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetTokenInformation | 0x0 | 0x415000 | 0x1aec0 | 0x198c0 | 0x15a |
GetSidSubAuthorityCount | 0x0 | 0x415004 | 0x1aec4 | 0x198c4 | 0x158 |
GetSidSubAuthority | 0x0 | 0x415008 | 0x1aec8 | 0x198c8 | 0x157 |
OpenProcessToken | 0x0 | 0x41500c | 0x1aecc | 0x198cc | 0x1f7 |
GetUserNameW | 0x0 | 0x415010 | 0x1aed0 | 0x198d0 | 0x165 |
CryptDestroyKey | 0x0 | 0x415014 | 0x1aed4 | 0x198d4 | 0xb7 |
CryptGenKey | 0x0 | 0x415018 | 0x1aed8 | 0x198d8 | 0xc0 |
CryptEncrypt | 0x0 | 0x41501c | 0x1aedc | 0x198dc | 0xba |
CryptImportKey | 0x0 | 0x415020 | 0x1aee0 | 0x198e0 | 0xca |
CryptReleaseContext | 0x0 | 0x415024 | 0x1aee4 | 0x198e4 | 0xcb |
CryptGetKeyParam | 0x0 | 0x415028 | 0x1aee8 | 0x198e8 | 0xc5 |
CryptAcquireContextW | 0x0 | 0x41502c | 0x1aeec | 0x198ec | 0xb1 |
CryptExportKey | 0x0 | 0x415030 | 0x1aef0 | 0x198f0 | 0xbf |
RegSetValueExW | 0x0 | 0x415034 | 0x1aef4 | 0x198f4 | 0x27e |
RegCloseKey | 0x0 | 0x415038 | 0x1aef8 | 0x198f8 | 0x230 |
RegOpenKeyExW | 0x0 | 0x41503c | 0x1aefc | 0x198fc | 0x261 |
RegQueryValueExW | 0x0 | 0x415040 | 0x1af00 | 0x19900 | 0x26e |
RegCreateKeyExW | 0x0 | 0x415044 | 0x1af04 | 0x19904 | 0x239 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathW | 0x0 | 0x415288 | 0x1b148 | 0x19b48 | 0xe1 |
ShellExecuteW | 0x0 | 0x41528c | 0x1b14c | 0x19b4c | 0x122 |
ShellExecuteExW | 0x0 | 0x415290 | 0x1b150 | 0x19b50 | 0x121 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoInitialize | 0x0 | 0x4152ec | 0x1b1ac | 0x19bac | 0x3e |
CoUninitialize | 0x0 | 0x4152f0 | 0x1b1b0 | 0x19bb0 | 0x6c |
CoCreateInstance | 0x0 | 0x4152f4 | 0x1b1b4 | 0x19bb4 | 0x10 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetCloseEnum | 0x0 | 0x41525c | 0x1b11c | 0x19b1c | 0x10 |
WNetOpenEnumW | 0x0 | 0x415260 | 0x1b120 | 0x19b20 | 0x3d |
WNetEnumResourceW | 0x0 | 0x415264 | 0x1b124 | 0x19b24 | 0x1c |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
HttpOpenRequestW | 0x0 | 0x4152c8 | 0x1b188 | 0x19b88 | 0x58 |
InternetOpenW | 0x0 | 0x4152cc | 0x1b18c | 0x19b8c | 0x9a |
InternetCloseHandle | 0x0 | 0x4152d0 | 0x1b190 | 0x19b90 | 0x6b |
HttpQueryInfoA | 0x0 | 0x4152d4 | 0x1b194 | 0x19b94 | 0x59 |
InternetConnectW | 0x0 | 0x4152d8 | 0x1b198 | 0x19b98 | 0x72 |
HttpSendRequestW | 0x0 | 0x4152dc | 0x1b19c | 0x19b9c | 0x5e |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StartXpsPrintJob | 0x0 | 0x4152e4 | 0x1b1a4 | 0x19ba4 | 0x1 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RpcBindingFromStringBindingW | 0x0 | 0x41526c | 0x1b12c | 0x19b2c | 0x15f |
NdrClientCall2 | 0x0 | 0x415270 | 0x1b130 | 0x19b30 | 0x95 |
RpcStringFreeW | 0x0 | 0x415274 | 0x1b134 | 0x19b34 | 0x1f2 |
RpcBindingFree | 0x0 | 0x415278 | 0x1b138 | 0x19b38 | 0x15d |
RpcBindingSetAuthInfoExW | 0x0 | 0x41527c | 0x1b13c | 0x19b3c | 0x16e |
RpcStringBindingComposeW | 0x0 | 0x415280 | 0x1b140 | 0x19b40 | 0x1ee |
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.htm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3785418085-2572485238-895829336-1000\b652534aebe43ee746cbc40ead5a6d17_cdd36b99-6027-4bbf-bf10-e7f8b416e3fb | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\eybr.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0001692D\06_Pictures_rated_4_or_5_stars.wpl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Shades of Blue.htm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\40id.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.htm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\MSNBC News~.feed-ms | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Windows Live\Windows Live Mail.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Adobe\Acrobat\10.0\JavaScripts\glob.settings.js | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.htm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\account{DD8DA3D5-48F0-4F18-846C-50E4200467F0}.oeaccount | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\D1Mcqgb3FDTv-8KryA5.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\LocalMLS_3.wmdb | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0001692D\04_Music_played_in_the_last_month.wpl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.htm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN Sports.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms | Modified File | Stream |
Not Queried
|
...
|
C:\Recovery\94048722-4631-11e7-a593-a98775ceb0ae\boot.sdi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\H5WuKLQ 4 uu.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\jEsyH8xMpokXjc mOu0.ods | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0001692D\12_All_Video.wpl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Feeds Cache\index.dat | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0001692D\01_Music_auto_rated_at_5_stars.wpl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Hand Prints.htm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Temp\ConfigureMachine.log | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\D4hFvv-xbwD80n_k.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Soft Blue.htm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\iaG_GkHNHdnzSAk_0f.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0001692D\08_Video_rated_at_4_or_5_stars.wpl | Modified File | Compressed |
Not Queried
|
...
|
C:\Users\Default\Contacts\Administrator.contact | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Microsoft\HTML Help\hh.dat | Modified File | Stream |
Not Queried
|
...
|
C:\Recovery\94048722-4631-11e7-a593-a98775ceb0ae\Winre.wim | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\5TbJjRTqQcJAG8oUNN.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0001692D\07_TV_recorded_in_the_last_week.wpl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0001692D\09_Music_played_the_most.wpl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Feeds\FeedsStore.feedsdb-ms | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\k34HcmsYrEK4_.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Cav7r34AQxz266BdGIX.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0001692D\02_Music_added_in_the_last_month.wpl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\-vZCBx3T8O8PG8Z7.rtf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\ABdV76mhVKc67XfMG.odp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\g-uvZ0afpQw.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Adobe\Acrobat\10.0\Security\addressbook.acrodata | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Microsoft\Internet Explorer\UserData\Low\3Q4BCXJF\id[1].xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Microsoft\MS Project\14\1033\Global.MPT | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\CmR7tOD7XC.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Backup\new\edb00001.log | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\edbres00001.jrs | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0001692D\11_All_Pictures.wpl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Protect\CREDHIST | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Windows Live\Windows Live Gallery.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.pat | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Green Bubbles.htm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Protect\S-1-5-21-3149542145-3322839065-4058237693-500\Preferred | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN Money.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms | Modified File | Audio |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN Autos.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSNBC News.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\account{91E541D8-6C9E-48C0-AB69-0A7168AA62DE}.oeaccount | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\account{553187ED-CFB2-4763-8DAE-48D3609A76AC}.oeaccount | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0001692D\10_All_Music.wpl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Orange Circles.htm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\edb.log | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0001692D\05_Pictures_taken_in_the_last_month.wpl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\edbres00002.jrs | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Links\Web Slice Gallery.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Adobe\Acrobat\10.0\Security\CRLCache\A9B8213768ADC68AF64FCC6409E8BE414726687F.crl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3785418085-2572485238-895829336-1000\83aa4cc77f591dfc2374580bbd95f6ba_cdd36b99-6027-4bbf-bf10-e7f8b416e3fb | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Microsoft\Internet Explorer\UserData\L3DK0KAH\id[1].xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0001692D\03_Music_rated_at_4_or_5_stars.wpl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Protect\S-1-5-21-3149542145-3322839065-4058237693-500\7c86938c-9ade-44b2-a1b9-d6e5269c7ffa | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Windows Live\Windows Live Spaces.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\41xTLbSy8hho.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.MSMessageStore | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Internet Explorer\brndlog.txt | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Sidebar\Settings.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.htm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Microsoft\Internet Explorer\UserData\Low\index.dat | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Adobe\Acrobat\10.0\Security\CRLCache\48B76449F3D5FEFA1133AA805E420F0FCA643651.crl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\oeold.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\edb00001.log | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\edb.chk | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\0IDnC0H9EMmV.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Windows Live\Get Windows Live.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\d9-2p9zLf4.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\WindowsMail.pat | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\du-5F19JYW5jR0wN.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN.url | Modified File | Stream |
Not Queried
|
...
|