Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2015-05-11 15:10:07,000 [root] INFO: Date set to: 05-11-15, time set to: 15:10:07
- 2015-05-11 15:10:07,019 [root] DEBUG: Starting analyzer from: C:\kbipm
- 2015-05-11 15:10:07,019 [root] DEBUG: Storing results at: C:\LmYtQfPO
- 2015-05-11 15:10:07,019 [root] DEBUG: Pipe server name: \\.\PIPE\unKzVtjLU
- 2015-05-11 15:10:07,319 [root] DEBUG: Started auxiliary module Browser
- 2015-05-11 15:10:07,319 [root] DEBUG: Started auxiliary module Disguise
- 2015-05-11 15:10:07,319 [root] DEBUG: Started auxiliary module Human
- 2015-05-11 15:10:07,319 [root] DEBUG: Started auxiliary module Screenshots
- 2015-05-11 15:10:07,349 [lib.api.process] INFO: Successfully executed process from path "C:\Windows\system32\regsvr32.exe" with arguments "C:\Users\dummy\AppData\Local\Temp\3b2143b70a79f4fe325aab9fdc4befff53316a8a.dll" with pid 3616
- 2015-05-11 15:10:07,359 [lib.api.process] DEBUG: Using QueueUserAPC injection.
- 2015-05-11 15:10:07,390 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 3616
- 2015-05-11 15:10:09,392 [lib.api.process] INFO: Successfully resumed process with pid 3616
- 2015-05-11 15:10:09,392 [root] INFO: Added new process to list with pid: 3616
- 2015-05-11 15:10:09,483 [root] INFO: Cuckoomon successfully loaded in process with pid 3616.
- 2015-05-11 15:10:09,592 [root] INFO: Announced 32-bit process name: explorer.exe pid: 2920
- 2015-05-11 15:10:09,602 [lib.api.process] DEBUG: Using QueueUserAPC injection.
- 2015-05-11 15:10:09,612 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2920
- 2015-05-11 15:10:09,612 [root] INFO: Disabling sleep skipping.
- 2015-05-11 15:10:10,414 [root] INFO: Process with pid 3616 has terminated
- 2015-05-11 15:10:30,612 [root] INFO: Process list is empty, terminating analysis.
- 2015-05-11 15:10:32,615 [root] INFO: Analysis completed.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement