e2ac9692...a787 | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Ransomware, Wiper, Trojan

VMRay Threat Indicators (12 rules, 646 matches)

Severity Category Operation Count Classification
5/5
Local AV Malicious content was detected by heuristic scan 1 -
5/5
Reputation Known malicious file 1 Trojan
  • File "C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\White.exe" is a known malicious file.
4/5
File System Renames user files 1 Ransomware
  • Renames multiple user files. This is an indicator for an encryption attempt.
4/5
File System Modifies content of user files 1 Ransomware
  • Modifies the content of multiple user files. This is an indicator for an encryption attempt.
4/5
File System Deletes user files 1 Wiper
  • Deletes multiple user files. This is an indicator for ransomware or wiper malware.
4/5
YARA YARA match 4 -
  • Rule "JS_High_Entropy" from ruleset "Generic" has matched on the modified file "C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_route_details.js".
  • Rule "JS_High_Entropy" from ruleset "Generic" has matched on the modified file "C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\common.js".
  • Rule "JS_High_Entropy" from ruleset "Generic" has matched on the modified file "C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\mirroring_common.js".
  • Rule "JS_High_Entropy" from ruleset "Generic" has matched on the modified file "C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\cast_app.js".
3/5
File System Possibly drops ransom note files 1 Ransomware
  • Possibly drops ransom note files (creates 175 instances of the file "HOW-TO-RECOVERY-FILES.TXT" in different locations).
2/5
Information Stealing Reads sensitive browser data 1 -
  • Trying to read sensitive data of web browser "Google Chrome" by file.
1/5
File System Modifies application directory 632 -
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\pmd.cer".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\rtc.der".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\air\nppdf32.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\air\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\browser\nppdf32.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\browser\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\cat\adobeid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\cat\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\cat\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\chs\adobeid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\chs\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\chs\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\cht\adobeid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\cze\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\dan\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\dan\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\deu\adobeid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\deu\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\deu\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\enu\adobeid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\esp\adobeid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\esp\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\esp\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\fra\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\fra\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\hrv\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\hrv\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\hun\adobeid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\hun\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\hun\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\kor\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\kor\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\nld\adobeid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\ptb\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\ptb\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\rum\adobeid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\rum\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\rum\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\sky\adobeid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\sky\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\sky\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\slv\adobeid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\slv\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\slv\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\suo\adobeid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\suo\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\sve\adobeid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\sve\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\tur\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\tur\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\ukr\adobeid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\idtemplates\ukr\defaultid.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\cat\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\chs\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\cht\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\dan\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\dan\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\deu\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\enu\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\esp\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\euq\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\fra\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\hrv\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\hun\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\ita\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\nld\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\nor\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\ptb\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\ptb\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\sky\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\slv\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\sve\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\sve\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\legal\tur\license.html".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\accessibility.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\acroform.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\adobecollabsync.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\annots.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\checkers.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\digsig.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\ebook.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\escript.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\ia32.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\makeaccessible.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\rdlang32.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\readoutloud.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\reflow.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\saveasrtf.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\search.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\sendmail.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\weblink.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\services\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\fi_fi\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\locale\hu_hu\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\chs\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\chs\hanko.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\chs\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\cht\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\cht\hanko.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\cht\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\cze\faces.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\cze\pointers.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\cze\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\cze\standard.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\cze\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\cze\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\dan\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\dan\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\deu\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\deu\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\deu\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\deu\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\enu\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\enu\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\enu\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\esp\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\euq\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\euq\faces.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\euq\pointers.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\euq\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\euq\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\euq\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\fra\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\hrv\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\hun\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\hun\faces.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\hun\pointers.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\hun\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\hun\standard.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\hun\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\hun\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\ita\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\ita\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\ita\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\ita\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\jpn\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\jpn\hanko.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\jpn\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\kor\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\kor\hanko.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\kor\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\nld\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\nld\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\nld\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\nor\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\nor\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\nor\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\pol\faces.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\pol\pointers.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\pol\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\pol\standard.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\pol\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\pol\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\ptb\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\ptb\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\ptb\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\rum\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\rum\faces.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\rum\standard.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\rum\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\rum\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\rus\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\rus\faces.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\rus\pointers.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\rus\standard.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\rus\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\rus\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\sky\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\sky\pointers.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\sky\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\sky\standard.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\slv\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\slv\faces.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\slv\pointers.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\slv\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\slv\standard.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\slv\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\slv\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\suo\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\suo\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\sve\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\sve\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\sve\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\tur\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\tur\pointers.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\tur\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\tur\standard.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\tur\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\ukr\dynamic.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\ukr\faces.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\ukr\signhere.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\ukr\standardbusiness.pdf".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\ukr\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\annotations\stamps\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\mcimpp.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\windowsmedia.suo".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\multimedia\mpp\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\plug_ins\multimedia\mpp_cze\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\services\services.cfg".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\forms_received.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\form_responses.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\info.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\open_original_form.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\pdf.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\reviews_sent.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\reviews_super.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\review_browser.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\review_email.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\review_same_reviewers.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\rss.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\server_issue.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\server_lg.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\server_ok.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\stop_collection_data.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\submission_history.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\tl.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\trash.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\turnonnotificationintray.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\warning.gif".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\tracker\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\reader\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\font\pfm\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar_ae.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar_bh.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar_dz.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar_eg.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar_iq.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar_kw.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar_lb.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar_ly.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar_ma.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar_qa.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar_sa.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar_sd.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar_sy.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ar_ye.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.bg.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.bg_bg.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ca.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ca_es.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ca_es_preeuro.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.cs.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.cs_cz.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.da.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.da_dk.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.de_ch.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.de_de.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.de_de_preeuro.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.el_gr_preeuro.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_ca.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_gb.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.en_us_posix.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_ar.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_bo.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_co.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_cr.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_es.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_es_preeuro.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_gt.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_hn.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_mx.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_ni.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_pa.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_pe.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_py.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_us.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es_ve.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.es__traditional.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.et.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.et_ee.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.fi.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.fi_fi.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.fi_fi_preeuro.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.fr_ca.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.fr_fr.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.fr_fr_preeuro.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.he.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.hr.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.hu.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.hu_hu.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.it.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.it_ch.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.it_it.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.it_it_preeuro.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ja.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ja_jp_traditional.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ko.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.lt.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.lv.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.lv_lv.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.nb_no.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.nl_be.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.nl_be_preeuro.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.nl_nl.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.nl_nl_preeuro.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.nn_no.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.pt_pt.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.pt_pt_preeuro.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ro.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ro_ro.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.ru_ua.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.sk_sk.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.sl.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.sl_si.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.sv.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.sv_fi.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.sv_se.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.tr.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.tr_tr.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.zh_cn.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\languagenames2\displaylanguagenames.zh_tw.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\linguistics\providers\proximity\11.00\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\icu\icudt26l.dat".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\adobe\japanese83pv.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\adobe\jisx0208.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\adobe\jisx0213.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\adobe\zdingbat.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\adobe\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\arabic.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\centeuro.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\chintrad.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\corpchar.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\croatian.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\farsi.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\greek.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\hebrew.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\iceland.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\japanese.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\symbol.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\thai.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\ukraine.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\mac\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\win\cp1250.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\win\cp1251.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\win\cp1252.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\win\cp1253.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\win\cp1254.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\win\cp1256.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\win\cp1257.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\win\cp1258.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\win\cp874.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\win\cp932.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\win\cp936.txt".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\resource\typesupport\unicode\mappings\win\cp949.txt".
  • Modifies "c:\program files (x86)\common files\adobe\arm\1.0\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\common files\microsoft shared\ink\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\common files\microsoft shared\textconv\en-us\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\visualelements\logo.png".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\visualelements\logocanary.png".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\visualelements\smalllogocanary.png".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\visualelements\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\widevinecdm\_platform_specific\win_x64\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\java\jre7\thirdpartylicensereadme-javafx.txt".
  • Modifies "c:\program files (x86)\java\jre7\lib\jvm.hprof.txt".
  • Modifies "c:\program files (x86)\java\jre7\lib\deploy\ffjcext.zip".
  • Modifies "c:\program files (x86)\java\jre7\lib\deploy\splash.gif".
  • Modifies "c:\program files (x86)\java\jre7\lib\images\cursors\win32_copydrop32x32.gif".
  • Modifies "c:\program files (x86)\java\jre7\lib\images\cursors\win32_copynodrop32x32.gif".
  • Modifies "c:\program files (x86)\java\jre7\lib\images\cursors\win32_linknodrop32x32.gif".
  • Modifies "c:\program files (x86)\java\jre7\lib\images\cursors\win32_movedrop32x32.gif".
  • Modifies "c:\program files (x86)\java\jre7\lib\images\cursors\win32_movenodrop32x32.gif".
  • Modifies "c:\program files (x86)\java\jre7\lib\images\cursors\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\java\jre7\lib\images\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\appconfig.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\appconfiginternal.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\assemblyinfointernal.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\codefile.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\dataset.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\emptydatabase.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\form.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\resource.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\resourceinternal.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\settings.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\settingsinternal.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\visualizer.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\xmlfile.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\1033\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\csharp\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\visualbasic\1033\emptydatabase.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\visualbasic\1033\explorer.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\visualbasic\1033\form.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\visualbasic\1033\loginform.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\visualbasic\1033\mdiparent.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\visualbasic\1033\resourceinternal.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\visualbasic\1033\settingsinternal.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\visualbasic\1033\splashscreen.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\visualbasic\1033\text.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\visualbasic\1033\usercontrol.zip".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\visualbasic\1033\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\vsta\itemtemplates\visualbasic\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\microsoft.net\redistlist\assemblylist_4_client.xml".
  • Modifies "c:\program files (x86)\mozilla firefox\install.log".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\blocklist.xml".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\searchplugins\twitter.xml".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\searchplugins\wikipedia.xml".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\searchplugins\yahoo.xml".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\searchplugins\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\mozilla firefox\uninstall\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\windows media player\media renderer\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\windows media player\network sharing\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\calendar.gadget\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\clock.gadget\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\cpu.gadget\en-us\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\currency.gadget\en-us\js\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\currency.gadget\en-us\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\currency.gadget\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\rssfeeds.gadget\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\slideshow.gadget\images\how-to-recovery-files.txt".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\weather.gadget\images\how-to-recovery-files.txt".
1/5
Information Stealing Possibly does reconnaissance 1 -
  • Possibly trying to gather information about application "Mozilla Firefox" by file.
1/5
File System Creates an unusually large number of files 1 -
1/5
Static Unparsable sections in file 1 -
  • Static analyzer was unable to completely parse the analyzed file: C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\White.exe.

Screenshots

Monitored Processes

Sample Information

ID #100244
MD5 c7157973ae9bfd04f871e9b80c4b0644 Copy to Clipboard
SHA1 826e0e9d7ce6d614238e93d48b3a5a0c29aa3c0d Copy to Clipboard
SHA256 e2ac9692c0816ccd59d1844048c6238dc5d105b0477620eeb1cdb0909804a787 Copy to Clipboard
SSDeep 768:2mOHkWx/vS4BZimJOLbVxlQdPAyI1V1zatwv:2mOHkE3GmJOLbvlwAyI1V1zlv Copy to Clipboard
ImpHash f34d5f2d4577ed6d9ceec516c1f5a744 Copy to Clipboard
Filename White.exe
File Size 35.50 KB
Sample Type Windows Exe (x86-32)

Analysis Information

Creation Time 2019-07-06 08:55 (UTC+2)
Analysis Duration 00:04:27
Number of Monitored Processes 1
Execution Successful True
Reputation Enabled True
WHOIS Enabled False
Local AV Enabled True
YARA Enabled True
Number of AV Matches 1
Number of YARA Matches 4
Termination Reason Timeout
Tags
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image