Dynamic Analysis Report |
Classification: Riskware, Trojan, Ransomware |
e7b3102e3e49c6c3611353d704aae797923b699227df92d97987a2e012ba3f25 (SHA256)
2017-04-03-EITest-Rig-EK-payload-matrix-ransomware-variant.exe
Created at 2018-08-30 21:34:00
Notifications (2/2)
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
The operating system was rebooted during the analysis.
Remarks
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 bytes |
...
|
This list contains only the embedded files and created files
Filters: |
There are no files for this filter
Filename | Category | Type | Severity | Actions |
---|
C:\Users\EEBsYm5\Desktop\2017-04-03-EITest-Rig-EK-payload-matrix-ransomware-variant.exe | Sample File | Binary |
Blacklisted
|
...
|
Severity |
Blacklisted
|
First Seen | 2017-04-04 10:52 (UTC+2) |
Last Seen | 2018-06-23 18:41 (UTC+2) |
Names | Win32.Trojan.Matrix |
Families | Matrix |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x402581 |
Size Of Code | 0x19c00 |
Size Of Initialized Data | 0x65800 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2017-04-03 13:37:54+00:00 |
LegalCopyright | Copyright (C) 2017 |
FileVersion | 1, 0, 0, 1 |
ProductVersion | 1, 0, 0, 1 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x19aea | 0x19c00 | 0x400 | cnt_code, mem_execute, mem_read | 6.55 |
.rdata | 0x41b000 | 0x47b4 | 0x4800 | 0x1a000 | cnt_initialized_data, mem_read | 5.0 |
.data | 0x420000 | 0x31f0 | 0x1000 | 0x1e800 | cnt_initialized_data, mem_read, mem_write | 2.66 |
.rsrc | 0x424000 | 0x5dd90 | 0x5de00 | 0x1f800 | cnt_initialized_data, mem_read | 7.99 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TerminateProcess | 0x0 | 0x41b008 | 0x1eff4 | 0x1dff4 | 0x4c0 |
GetProcAddress | 0x0 | 0x41b00c | 0x1eff8 | 0x1dff8 | 0x245 |
LoadLibraryA | 0x0 | 0x41b010 | 0x1effc | 0x1dffc | 0x33c |
AddAtomA | 0x0 | 0x41b014 | 0x1f000 | 0x1e000 | 0x3 |
GetProcessAffinityMask | 0x0 | 0x41b018 | 0x1f004 | 0x1e004 | 0x246 |
VirtualProtect | 0x0 | 0x41b01c | 0x1f008 | 0x1e008 | 0x4ef |
LoadLibraryW | 0x0 | 0x41b020 | 0x1f00c | 0x1e00c | 0x33f |
EnumSystemLocalesA | 0x0 | 0x41b024 | 0x1f010 | 0x1e010 | 0x10d |
GetLocaleInfoA | 0x0 | 0x41b028 | 0x1f014 | 0x1e014 | 0x204 |
GetUserDefaultLCID | 0x0 | 0x41b02c | 0x1f018 | 0x1e018 | 0x29b |
CreateFileW | 0x0 | 0x41b030 | 0x1f01c | 0x1e01c | 0x8f |
SetStdHandle | 0x0 | 0x41b034 | 0x1f020 | 0x1e020 | 0x487 |
WriteConsoleW | 0x0 | 0x41b038 | 0x1f024 | 0x1e024 | 0x524 |
GetTempPathA | 0x0 | 0x41b03c | 0x1f028 | 0x1e028 | 0x284 |
GetDriveTypeW | 0x0 | 0x41b040 | 0x1f02c | 0x1e02c | 0x1d3 |
GetCommandLineA | 0x0 | 0x41b044 | 0x1f030 | 0x1e030 | 0x186 |
HeapSetInformation | 0x0 | 0x41b048 | 0x1f034 | 0x1e034 | 0x2d3 |
GetStartupInfoW | 0x0 | 0x41b04c | 0x1f038 | 0x1e038 | 0x263 |
RaiseException | 0x0 | 0x41b050 | 0x1f03c | 0x1e03c | 0x3b1 |
GetCurrentProcess | 0x0 | 0x41b054 | 0x1f040 | 0x1e040 | 0x1c0 |
UnhandledExceptionFilter | 0x0 | 0x41b058 | 0x1f044 | 0x1e044 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x41b05c | 0x1f048 | 0x1e048 | 0x4a5 |
IsDebuggerPresent | 0x0 | 0x41b060 | 0x1f04c | 0x1e04c | 0x300 |
HeapAlloc | 0x0 | 0x41b064 | 0x1f050 | 0x1e050 | 0x2cb |
GetLastError | 0x0 | 0x41b068 | 0x1f054 | 0x1e054 | 0x202 |
HeapFree | 0x0 | 0x41b06c | 0x1f058 | 0x1e058 | 0x2cf |
IsProcessorFeaturePresent | 0x0 | 0x41b070 | 0x1f05c | 0x1e05c | 0x304 |
EnterCriticalSection | 0x0 | 0x41b074 | 0x1f060 | 0x1e060 | 0xee |
LeaveCriticalSection | 0x0 | 0x41b078 | 0x1f064 | 0x1e064 | 0x339 |
DecodePointer | 0x0 | 0x41b07c | 0x1f068 | 0x1e068 | 0xca |
SetHandleCount | 0x0 | 0x41b080 | 0x1f06c | 0x1e06c | 0x46f |
GetStdHandle | 0x0 | 0x41b084 | 0x1f070 | 0x1e070 | 0x264 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41b088 | 0x1f074 | 0x1e074 | 0x2e3 |
GetFileType | 0x0 | 0x41b08c | 0x1f078 | 0x1e078 | 0x1f3 |
DeleteCriticalSection | 0x0 | 0x41b090 | 0x1f07c | 0x1e07c | 0xd1 |
EncodePointer | 0x0 | 0x41b094 | 0x1f080 | 0x1e080 | 0xea |
GetModuleHandleW | 0x0 | 0x41b098 | 0x1f084 | 0x1e084 | 0x218 |
ExitProcess | 0x0 | 0x41b09c | 0x1f088 | 0x1e088 | 0x119 |
WriteFile | 0x0 | 0x41b0a0 | 0x1f08c | 0x1e08c | 0x525 |
GetModuleFileNameW | 0x0 | 0x41b0a4 | 0x1f090 | 0x1e090 | 0x214 |
GetModuleFileNameA | 0x0 | 0x41b0a8 | 0x1f094 | 0x1e094 | 0x213 |
FreeEnvironmentStringsW | 0x0 | 0x41b0ac | 0x1f098 | 0x1e098 | 0x161 |
WideCharToMultiByte | 0x0 | 0x41b0b0 | 0x1f09c | 0x1e09c | 0x511 |
GetEnvironmentStringsW | 0x0 | 0x41b0b4 | 0x1f0a0 | 0x1e0a0 | 0x1da |
TlsAlloc | 0x0 | 0x41b0b8 | 0x1f0a4 | 0x1e0a4 | 0x4c5 |
TlsGetValue | 0x0 | 0x41b0bc | 0x1f0a8 | 0x1e0a8 | 0x4c7 |
TlsSetValue | 0x0 | 0x41b0c0 | 0x1f0ac | 0x1e0ac | 0x4c8 |
TlsFree | 0x0 | 0x41b0c4 | 0x1f0b0 | 0x1e0b0 | 0x4c6 |
InterlockedIncrement | 0x0 | 0x41b0c8 | 0x1f0b4 | 0x1e0b4 | 0x2ef |
SetLastError | 0x0 | 0x41b0cc | 0x1f0b8 | 0x1e0b8 | 0x473 |
GetCurrentThreadId | 0x0 | 0x41b0d0 | 0x1f0bc | 0x1e0bc | 0x1c5 |
InterlockedDecrement | 0x0 | 0x41b0d4 | 0x1f0c0 | 0x1e0c0 | 0x2eb |
GetCurrentThread | 0x0 | 0x41b0d8 | 0x1f0c4 | 0x1e0c4 | 0x1c4 |
HeapCreate | 0x0 | 0x41b0dc | 0x1f0c8 | 0x1e0c8 | 0x2cd |
HeapDestroy | 0x0 | 0x41b0e0 | 0x1f0cc | 0x1e0cc | 0x2ce |
QueryPerformanceCounter | 0x0 | 0x41b0e4 | 0x1f0d0 | 0x1e0d0 | 0x3a7 |
GetTickCount | 0x0 | 0x41b0e8 | 0x1f0d4 | 0x1e0d4 | 0x293 |
GetCurrentProcessId | 0x0 | 0x41b0ec | 0x1f0d8 | 0x1e0d8 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x41b0f0 | 0x1f0dc | 0x1e0dc | 0x279 |
Sleep | 0x0 | 0x41b0f4 | 0x1f0e0 | 0x1e0e0 | 0x4b2 |
FatalAppExitA | 0x0 | 0x41b0f8 | 0x1f0e4 | 0x1e0e4 | 0x120 |
GetCPInfo | 0x0 | 0x41b0fc | 0x1f0e8 | 0x1e0e8 | 0x172 |
GetACP | 0x0 | 0x41b100 | 0x1f0ec | 0x1e0ec | 0x168 |
GetOEMCP | 0x0 | 0x41b104 | 0x1f0f0 | 0x1e0f0 | 0x237 |
IsValidCodePage | 0x0 | 0x41b108 | 0x1f0f4 | 0x1e0f4 | 0x30a |
RtlUnwind | 0x0 | 0x41b10c | 0x1f0f8 | 0x1e0f8 | 0x418 |
HeapSize | 0x0 | 0x41b110 | 0x1f0fc | 0x1e0fc | 0x2d4 |
SetConsoleCtrlHandler | 0x0 | 0x41b114 | 0x1f100 | 0x1e100 | 0x42d |
FreeLibrary | 0x0 | 0x41b118 | 0x1f104 | 0x1e104 | 0x162 |
InterlockedExchange | 0x0 | 0x41b11c | 0x1f108 | 0x1e108 | 0x2ec |
GetLocaleInfoW | 0x0 | 0x41b120 | 0x1f10c | 0x1e10c | 0x206 |
HeapReAlloc | 0x0 | 0x41b124 | 0x1f110 | 0x1e110 | 0x2d2 |
GetConsoleCP | 0x0 | 0x41b128 | 0x1f114 | 0x1e114 | 0x19a |
GetConsoleMode | 0x0 | 0x41b12c | 0x1f118 | 0x1e118 | 0x1ac |
FlushFileBuffers | 0x0 | 0x41b130 | 0x1f11c | 0x1e11c | 0x157 |
LCMapStringW | 0x0 | 0x41b134 | 0x1f120 | 0x1e120 | 0x32d |
MultiByteToWideChar | 0x0 | 0x41b138 | 0x1f124 | 0x1e124 | 0x367 |
GetStringTypeW | 0x0 | 0x41b13c | 0x1f128 | 0x1e128 | 0x269 |
SetFilePointer | 0x0 | 0x41b140 | 0x1f12c | 0x1e12c | 0x466 |
CloseHandle | 0x0 | 0x41b144 | 0x1f130 | 0x1e130 | 0x52 |
IsValidLocale | 0x0 | 0x41b148 | 0x1f134 | 0x1e134 | 0x30c |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PostQuitMessage | 0x0 | 0x41b150 | 0x1f13c | 0x1e13c | 0x237 |
DefWindowProcA | 0x0 | 0x41b154 | 0x1f140 | 0x1e140 | 0x9b |
EnableScrollBar | 0x0 | 0x41b158 | 0x1f144 | 0x1e144 | 0xd7 |
LoadImageA | 0x0 | 0x41b15c | 0x1f148 | 0x1e148 | 0x1ee |
DestroyWindow | 0x0 | 0x41b160 | 0x1f14c | 0x1e14c | 0xa6 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetEnhMetaFileHeader | 0x0 | 0x41b000 | 0x1efec | 0x1dfec | 0x1d4 |
C:\Users\Default\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Stream |
Unknown
|
...
|
C:\Users\Default\Searches\Everywhere.search-ms | Modified File | Stream |
Unknown
|
...
|
C:\Users\EEBsYm5\Desktop\dcFt2Dy7M6d8J9.ots | Modified File | Stream |
Unknown
|
...
|
C:\Users\EEBsYm5\Documents\fcfnnEKYsCveHRXmenn\wj5G.ppt | Modified File | Stream |
Unknown
|
...
|
C:\Users\EEBsYm5\Pictures\wo_IX7FkjtTmLgs.jpg | Modified File | Stream |
Unknown
|
...
|
c:\programdata\microsoft help\ms.visio.dev.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\Oases7ZDuwJ0FV.xls | Modified File | Stream |
Unknown
|
...
|
c:\programdata\microsoft help\ms.setlang.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
c:\programdata\microsoft help\ms.excel.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\pub6intl.rest.trx_dll | Modified File | Stream |
Unknown
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\3082\ENVELOPR.DLL.trx_dll.b10cked | Modified File | Stream |
Unknown
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\wwintl.rest.trx_dll | Modified File | Stream |
Unknown
|
...
|
C:\Users\EEBsYm5\Contacts\uosjfl sidvllie.contact | Modified File | Stream |
Unknown
|
...
|
C:\Users\ALLUSE~1\Adobe\Acrobat\10.0\REPLIC~1\Security\directories.acrodata.b10cked | Modified File | Stream |
Unknown
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\vMfCCeRYkvQy\Gy2dwmVF.cmd | Created File | Text |
Unknown
|
...
|
c:\users\eebsym5\pictures\lr0ar2rewelj\j4m1cx oc5jpl3u0yc.lnk | Created File | Stream |
Unknown
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\WWINTL.REST.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\gcAp-7-i61tX.bmp | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.visio.shapesheet.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\OMSINTL.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\ppintl.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\tWV414DCFHSA.ppt | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\stintl.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\XLINTL32.REST.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\Lp6Y\hqVibu00\u7E2T\4_Irbu3SMZgt2KGk_cO7.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\MF\Pending.GRL.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\Outlook Files\feasf@efw.com.pst | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\BcUgG-6ytRMwdapH.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Links\Web Slice Gallery.url | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\outlwvw.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\fcfnnEKYsCveHRXmenn\0Q56T.odt | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\PPINTL.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\visbrres.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\fcfnnEKYsCveHRXmenn\gaY66uwM4.ots | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\outllibr.rest.trx_dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\fcfnnEKYsCveHRXmenn\P939uI0IUIKwHsX.xlsx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN.url | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.infopath.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\8rVd3erYRX.docx | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.winword.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.visio_prm.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\GbkI\bON4k7zjy0QFC_kDVvV.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\xJ2fmd\lim3Lqu-K6HO.xls | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\MSOINTL.REST.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\fcfnnEKYsCveHRXmenn\VBKNjIyz39y.ods | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2VgMmRhPzB7.docx | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\msointl.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\hx_1033_mtoc_hx.hxh | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\XLSLICER.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.outlook.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Pictures\lr0aR2rEWELj\j4m1cX oc5jpl3U0YC\EEJhG5emgLWHUyVz.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\59nIYoZ1Klx-.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\GRINTL32.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\5OwEKsaDhMyqwxmS\nRwdONYdB2-UAOUM\1VhPwYxy0yNVr kbAeh\tgRDf2UBQ_aR.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\VISINTL.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\PPINTL.REST.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\omsintl.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\GbkI\WtCCLcHrwK.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\ONINTL.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.outlook.dev.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Pictures\lr0aR2rEWELj\j4m1cX oc5jpl3U0YC\qgVefxhoS8T3s19q574.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\Lp6Y\hqVibu00\OXP9rCEqmjhd9gNfz.avi | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\user account pictures\guest.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\MF\Active.GRL.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\WWINTL.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\Lp6Y\hqVibu00\u7E2T\92pj.doc | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\1uB93z-ou.pptx | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\xlintl32.rest.trx_dll | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\onintl.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\pubwzint.rest.trx_dll | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\xlslicer.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\kawGr8UmxCuLrfZA.swf | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\pub6intl.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\grintl32.rest.trx_dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\5OwEKsaDhMyqwxmS\9bQDI69.ods | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.mspub.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\xJ2fmd\oR2F.csv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Pictures\aR0_1pZCSZwjfY.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\MOR6INT.REST.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\xlintl32.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.msaccess.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.onenote.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Contacts\ihnvbh euuncnh.contact | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Pictures\lr0aR2rEWELj\QO_v_Iwy7B17SYlN-.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\gjVvzAf3d4AVCevrZIj.xlsx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\5OwEKsaDhMyqwxmS\WxMD5ucxt4TTzYn6xhkt\WnPdVDXwSUv.doc | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\OUTLLIBR.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\onintl.rest.trx_dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\qXDEHmzN LrwSQhutJ.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\-V83XFbt5-FsW.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\GbkI\ftTfHtfADyQIa-_\Tq3yPk_6C.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\5OwEKsaDhMyqwxmS\WxMD5ucxt4TTzYn6xhkt\vaFvM9aFd9qECGT.odt | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\visintl.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\PUB6INTL.REST.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Contacts\Administrator.contact | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\5OwEKsaDhMyqwxmS\nRwdONYdB2-UAOUM\1VhPwYxy0yNVr kbAeh\BS0-Nm2046.xlsx | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\user account pictures\user.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\5OwEKsaDhMyqwxmS\5d djXdWwSLPL XJ.xls | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\7jmxgwY9.xlsx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\MAPIR.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.visio.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\ERN4JQpRpgZde9N.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\mXjqIsUDXYxFeYxzgw.ots | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\outllibr.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\Tdxt9-_3mYM7NtN.pptx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\fUt5wrAPeTu.pptx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\DDlQzm1zrUmfqtdJ.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\OUTLLIBR.REST.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\fcfnnEKYsCveHRXmenn\Mmwj0D0mDfuQB5wXA.odp | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\aK_FOd5jl.ots | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\PUB6INTL.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.winproj.dev.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\bkwVSdvUcmd7uNf_5 x.jpg | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.msouc.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\pWkwXr56WJA6 l5.ods | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\D2poZdDEdi.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\egB3USbk0IDbq.odt | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\9CDgy bLN0e-uZnqSYBc.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN Money.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Contacts\mneuc uhnfghgg.contact | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.infopatheditor.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Contacts\Administrator.contact | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.ois.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\mor6int.rest.trx_dll | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.powerpnt.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSNBC News.url | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\mapir.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\SGRES.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\95ICx9P6yb.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\IJFqBHm_BK63v.ods | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Searches\Indexed Locations.search-ms | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\fcfnnEKYsCveHRXmenn\UFl3tyKJKu.ppt | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Bl0cked-ReadMe.rtf | Created File | Text |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\msointl.rest.trx_dll | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.groove.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\M9MmOpgceUJDVTGEEh.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\Lp6Y\hqVibu00\LUKOkovEeIsTMf0.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\5OwEKsaDhMyqwxmS\WxMD5ucxt4TTzYn6xhkt\Cf aWIIkKxWa7MD7fCc.xlsx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\ONINTL.REST.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\nslist.hxl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\XLINTL32.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\hx_1033_mkwd_k.hxw | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN Autos.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\xJ2fmd\TAXJKdn0yOKX7tSSpc.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\GRINTL32.REST.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\hx_1033_mvalidator.hxd | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\Lp6Y\hqVibu00\cii3Zm5ag7.wav | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.mspub.dev.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\ENVELOPR.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.winproj.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Contacts\ofhbnh edferrr.contact | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.winword.dev.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\5OwEKsaDhMyqwxmS\Thcv85KW1KoWsUQP.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Pictures\lr0aR2rEWELj\j4m1cX oc5jpl3U0YC\u8sH0rXco9.jpg | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.msaccess.dev.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\3082\GRINTL32.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\5OwEKsaDhMyqwxmS\WxMD5ucxt4TTzYn6xhkt\ieMCxg.pps | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\package cache\{f325f05b-f963-4640-a43b-c8a494cdda0f}\state.rsm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\PUBWZINT.REST.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\Lp6Y\e-AggmA P_oioCEdo08.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\VISBRRES.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\VX2e_AgjuFQyd1Woq.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\5OwEKsaDhMyqwxmS\nRwdONYdB2-UAOUM\1VhPwYxy0yNVr kbAeh\RIbq701A98461 y-C _\iyDSdIsdd3hcv.pptx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\5OwEKsaDhMyqwxmS\nRwdONYdB2-UAOUM\1VhPwYxy0yNVr kbAeh\UzyEGr8akjufgS.doc | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\OUTLWVW.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\5OwEKsaDhMyqwxmS\nRwdONYdB2-UAOUM\1VhPwYxy0yNVr kbAeh\g ol7OxwE18leXod.csv | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\package cache\{e6e75766-da0f-4ba2-9788-6ea593ce702d}\state.rsm | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.graph.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Pictures\kYWWkRklabLUzyrJ9.jpg | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\wwintl.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\STINTL.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.powerpnt.dev.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.mstore.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN Sports.url | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\ppintl.rest.trx_dll | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.visio_std.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\mPZFEDoY9Zi_en.flv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\xJ2fmd\bDJO8cWgfh9q_unjpPU-.doc | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\5OwEKsaDhMyqwxmS\rd4bMPAMmCyKiYpJrFwO.ots | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Documents\2w7_ew\xJ2fmd\iu1VEIcz.ods | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\Lp6Y\hqVibu00\Q--qnZ17d.bmp | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\ms.excel.dev.14.1033.hxn | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\SXGpQHv i4OFxmN5_1.odp | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft help\hx_1033_mkwd_namedurl.hxw | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Contacts\lodkd auftnm.contact | Modified File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082\sgres.dll.trx_dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\GbkI\ftTfHtfADyQIa-_\1up3 l.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\Desktop\GbkI\ftTfHtfADyQIa-_\65OAv.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\ALLUSE~1\MICROS~1\OFFICE\UICAPT~1\1036\MSOINTL.DLL.trx_dll.b10cked | Modified File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\2w7_ew\5oweksadhmyqwxms.lnk | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\fcfnnekyscvehrxmenn.lnk | Created File | Stream |
Not Queried
|
...
|
c:\programdata\package cache\{e6e75766-da0f-4ba2-9788-6ea593ce702d}.lnk | Created File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\vMfCCeRYkvQy\1A4qO2RH.cmd | Created File | Text |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\vMfCCeRYkvQy\KGiXH98V.cmd | Created File | Text |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\Microsoft\Windows\7l6OWDI9Fmrsoy1O.ico | Created File | Image |
Not Queried
|
...
|
c:\programdata\microsoft\user account pictures\default pictures.lnk | Created File | Stream |
Not Queried
|
...
|
c:\programdata\adobe\acrobat\10.0\replicate\security.lnk | Created File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\7l6OWDI9Fmrsoy1O.ast | Created File | Unknown |
Not Queried
|
...
|
c:\programdata\package cache\{f325f05b-f963-4640-a43b-c8a494cdda0f}.lnk | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\lp6y\hqvibu00.lnk | Created File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\vMfCCeRYkvQy\DGaezHhx.cmd | Created File | Text |
Not Queried
|
...
|
c:\users\eebsym5\desktop\lp6y\hqvibu00\u7e2t.lnk | Created File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\vMfCCeRYkvQy\QQZAKkLZ.cmd | Created File | Text |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\vMfCCeRYkvQy\sQFgqtRn.cmd | Created File | Text |
Not Queried
|
...
|
c:\users\default\favorites\msn websites.lnk | Created File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\3188F4D96148D062.sek | Created File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\vMfCCeRYkvQy\8Nkh0cv7.cmd | Created File | Text |
Not Queried
|
...
|
c:\users\eebsym5\desktop\gbki\fttfhtfadyqia-_.lnk | Created File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}.lnk | Created File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\1036.lnk | Created File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}.lnk | Created File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\vMfCCeRYkvQy\CbFFjy09.cmd | Created File | Text |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\vMfCCeRYkvQy\RiKWxOaL.cmd | Created File | Text |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\3188F4D96148D062.pek | Created File | Text |
Not Queried
|
...
|
c:\users\eebsym5\documents\2w7_ew\xj2fmd.lnk | Created File | Stream |
Not Queried
|
...
|
c:\programdata\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}.lnk | Created File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\vMfCCeRYkvQy\p0mhdE5X.cmd | Created File | Text |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\vMfCCeRYkvQy\7l6OWDI9Fmrsoy1O.elst | Created File | Text |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\vMfCCeRYkvQy\2btKHTzb.cmd | Created File | Text |
Not Queried
|
...
|
c:\programdata\microsoft\rac\publisheddata.lnk | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\2w7_ew\5oweksadhmyqwxms\wxmd5ucxt4ttzyn6xhkt.lnk | Created File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\office\uicaptions\3082.lnk | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\2w7_ew\5oweksadhmyqwxms\nrwdonydb2-uaoum\1vhpwyxy0ynvr kbaeh.lnk | Created File | Stream |
Not Queried
|
...
|
C:\Users\EEBsYm5\AppData\Roaming\vMfCCeRYkvQy\WlLsor5U.cmd | Created File | Text |
Not Queried
|
...
|
c:\users\eebsym5\documents\2w7_ew\5oweksadhmyqwxms\nrwdonydb2-uaoum\1vhpwyxy0ynvr kbaeh\ribq701a98461 y-c _.lnk | Created File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\rac\statedata.lnk | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\lr0ar2rewelj.lnk | Created File | Stream |
Not Queried
|
...
|
c:\programdata\microsoft\user account pictures.lnk | Created File | Stream |
Not Queried
|
...
|
c:\users\default\favorites\microsoft websites.lnk | Created File | Stream |
Not Queried
|
...
|