paladin316

remcos_dc91ac8ad98558cdff91783713221ae4b5597178bdfae08569d09ac2bdca63d9_2019-08-21_11_50.txt

Aug 21st, 2019
2,114
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 23.99 KB | None | 0 0
  1.  
  2. * MalFamily: "Remcos"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "remcos_dc91ac8ad98558cdff91783713221ae4b5597178bdfae08569d09ac2bdca63d9"
  7. * File Size: 3035016
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "dc91ac8ad98558cdff91783713221ae4b5597178bdfae08569d09ac2bdca63d9"
  10. * MD5: "95829108b0e5f9ebeb15ca5ae1a9ad5d"
  11. * SHA1: "f6edc808863f4490096fc6b5f0b31119a668e116"
  12. * SHA512: "79885603888d67d160b0a0228e13800070c3526a7b9bfa0b1612d93f5fc2ba758b5dd4a1e09051dd16b1c18e28d37c8c52d47e068f88f45094d8832000154462"
  13. * CRC32: "91B1BC5C"
  14. * SSDEEP: "49152:hh+ZkldoPK8Yad7cwj644Mh+ZkldoPK8YaLDNcJ:C2cPK8YwjE2cPK8E"
  15.  
  16. * Process Execution:
  17. "remcos_dc91ac8ad98558cdff91783713221ae4b5597178bdfae08569d09ac2bdca63d9.exe",
  18. "remcos_agent_Protected.exe",
  19. "remcos_agent_Protected.exe",
  20. "wscript.exe",
  21. "schtasks.exe",
  22. "AcroRd32.exe",
  23. "Eula.exe",
  24. "schtasks.exe",
  25. "svchost.exe"
  26.  
  27.  
  28. * Executed Commands:
  29. "\"C:\\Users\\user\\AppData\\Roaming\\remcos_agent_Protected.exe\"",
  30. "C:\\Users\\user\\AppData\\Roaming\\remcos_agent_Protected.exe ",
  31. "\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroRd32.exe\" \"C:\\Users\\user\\AppData\\Local\\Temp\\medical-application-form.pdf\"",
  32. "C:\\Users\\user\\AppData\\Local\\Temp\\medical-application-form.pdf ",
  33. "\"C:\\Windows\\SysWOW64\\schtasks.exe\" /create /tn WWAHost /tr \"C:\\Users\\user\\AppData\\Roaming\\RtDCpl64\\driverquery.exe\" /sc minute /mo 1 /F",
  34. "schtasks /create /tn WWAHost /tr \"C:\\Users\\user\\AppData\\Roaming\\RtDCpl64\\driverquery.exe\" /sc minute /mo 1 /F",
  35. "\"C:\\Windows\\SysWOW64\\schtasks.exe\" /create /tn setx /tr \"C:\\Users\\user\\AppData\\Roaming\\CapabilityAccessHandlers\\sfc.exe\" /sc minute /mo 1 /F",
  36. "schtasks /create /tn setx /tr \"C:\\Users\\user\\AppData\\Roaming\\CapabilityAccessHandlers\\sfc.exe\" /sc minute /mo 1 /F",
  37. "\"C:\\Windows\\System32\\WScript.exe\" \"C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs\"",
  38. "C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs ",
  39. "\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroRd32.exe\" --type=renderer \"C:\\Users\\user\\AppData\\Local\\Temp\\medical-application-form.pdf\"",
  40. "\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroCEF\\RdrCEF.exe\" --backgroundcolor=16514043",
  41. "\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Eula.exe\" Adobe Acrobat Reader DC;852442;1033"
  42.  
  43.  
  44. * Signatures Detected:
  45.  
  46. "Description": "Creates RWX memory",
  47. "Details":
  48.  
  49.  
  50. "Description": "Possible date expiration check, exits too soon after checking local time",
  51. "Details":
  52.  
  53. "process": "schtasks.exe, PID 1812"
  54.  
  55.  
  56.  
  57.  
  58. "Description": "A process attempted to delay the analysis task.",
  59. "Details":
  60.  
  61. "Process": "svchost.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  62.  
  63.  
  64.  
  65.  
  66. "Description": "Reads data out of its own binary image",
  67. "Details":
  68.  
  69. "self_read": "process: remcos_dc91ac8ad98558cdff91783713221ae4b5597178bdfae08569d09ac2bdca63d9.exe, pid: 208, offset: 0x00000000, length: 0x002e4f88"
  70.  
  71.  
  72. "self_read": "process: remcos_agent_Protected.exe, pid: 2404, offset: 0x00000000, length: 0x0011fe00"
  73.  
  74.  
  75. "self_read": "process: Eula.exe, pid: 2248, offset: 0x00000000, length: 0x00000040"
  76.  
  77.  
  78. "self_read": "process: Eula.exe, pid: 2248, offset: 0x00000100, length: 0x00000018"
  79.  
  80.  
  81. "self_read": "process: Eula.exe, pid: 2248, offset: 0x000001f8, length: 0x000000a0"
  82.  
  83.  
  84. "self_read": "process: Eula.exe, pid: 2248, offset: 0x00012600, length: 0x00000010"
  85.  
  86.  
  87.  
  88.  
  89. "Description": "A process created a hidden window",
  90. "Details":
  91.  
  92. "Process": "remcos_dc91ac8ad98558cdff91783713221ae4b5597178bdfae08569d09ac2bdca63d9.exe -> schtasks"
  93.  
  94.  
  95. "Process": "remcos_agent_Protected.exe -> schtasks"
  96.  
  97.  
  98. "Process": "remcos_agent_Protected.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs"
  99.  
  100.  
  101.  
  102.  
  103. "Description": "Drops a binary and executes it",
  104. "Details":
  105.  
  106. "binary": "C:\\Users\\user\\AppData\\Roaming\\remcos_agent_Protected.exe"
  107.  
  108.  
  109.  
  110.  
  111. "Description": "Executed a process and injected code into it, probably while unpacking",
  112. "Details":
  113.  
  114. "Injection": "remcos_agent_Protected.exe(2404) -> remcos_agent_Protected.exe(2344)"
  115.  
  116.  
  117.  
  118.  
  119. "Description": "A potential decoy document was displayed to the user",
  120. "Details":
  121.  
  122. "disguised_executable": "The submitted file was an executable indicative of an attempt to get a user to run executable content disguised as a document"
  123.  
  124.  
  125. "Decoy Document": "\"c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\acrord32.exe\" \"c:\\users\\user\\appdata\\local\\temp\\medical-application-form.pdf\""
  126.  
  127.  
  128.  
  129.  
  130. "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
  131. "Details":
  132.  
  133. "MITRE T1078 - schtask": "(Tactic: Execution, Persistence, Privilege Escalation)"
  134.  
  135.  
  136.  
  137.  
  138. "Description": "Installs itself for autorun at Windows startup",
  139. "Details":
  140.  
  141. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos"
  142.  
  143.  
  144. "data": "\"C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe\""
  145.  
  146.  
  147. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos"
  148.  
  149.  
  150. "data": "\"C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe\""
  151.  
  152.  
  153. "task": "\"C:\\Windows\\SysWOW64\\schtasks.exe\" /create /tn WWAHost /tr \"C:\\Users\\user\\AppData\\Roaming\\RtDCpl64\\driverquery.exe\" /sc minute /mo 1 /F"
  154.  
  155.  
  156.  
  157.  
  158. "Description": "Creates a hidden or system file",
  159. "Details":
  160.  
  161. "file": "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe"
  162.  
  163.  
  164. "file": "C:\\Users\\user\\AppData\\Roaming\\remcos"
  165.  
  166.  
  167.  
  168.  
  169. "Description": "File has been identified by 48 Antiviruses on VirusTotal as malicious",
  170. "Details":
  171.  
  172. "MicroWorld-eScan": "Trojan.GenericKD.41548276"
  173.  
  174.  
  175. "FireEye": "Generic.mg.95829108b0e5f9eb"
  176.  
  177.  
  178. "CAT-QuickHeal": "PUA.Presenoker.S5304897"
  179.  
  180.  
  181. "McAfee": "Artemis!95829108B0E5"
  182.  
  183.  
  184. "Malwarebytes": "Backdoor.Remcos.AutoIt"
  185.  
  186.  
  187. "K7AntiVirus": "Trojan ( 700000111 )"
  188.  
  189.  
  190. "Alibaba": "Backdoor:Win32/Remcos.90bce6ee"
  191.  
  192.  
  193. "K7GW": "Trojan ( 700000111 )"
  194.  
  195.  
  196. "Cybereason": "malicious.8b0e5f"
  197.  
  198.  
  199. "Arcabit": "Trojan.Generic.D279F9F4"
  200.  
  201.  
  202. "Invincea": "heuristic"
  203.  
  204.  
  205. "F-Prot": "W32/AutoIt.JD.gen!Eldorado"
  206.  
  207.  
  208. "Symantec": "ML.Attribute.HighConfidence"
  209.  
  210.  
  211. "APEX": "Malicious"
  212.  
  213.  
  214. "Avast": "Win32:Trojan-gen"
  215.  
  216.  
  217. "ClamAV": "Win.Downloader.LokiBot-6962970-0"
  218.  
  219.  
  220. "Kaspersky": "Backdoor.Win32.Remcos.cxb"
  221.  
  222.  
  223. "BitDefender": "Trojan.GenericKD.41548276"
  224.  
  225.  
  226. "NANO-Antivirus": "Trojan.Win32.Remcos.fqrrmb"
  227.  
  228.  
  229. "Paloalto": "generic.ml"
  230.  
  231.  
  232. "Ad-Aware": "Trojan.GenericKD.41548276"
  233.  
  234.  
  235. "Emsisoft": "Trojan.GenericKD.41548276 (B)"
  236.  
  237.  
  238. "F-Secure": "Dropper.DR/AutoIt.Gen8"
  239.  
  240.  
  241. "DrWeb": "Trojan.Inject3.16009"
  242.  
  243.  
  244. "TrendMicro": "Trojan.AutoIt.CRYPTINJECT.SMA"
  245.  
  246.  
  247. "McAfee-GW-Edition": "BehavesLike.Win32.Dropper.vh"
  248.  
  249.  
  250. "Sophos": "Troj/AutoIt-CKU"
  251.  
  252.  
  253. "Ikarus": "Trojan.Autoit"
  254.  
  255.  
  256. "Cyren": "W32/AutoIt.JD.gen!Eldorado"
  257.  
  258.  
  259. "Avira": "DR/AutoIt.Gen8"
  260.  
  261.  
  262. "MAX": "malware (ai score=85)"
  263.  
  264.  
  265. "Antiy-AVL": "GrayWare/Autoit.ShellCode.a"
  266.  
  267.  
  268. "Microsoft": "VirTool:Win32/AutInject.CZ!bit"
  269.  
  270.  
  271. "Endgame": "malicious (high confidence)"
  272.  
  273.  
  274. "AegisLab": "Trojan.Win32.Remcos.m!c"
  275.  
  276.  
  277. "ZoneAlarm": "Backdoor.Win32.Remcos.cxb"
  278.  
  279.  
  280. "GData": "Trojan.GenericKD.41548276"
  281.  
  282.  
  283. "AhnLab-V3": "Win-Trojan/AutoInj.Exp"
  284.  
  285.  
  286. "Acronis": "suspicious"
  287.  
  288.  
  289. "ALYac": "Trojan.GenericKD.41548276"
  290.  
  291.  
  292. "Cylance": "Unsafe"
  293.  
  294.  
  295. "ESET-NOD32": "a variant of Win32/Injector.Autoit.DUR"
  296.  
  297.  
  298. "TrendMicro-HouseCall": "Trojan.AutoIt.CRYPTINJECT.SMA"
  299.  
  300.  
  301. "Fortinet": "AutoIt/Injector.DWD!tr"
  302.  
  303.  
  304. "AVG": "Win32:Trojan-gen"
  305.  
  306.  
  307. "Panda": "Trj/Genetic.gen"
  308.  
  309.  
  310. "CrowdStrike": "win/malicious_confidence_100% (W)"
  311.  
  312.  
  313. "Qihoo-360": "HEUR/QVM41.1.596F.Malware.Gen"
  314.  
  315.  
  316.  
  317.  
  318. "Description": "Attempts to modify browser security settings",
  319. "Details":
  320.  
  321.  
  322. "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
  323. "Details":
  324.  
  325. "target": "clamav:Win.Downloader.LokiBot-6962970-0, sha256:dc91ac8ad98558cdff91783713221ae4b5597178bdfae08569d09ac2bdca63d9, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  326.  
  327.  
  328. "dropped": "clamav:Win.Malware.Autoit-6985962-0, sha256:149a749d51ed86548bdcaa22f161a3295628469c0fada73f5db02ad7d9d8e392 , guest_paths:C:\\Users\\user\\AppData\\Roaming\\CapabilityAccessHandlers\\sfc.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  329.  
  330.  
  331. "dropped": "clamav:Win.Malware.Autoit-6985962-0, sha256:7210f2ca290296d1f6e61da4b3192ad19afd719d6cf77dbb2d6810734b349826 , guest_paths:C:\\Users\\user\\AppData\\Roaming\\remcos_agent_Protected.exe*C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  332.  
  333.  
  334. "dropped": "clamav:Win.Downloader.LokiBot-6962970-0, sha256:851a391675bd01b40a7279ea87d62a5d5c1c47383ee73c5c6d3e0627a283009c , guest_paths:C:\\Users\\user\\AppData\\Roaming\\RtDCpl64\\driverquery.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  335.  
  336.  
  337.  
  338.  
  339. "Description": "Creates a slightly modified copy of itself",
  340. "Details":
  341.  
  342. "file": "C:\\Users\\user\\AppData\\Roaming\\RtDCpl64\\driverquery.exe"
  343.  
  344.  
  345. "percent_match": 99
  346.  
  347.  
  348.  
  349.  
  350. "Description": "Anomalous binary characteristics",
  351. "Details":
  352.  
  353. "anomaly": "Actual checksum does not match that reported in PE header"
  354.  
  355.  
  356.  
  357.  
  358.  
  359. * Started Service:
  360.  
  361. * Mutexes:
  362. "bderepair",
  363. "Local\\ZoneAttributeCacheCounterMutex",
  364. "Local\\ZonesCacheCounterMutex",
  365. "Local\\ZonesLockedCacheCounterMutex",
  366. "MDMAppInstaller",
  367. "Remcos_Mutex_Inj",
  368. "Remcos-S1KNPZ",
  369. "Global\\ARM Update Mutex",
  370. "Global\\Acro Update Mutex",
  371. "100184D2-BDC3-477a-B8D3-65548B67914C_3052",
  372. "Global\\100184D2-BDC3-477a-B8D3-65548B67914C_1068",
  373. "com.adobe.acrobat.rna.RdrCefBrowserLock.DC",
  374. "Local\\WininetStartupMutex",
  375. "Local\\ZonesCounterMutex",
  376. "Local\\_!MSFTHISTORY!_",
  377. "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
  378. "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
  379. "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
  380. "Local\\!IETld!Mutex",
  381. "_!SHMSFTHISTORY!_",
  382. "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!mshist012019082120190822!",
  383. "CicLoadWinStaWinSta0",
  384. "Local\\MSCTF.CtfMonitorInstMutexDefault1"
  385.  
  386.  
  387. * Modified Files:
  388. "C:\\Users\\user\\AppData\\Roaming\\remcos_agent_Protected.exe",
  389. "C:\\Users\\user\\AppData\\Local\\Temp\\medical-application-form.pdf",
  390. "C:\\Users\\user\\AppData\\Roaming\\RtDCpl64\\driverquery.exe",
  391. "C:\\Users\\user\\AppData\\Roaming\\CapabilityAccessHandlers\\sfc.exe",
  392. "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe",
  393. "C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs",
  394. "C:\\Users\\user\\AppData\\Local\\Adobe\\Color\\Profiles\\wscRGB.icc",
  395. "C:\\Users\\user\\AppData\\Local\\Adobe\\Color\\Profiles\\wsRGB.icc",
  396. "C:\\Users\\user\\AppData\\Local\\Adobe\\Color\\ACECache11.lst",
  397. "C:\\Users\\user\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\ReaderMessages",
  398. "C:\\Users\\user\\AppData\\Local\\Adobe\\Acrobat\\DC\\UserCache.bin",
  399. "\\??\\pipe\\com.adobe.reader.rna.user.DC.0",
  400. "C:\\Users\\user\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\Reader\\DesktopNotification\\NotificationsDB\\notificationsDB",
  401. "C:\\Users\\user\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\Reader\\DesktopNotification\\NotificationsDB\\notificationsDB-journal",
  402. "C:\\Users\\user\\AppData\\Local\\Adobe\\Acrobat\\DC\\SharedDataEvents",
  403. "C:\\Users\\user\\AppData\\Local\\Adobe\\Acrobat\\DC\\SharedDataEvents-journal",
  404. "C:\\Users\\user\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\ReaderMessages-journal",
  405. "C:\\Windows\\sysnative\\Tasks\\setx",
  406. "C:\\Windows\\sysnative\\Tasks\\WWAHost",
  407. "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf",
  408. "C:\\Windows\\SoftwareDistribution\\DataStore\\DataStore.edb",
  409. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edb.chk",
  410. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
  411. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
  412. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
  413. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012019082120190822\\index.dat"
  414.  
  415.  
  416. * Deleted Files:
  417. "C:\\Windows\\Tasks\\setx.job",
  418. "C:\\Windows\\Tasks\\WWAHost.job",
  419. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edbtmp.log",
  420. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012019052620190527\\index.dat",
  421. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012019052620190527\\"
  422.  
  423.  
  424. * Modified Registry Keys:
  425. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  426. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  427. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos",
  428. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos",
  429. "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Acrobat\\DC\\DiskCabs",
  430. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC",
  431. "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Synchronizer\\DC",
  432. "HKEY_CURRENT_USER\\Software\\Adobe\\CommonFiles\\Usage\\AcrobatDC",
  433. "HKEY_CURRENT_USER\\Software\\Adobe\\CommonFiles\\Usage\\Reader DC",
  434. "HKEY_CURRENT_USER\\Software\\Adobe\\CommonFiles\\Usage\\Reader 19_Acrobat19_Reader_19.10.20069",
  435. "HKEY_LOCAL_MACHINE\\System\\Acrobatbrokerserverdispatchercpp789",
  436. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Installer",
  437. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Installer\\Migrated",
  438. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Language",
  439. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Language\\UseMUI",
  440. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Language\\next",
  441. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Language\\current",
  442. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Originals",
  443. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\ExitSection",
  444. "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Synchronizer\\DC\\Acrobat.com",
  445. "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Synchronizer\\DC\\Acrobat.com.v2",
  446. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVConnector",
  447. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVConnector\\cv1",
  448. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral",
  449. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cTaskPanes",
  450. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cTaskPanes\\cBasicCommentPane",
  451. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\FTEDialog",
  452. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\FlashDebug",
  453. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\OnBoardingSection",
  454. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\OnBoardingSection\\chomeView",
  455. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\SDI",
  456. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Selection",
  457. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Window",
  458. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Window\\cAVUIPopupList",
  459. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1",
  460. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\aFS",
  461. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\tDIText",
  462. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\tFileName",
  463. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\sFileAncestors",
  464. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\sDI",
  465. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\sDate",
  466. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVEntitlement",
  467. "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION",
  468. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION\\AcroRd32.exe",
  469. "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Synchronizer\\DC\\CredentialsV3",
  470. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\UsageMeasurement",
  471. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\IPM",
  472. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\D4AC88D2-7778-46EF-B497-923C2BF340FE\\Path",
  473. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\D4AC88D2-7778-46EF-B497-923C2BF340FE\\Hash",
  474. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\setx\\Id",
  475. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\setx\\Index",
  476. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\D4AC88D2-7778-46EF-B497-923C2BF340FE\\Triggers",
  477. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\D4AC88D2-7778-46EF-B497-923C2BF340FE\\DynamicInfo",
  478. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\B340FAEB-2E15-48C3-89FE-AB1CD5DB886F\\Path",
  479. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\B340FAEB-2E15-48C3-89FE-AB1CD5DB886F\\Hash",
  480. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\WWAHost\\Id",
  481. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\WWAHost\\Index",
  482. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\B340FAEB-2E15-48C3-89FE-AB1CD5DB886F\\Triggers",
  483. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\B340FAEB-2E15-48C3-89FE-AB1CD5DB886F\\DynamicInfo",
  484. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019082120190822",
  485. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019082120190822\\CachePath",
  486. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019082120190822\\CachePrefix",
  487. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019082120190822\\CacheLimit",
  488. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019082120190822\\CacheOptions",
  489. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019082120190822\\CacheRepair",
  490. "HKEY_LOCAL_MACHINE\\Software\\Adobe\\Acrobat Reader\\DC\\AdobeViewer",
  491. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Adobe\\Acrobat Reader\\DC\\AdobeViewer\\EULA",
  492. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AdobeViewer",
  493. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AdobeViewer\\EULA"
  494.  
  495.  
  496. * Deleted Registry Keys:
  497. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  498. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  499. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  500. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  501. "HKEY_CURRENT_USER\\Software\\Adobe\\CommonFiles\\Usage\\Reader DC\\OptIn",
  502. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\setx.job",
  503. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\setx.job.fp",
  504. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\WWAHost.job",
  505. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\WWAHost.job.fp",
  506. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFavoritesInitialSelection",
  507. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFeedsInitialSelection"
  508.  
  509.  
  510. * DNS Communications:
  511.  
  512. * Domains:
  513.  
  514. * Network Communication - ICMP:
  515.  
  516. * Network Communication - HTTP:
  517.  
  518. * Network Communication - SMTP:
  519.  
  520. * Network Communication - Hosts:
  521.  
  522. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment