paladin316

cli-32_exe_2019-07-09_09_30.txt

Jul 9th, 2019
2,081
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 68.64 KB | None | 0 0
  1.  
  2. * MalFamily: "Neshta"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "cli-32.exe"
  7. * File Size: 107008
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "f12ec40aed9da26e4ab3ed94c6242eac0dc27abc6dbfffdbf713e5ea524bf5d3"
  10. * MD5: "d8b855b39421548acdc842b1a1dbd0e9"
  11. * SHA1: "f34cbe71ce66b1d5e77948b870f3d7fe62d3020f"
  12. * SHA512: "2b7efac4c6ac83091be96191b41676a77546732b0f7c2eaa8ee131ccbe1cede9f21514c43aab453161b2e67bea272855aebce821c7038cd687c89f66403c1486"
  13. * CRC32: "917D427D"
  14. * SSDEEP: "1536:JxqjQ+P04wsmJCDNu4GhQkfnLq01weW5yX3jFxv4b:sr85ChTGhQl3ym"
  15.  
  16. * Process Execution:
  17. "cli-32.exe",
  18. "cli-32.exe"
  19.  
  20.  
  21. * Executed Commands:
  22. "C:\\Users\\user\\AppData\\Local\\Temp\\3582-490\\cli-32.exe "
  23.  
  24.  
  25. * Signatures Detected:
  26.  
  27. "Description": "Possible date expiration check, exits too soon after checking local time",
  28. "Details":
  29.  
  30. "process": "cli-32.exe, PID 1752"
  31.  
  32.  
  33.  
  34.  
  35. "Description": "Reads data out of its own binary image",
  36. "Details":
  37.  
  38. "self_read": "process: cli-32.exe, pid: 1752, offset: 0x00000000, length: 0x0001a200"
  39.  
  40.  
  41.  
  42.  
  43. "Description": "Drops a binary and executes it",
  44. "Details":
  45.  
  46. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\3582-490\\cli-32.exe"
  47.  
  48.  
  49.  
  50.  
  51. "Description": "Installs itself for autorun at Windows startup",
  52. "Details":
  53.  
  54. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)"
  55.  
  56.  
  57. "data": "C:\\Windows\\svchost.com \"%1\" %*"
  58.  
  59.  
  60.  
  61.  
  62. "Description": "Likely virus infection of existing system binary",
  63. "Details":
  64.  
  65. "file": "c:\\python27\\lib\\site-packages\\pip\\_vendor\\distlib\\w64.exe"
  66.  
  67.  
  68. "file": "c:\\python27\\lib\\site-packages\\pip\\_vendor\\distlib\\w32.exe"
  69.  
  70.  
  71. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-8.0.exe"
  72.  
  73.  
  74. "file": "c:\\program files (x86)\\microsoft office\\office15\\iecontentservice.exe"
  75.  
  76.  
  77. "file": "c:\\program files (x86)\\microsoft office\\office15\\namecontrolserver.exe"
  78.  
  79.  
  80. "file": "c:\\program files (x86)\\microsoft office\\office15\\ocpubmgr.exe"
  81.  
  82.  
  83. "file": "c:\\program files (x86)\\microsoft office\\office15\\msohtmed.exe"
  84.  
  85.  
  86. "file": "c:\\python27\\lib\\distutils\\command\\wininst-9.0.exe"
  87.  
  88.  
  89. "file": "c:\\program files (x86)\\microsoft office\\office15\\xlicons.exe"
  90.  
  91.  
  92. "file": "c:\\program files (x86)\\google\\chrome\\application\\chrome_proxy.exe"
  93.  
  94.  
  95. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\pip\\_vendor\\distlib\\w64.exe"
  96.  
  97.  
  98. "file": "c:\\program files (x86)\\microsoft office\\office15\\accicons.exe"
  99.  
  100.  
  101. "file": "c:\\users\\user\\appdata\\local\\microsoft\\onedrive\\17.3.4604.0120\\onedrivesetup.exe"
  102.  
  103.  
  104. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\acrobroker.exe"
  105.  
  106.  
  107. "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\msosqm.exe"
  108.  
  109.  
  110. "file": "c:\\program files (x86)\\microsoft office\\office15\\clview.exe"
  111.  
  112.  
  113. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\setuptools\\gui.exe"
  114.  
  115.  
  116. "file": "c:\\program files (x86)\\microsoft office\\office15\\onenotem.exe"
  117.  
  118.  
  119. "file": "c:\\program files (x86)\\common files\\java\\java update\\jusched.exe"
  120.  
  121.  
  122. "file": "c:\\program files (x86)\\google\\update\\google_disabled_update.exe"
  123.  
  124.  
  125. "file": "c:\\program files (x86)\\common files\\microsoft shared\\source engine\\ose.exe"
  126.  
  127.  
  128. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\venv\\scripts\\nt\\pythonw.exe"
  129.  
  130.  
  131. "file": "c:\\program files (x86)\\microsoft analysis services\\as oledb\\110\\sqldumper.exe"
  132.  
  133.  
  134. "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googledisabledupdatesetup.exe"
  135.  
  136.  
  137. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-9.0-amd64.exe"
  138.  
  139.  
  140. "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\office setup controller\\setup.exe"
  141.  
  142.  
  143. "file": "c:\\program files (x86)\\common files\\oracle\\java\\javapath\\javaws.exe"
  144.  
  145.  
  146. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\scripts\\easy_install.exe"
  147.  
  148.  
  149. "file": "c:\\users\\user\\volumeid.exe"
  150.  
  151.  
  152. "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googledisabledupdatecore.exe"
  153.  
  154.  
  155. "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\fltldr.exe"
  156.  
  157.  
  158. "file": "c:\\msocache\\all users\\91150000-0011-0000-0000-0000000ff1ce-c\\ose.exe"
  159.  
  160.  
  161. "file": "c:\\program files (x86)\\microsoft office\\office15\\pptico.exe"
  162.  
  163.  
  164. "file": "c:\\program files (x86)\\microsoft office\\office15\\dcf\\filecompare.exe"
  165.  
  166.  
  167. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\acrord32.exe"
  168.  
  169.  
  170. "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\liclua.exe"
  171.  
  172.  
  173. "file": "c:\\python27\\lib\\site-packages\\pip\\_vendor\\distlib\\t64.exe"
  174.  
  175.  
  176. "file": "c:\\program files (x86)\\microsoft office\\office15\\setlang.exe"
  177.  
  178.  
  179. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\setuptools\\cli-64.exe"
  180.  
  181.  
  182. "file": "c:\\python27\\lib\\site-packages\\setuptools\\cli-64.exe"
  183.  
  184.  
  185. "file": "c:\\program files (x86)\\common files\\microsoft shared\\dw\\dw20.exe"
  186.  
  187.  
  188. "file": "c:\\program files (x86)\\microsoft office\\office15\\vpreview.exe"
  189.  
  190.  
  191. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\setuptools\\gui-64.exe"
  192.  
  193.  
  194. "file": "c:\\python27\\scripts\\pip2.exe"
  195.  
  196.  
  197. "file": "c:\\program files (x86)\\microsoft office\\office15\\msosync.exe"
  198.  
  199.  
  200. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\eula.exe"
  201.  
  202.  
  203. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\adelrcp.exe"
  204.  
  205.  
  206. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-9.0.exe"
  207.  
  208.  
  209. "file": "c:\\program files (x86)\\google\\update\\download\\430fd4d0-b729-4f61-aa34-91526481799d\\1.3.34.11\\googleupdatesetup.exe"
  210.  
  211.  
  212. "file": "c:\\python27\\scripts\\easy_install.exe"
  213.  
  214.  
  215. "file": "c:\\program files (x86)\\common files\\microsoft shared\\vsto\\10.0\\vstoinstaller.exe"
  216.  
  217.  
  218. "file": "c:\\program files (x86)\\common files\\microsoft shared\\equation\\eqnedt32.exe"
  219.  
  220.  
  221. "file": "c:\\python27\\lib\\site-packages\\setuptools\\gui-32.exe"
  222.  
  223.  
  224. "file": "c:\\program files (x86)\\microsoft office\\office15\\misc.exe"
  225.  
  226.  
  227. "file": "c:\\program files (x86)\\microsoft office\\office15\\ucmapi.exe"
  228.  
  229.  
  230. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\scripts\\easy_install-3.7.exe"
  231.  
  232.  
  233. "file": "c:\\program files (x86)\\microsoft office\\office15\\dcf\\databasecompare.exe"
  234.  
  235.  
  236. "file": "c:\\users\\user\\appdata\\local\\microsoft\\onedrive\\17.3.4604.0120\\filesyncconfig.exe"
  237.  
  238.  
  239. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\pip\\_vendor\\distlib\\t32.exe"
  240.  
  241.  
  242. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\fulltrustnotifier.exe"
  243.  
  244.  
  245. "file": "c:\\users\\user\\appdata\\local\\microsoft\\onedrive\\17.3.4604.0120_1\\onedrivesetup.exe"
  246.  
  247.  
  248. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-10.0-amd64.exe"
  249.  
  250.  
  251. "file": "c:\\program files (x86)\\microsoft office\\office15\\graph.exe"
  252.  
  253.  
  254. "file": "c:\\program files (x86)\\microsoft office\\office15\\msqry32.exe"
  255.  
  256.  
  257. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-14.0.exe"
  258.  
  259.  
  260. "file": "c:\\program files (x86)\\google\\chrome\\application\\chrome.exe"
  261.  
  262.  
  263. "file": "c:\\python27\\removepil.exe"
  264.  
  265.  
  266. "file": "c:\\users\\user\\appdata\\local\\microsoft\\onedrive\\onedrive.exe"
  267.  
  268.  
  269. "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googledisabledupdatewebplugin.exe"
  270.  
  271.  
  272. "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googlecrashhandler64.exe"
  273.  
  274.  
  275. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\setuptools\\cli-32.exe"
  276.  
  277.  
  278. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\acrotextextractor.exe"
  279.  
  280.  
  281. "file": "c:\\programdata\\adobe\\setup\\ac76ba86-7ad7-1033-7b44-ac0f074e4100\\setup.exe"
  282.  
  283.  
  284. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\setuptools\\gui-32.exe"
  285.  
  286.  
  287. "file": "c:\\python27\\lib\\distutils\\command\\wininst-7.1.exe"
  288.  
  289.  
  290. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\logtransport2.exe"
  291.  
  292.  
  293. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-14.0-amd64.exe"
  294.  
  295.  
  296. "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googledisabledupdatebroker.exe"
  297.  
  298.  
  299. "file": "c:\\python27\\w9xpopen.exe"
  300.  
  301.  
  302. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\plug_ins\\pi_brokers\\32bitmapibroker.exe"
  303.  
  304.  
  305. "file": "c:\\users\\user\\appdata\\local\\apps\\2.0\\z0gkgt47.zk6\\lg8n4v75.0o7\\clic...exe_9ae46cec200785df_0001.0003_none_a8944a4a5d6278ab\\googleupdatesetup.exe"
  306.  
  307.  
  308. "file": "c:\\program files (x86)\\microsoft office\\office15\\cnfnot32.exe"
  309.  
  310.  
  311. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\pythonw.exe"
  312.  
  313.  
  314. "file": "c:\\program files (x86)\\common files\\oracle\\java\\javapath\\javaw.exe"
  315.  
  316.  
  317. "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\office setup controller\\odeploy.exe"
  318.  
  319.  
  320. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\venv\\scripts\\nt\\python.exe"
  321.  
  322.  
  323. "file": "c:\\python27\\lib\\site-packages\\setuptools\\cli.exe"
  324.  
  325.  
  326. "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\olicenseheartbeat.exe"
  327.  
  328.  
  329. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\setuptools\\cli.exe"
  330.  
  331.  
  332. "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googledisabledupdatecomregistershell64.exe"
  333.  
  334.  
  335. "file": "c:\\program files (x86)\\google\\chrome\\application\\74.0.3729.169\\installer\\setup.exe"
  336.  
  337.  
  338. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\pip\\_vendor\\distlib\\w32.exe"
  339.  
  340.  
  341. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\python.exe"
  342.  
  343.  
  344. "file": "c:\\program files (x86)\\common files\\adobe\\arm\\1.0\\adobearm.exe"
  345.  
  346.  
  347. "file": "c:\\program files (x86)\\google\\chrome\\application\\74.0.3729.169\\elevation_service.exe"
  348.  
  349.  
  350. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\scripts\\pip.exe"
  351.  
  352.  
  353. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\scripts\\pip3.7.exe"
  354.  
  355.  
  356. "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\oarpmany.exe"
  357.  
  358.  
  359. "file": "c:\\program files (x86)\\microsoft office\\office15\\pdfreflow.exe"
  360.  
  361.  
  362. "file": "c:\\users\\user\\devmanview.exe"
  363.  
  364.  
  365. "file": "c:\\program files (x86)\\microsoft office\\office15\\powerpnt.exe"
  366.  
  367.  
  368. "file": "c:\\program files (x86)\\microsoft office\\office15\\dcf\\spreadsheetcompare.exe"
  369.  
  370.  
  371. "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\msoxmled.exe"
  372.  
  373.  
  374. "file": "c:\\program files (x86)\\common files\\microsoft shared\\dw\\dwtrig20.exe"
  375.  
  376.  
  377. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\acrocef\\rdrcef.exe"
  378.  
  379.  
  380. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\arh.exe"
  381.  
  382.  
  383. "file": "c:\\program files (x86)\\microsoft office\\office15\\protocolhandler.exe"
  384.  
  385.  
  386. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\reader_sl.exe"
  387.  
  388.  
  389. "file": "c:\\python27\\scripts\\pip.exe"
  390.  
  391.  
  392. "file": "c:\\program files (x86)\\microsoft office\\office15\\firstrun.exe"
  393.  
  394.  
  395. "file": "c:\\program files (x86)\\common files\\adobe\\arm\\1.0\\adobearmhelper.exe"
  396.  
  397.  
  398. "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\csisyncclient.exe"
  399.  
  400.  
  401. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\pip\\_vendor\\distlib\\t64.exe"
  402.  
  403.  
  404. "file": "c:\\program files (x86)\\google\\chrome\\application\\74.0.3729.169\\installer\\chrmstp.exe"
  405.  
  406.  
  407. "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googledisabledupdateondemand.exe"
  408.  
  409.  
  410. "file": "c:\\python27\\lib\\site-packages\\pip\\_vendor\\distlib\\t32.exe"
  411.  
  412.  
  413. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\wow_helper.exe"
  414.  
  415.  
  416. "file": "c:\\program files (x86)\\common files\\java\\java update\\jaureg.exe"
  417.  
  418.  
  419. "file": "c:\\program files (x86)\\microsoft office\\office15\\onenote.exe"
  420.  
  421.  
  422. "file": "c:\\python27\\lib\\distutils\\command\\wininst-9.0-amd64.exe"
  423.  
  424.  
  425. "file": "c:\\python27\\scripts\\pip2.7.exe"
  426.  
  427.  
  428. "file": "c:\\users\\user\\appdata\\local\\microsoft\\onedrive\\17.3.4604.0120_1\\filesyncconfig.exe"
  429.  
  430.  
  431. "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googlecrashhandler.exe"
  432.  
  433.  
  434. "file": "c:\\users\\user\\appdata\\local\\package cache\\c0f1e976-f585-48f8-968d-48c870496d4e\\python-3.7.2-amd64.exe"
  435.  
  436.  
  437. "file": "c:\\msocache\\all users\\91150000-0011-0000-0000-0000000ff1ce-c\\setup.exe"
  438.  
  439.  
  440. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\plug_ins\\pi_brokers\\64bitmapibroker.exe"
  441.  
  442.  
  443. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\browser\\wcchromeextn\\wcchromenativemessaginghost.exe"
  444.  
  445.  
  446. "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\adobecollabsync.exe"
  447.  
  448.  
  449. "file": "c:\\program files (x86)\\google\\chrome\\application\\74.0.3729.169\\notification_helper.exe"
  450.  
  451.  
  452. "file": "c:\\python27\\lib\\distutils\\command\\wininst-6.0.exe"
  453.  
  454.  
  455. "file": "c:\\program files (x86)\\microsoft office\\office15\\lynchtmlconv.exe"
  456.  
  457.  
  458. "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\msoicons.exe"
  459.  
  460.  
  461. "file": "c:\\program files (x86)\\microsoft office\\office15\\wordicon.exe"
  462.  
  463.  
  464. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\scripts\\pip3.exe"
  465.  
  466.  
  467. "file": "c:\\program files (x86)\\microsoft office\\office15\\infopath.exe"
  468.  
  469.  
  470. "file": "c:\\program files (x86)\\microsoft office\\office15\\msouc.exe"
  471.  
  472.  
  473. "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\google_disabledupdate.exe"
  474.  
  475.  
  476. "file": "c:\\programdata\\microsoft\\clicktorun\\9ac08e99-230b-47e8-9721-4577b7f124ea\\integrator.exe"
  477.  
  478.  
  479. "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\cmigrate.exe"
  480.  
  481.  
  482. "file": "c:\\python27\\lib\\distutils\\command\\wininst-8.0.exe"
  483.  
  484.  
  485. "file": "c:\\program files (x86)\\microsoft office\\office15\\selfcert.exe"
  486.  
  487.  
  488. "file": "c:\\program files (x86)\\microsoft office\\office15\\winword.exe"
  489.  
  490.  
  491. "file": "c:\\python27\\scripts\\easy_install-2.7.exe"
  492.  
  493.  
  494. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-10.0.exe"
  495.  
  496.  
  497. "file": "c:\\python27\\lib\\site-packages\\setuptools\\gui.exe"
  498.  
  499.  
  500. "file": "c:\\program files (x86)\\common files\\oracle\\java\\javapath\\java.exe"
  501.  
  502.  
  503. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-7.1.exe"
  504.  
  505.  
  506. "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-6.0.exe"
  507.  
  508.  
  509. "file": "c:\\program files (x86)\\common files\\java\\java update\\jucheck.exe"
  510.  
  511.  
  512. "file": "c:\\program files (x86)\\microsoft onedrive\\onedrivesetup.exe"
  513.  
  514.  
  515. "file": "c:\\program files (x86)\\microsoft office\\office15\\groove.exe"
  516.  
  517.  
  518. "file": "c:\\python27\\lib\\site-packages\\setuptools\\cli-32.exe"
  519.  
  520.  
  521. "file": "c:\\python27\\lib\\site-packages\\setuptools\\gui-64.exe"
  522.  
  523.  
  524.  
  525.  
  526. "Description": "File has been identified by 65 Antiviruses on VirusTotal as malicious",
  527. "Details":
  528.  
  529. "Bkav": "W32.NeshtaB.PE"
  530.  
  531.  
  532. "MicroWorld-eScan": "Win32.Neshta.A"
  533.  
  534.  
  535. "CMC": "Virus.Win32.Neshta!O"
  536.  
  537.  
  538. "CAT-QuickHeal": "W32.Neshta.C8"
  539.  
  540.  
  541. "McAfee": "W32/HLLP.41472.e"
  542.  
  543.  
  544. "Cylance": "Unsafe"
  545.  
  546.  
  547. "Zillya": "Virus.Neshta.Win32.1"
  548.  
  549.  
  550. "K7AntiVirus": "Virus ( 700000131 )"
  551.  
  552.  
  553. "Alibaba": "Virus:Win32/Neshta.8ec2026a"
  554.  
  555.  
  556. "K7GW": "Virus ( 700000131 )"
  557.  
  558.  
  559. "Cybereason": "malicious.394215"
  560.  
  561.  
  562. "Baidu": "Win32.Virus.Neshta.a"
  563.  
  564.  
  565. "F-Prot": "W32/Trojan2.PZKG"
  566.  
  567.  
  568. "Symantec": "Trojan.Gen.6"
  569.  
  570.  
  571. "TotalDefense": "Win32/Neshta.A"
  572.  
  573.  
  574. "APEX": "Malicious"
  575.  
  576.  
  577. "Paloalto": "generic.ml"
  578.  
  579.  
  580. "ClamAV": "Win.Trojan.Neshuta-1"
  581.  
  582.  
  583. "Kaspersky": "Virus.Win32.Neshta.a"
  584.  
  585.  
  586. "BitDefender": "Win32.Neshta.A"
  587.  
  588.  
  589. "NANO-Antivirus": "Trojan.Win32.Winlock.fmobyw"
  590.  
  591.  
  592. "ViRobot": "Win32.Neshta.Gen.A"
  593.  
  594.  
  595. "Endgame": "malicious (high confidence)"
  596.  
  597.  
  598. "Sophos": "W32/Bloat-A"
  599.  
  600.  
  601. "Comodo": "Win32.Neshta.A@3ypg"
  602.  
  603.  
  604. "F-Secure": "Malware.W32/Neshta.A"
  605.  
  606.  
  607. "DrWeb": "Win32.HLLP.Neshta"
  608.  
  609.  
  610. "VIPRE": "Virus.Win32.Neshta.a (v)"
  611.  
  612.  
  613. "Invincea": "heuristic"
  614.  
  615.  
  616. "McAfee-GW-Edition": "BehavesLike.Win32.HLLP.ch"
  617.  
  618.  
  619. "Trapmine": "malicious.high.ml.score"
  620.  
  621.  
  622. "FireEye": "Generic.mg.d8b855b39421548a"
  623.  
  624.  
  625. "Emsisoft": "Win32.Neshta.A (B)"
  626.  
  627.  
  628. "Ikarus": "Virus.Win32.Neshta"
  629.  
  630.  
  631. "Cyren": "W32/Trojan.OBIX-2981"
  632.  
  633.  
  634. "Jiangmin": "Virus.Neshta.a"
  635.  
  636.  
  637. "Avira": "W32/Neshta.A"
  638.  
  639.  
  640. "eGambit": "Unsafe.AI_Score_99%"
  641.  
  642.  
  643. "MAX": "malware (ai score=100)"
  644.  
  645.  
  646. "Antiy-AVL": "Virus/Win32.Neshta.a"
  647.  
  648.  
  649. "Kingsoft": "Win32.Neshta.nl.30720"
  650.  
  651.  
  652. "Microsoft": "Virus:Win32/Neshta.A"
  653.  
  654.  
  655. "Arcabit": "Win32.Neshta.A"
  656.  
  657.  
  658. "ZoneAlarm": "Virus.Win32.Neshta.a"
  659.  
  660.  
  661. "GData": "Win32.Virus.Neshta.A"
  662.  
  663.  
  664. "AhnLab-V3": "Win32/Neshta"
  665.  
  666.  
  667. "Acronis": "suspicious"
  668.  
  669.  
  670. "ALYac": "Win32.Neshta.A"
  671.  
  672.  
  673. "TACHYON": "Virus/W32.Neshta"
  674.  
  675.  
  676. "VBA32": "Virus.Win32.Neshta.a"
  677.  
  678.  
  679. "Malwarebytes": "Virus.Neshta"
  680.  
  681.  
  682. "Panda": "W32/Neshta.A"
  683.  
  684.  
  685. "Zoner": "Virus.Win32.19514"
  686.  
  687.  
  688. "ESET-NOD32": "Win32/Neshta.A"
  689.  
  690.  
  691. "TrendMicro-HouseCall": "PE_NESHTA.A"
  692.  
  693.  
  694. "Tencent": "Virus.Win32.Neshta.a"
  695.  
  696.  
  697. "Yandex": "Win32.Neshta.A"
  698.  
  699.  
  700. "SentinelOne": "DFI - Malicious PE"
  701.  
  702.  
  703. "MaxSecure": "Virus.Infector.Gen9"
  704.  
  705.  
  706. "Fortinet": "W32/Neshta.A"
  707.  
  708.  
  709. "Ad-Aware": "Win32.Neshta.A"
  710.  
  711.  
  712. "AVG": "Win32:Apanas Trj"
  713.  
  714.  
  715. "Avast": "Win32:Apanas Trj"
  716.  
  717.  
  718. "CrowdStrike": "win/malicious_confidence_100% (W)"
  719.  
  720.  
  721. "Qihoo-360": "Virus.Win32.Neshta.B"
  722.  
  723.  
  724.  
  725.  
  726. "Description": "Detects VirtualBox through the presence of a file",
  727. "Details":
  728.  
  729. "file": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vboxguest.inf_amd64_neutral_aaf5cae56df6be2b\\VBoxControl.exe"
  730.  
  731.  
  732. "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxControl.exe"
  733.  
  734.  
  735. "file": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vboxguest.inf_amd64_neutral_aaf5cae56df6be2b\\VBoxTray.exe"
  736.  
  737.  
  738. "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxTray.exe"
  739.  
  740.  
  741. "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxDrvInst.exe"
  742.  
  743.  
  744. "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxWHQLFake.exe"
  745.  
  746.  
  747. "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxControl.exe"
  748.  
  749.  
  750. "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxWHQLFake.exe"
  751.  
  752.  
  753. "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\uninst.exe"
  754.  
  755.  
  756. "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxDrvInst.exe"
  757.  
  758.  
  759. "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxTray.exe"
  760.  
  761.  
  762.  
  763.  
  764. "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
  765. "Details":
  766.  
  767. "target": "clamav:Win.Trojan.Neshuta-1, sha256:f12ec40aed9da26e4ab3ed94c6242eac0dc27abc6dbfffdbf713e5ea524bf5d3, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  768.  
  769.  
  770. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:89afb02f331e50a5c8df5095de66437a8eb4deae194cd77f76cf11c32a161c46 , guest_paths:C:\\Users\\user\\DevManView.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  771.  
  772.  
  773.  
  774.  
  775. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:5c3ef3ec7594c040146e908014791dd15201ba58b4d70032770bb661b6a0e394 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Eula.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  776.  
  777.  
  778.  
  779.  
  780. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:869d5ca37263a7c0a59414ab38e4e501eff3cb8f1dbafc33c97aff1513cdf668 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOUC.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  781.  
  782.  
  783. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:cb17794b3b15002bbb49ba23455dbb49abc6c1f68d616f1ae633fed3b7e817aa , guest_paths:C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath\\javaw.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  784.  
  785.  
  786.  
  787.  
  788.  
  789.  
  790. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:ded54d1fcca07b6bff2bc3b9a1131eac29ff1f836e5d7a7c5c325ec5abe96e29 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroTextExtractor.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  791.  
  792.  
  793. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:ba3dc87fca4641e5f5486c4d50c09d087e65264e6c5c885fa6866f6ccb23167b , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\EQUATION\\EQNEDT32.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  794.  
  795.  
  796. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:28d8a9c50eca6f73bdea888d5132bf16ce87ad4f7b2dd2d10b2729fadc0fd5a9 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOHTMED.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  797.  
  798.  
  799. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:31da9632f5d25806b77b617d48da52a14afc574bbe1653120f97705284ea566c , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroCEF\\RdrCEF.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  800.  
  801.  
  802. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:8384cb761b1a34ac1e4184b9e85d438b6ca6eeef19493b9ee5b568d280ee64ba , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\PPTICO.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  803.  
  804.  
  805. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:2ec470364d4c51ac8a55c18333a508117718774e13ce3d34af67566937ebadb4 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\GRAPH.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  806.  
  807.  
  808. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:75189debfc73a223a5297becd778b9d2710f3683c76db93ae40a62c5be42c56f , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateWebPlugin.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  809.  
  810.  
  811.  
  812.  
  813. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:7615625c3f23c63f1ba25103f023f81379e124bee0852ee7bebb453e2782d30a , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\INFOPATH.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  814.  
  815.  
  816. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:5f0e4dd286b7e861c1b8c4ee60748b7881ab627c2f50495c35b6fa24cd92ee6f , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\MSOSQM.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  817.  
  818.  
  819. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:d6543117296029ed5f927a812b2269bfc3edcfceca7c3a4fb2c36ee6b8791fa1 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\CLVIEW.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  820.  
  821.  
  822. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:6c7fcba8eddbf20d3ccf97ec075d55ee7fea49140a7e9f5b36e96abaa6c5ab70 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\WINWORD.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  823.  
  824.  
  825. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:236f874e3627f1be2c597edf64b15c786c5d22bfcdeed410e6f3b1c0f0230fee , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\DW\\DWTRIG20.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  826.  
  827.  
  828. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:1586287394a7d5c1a0d52b256bb631961a4b05b873307c78896b79709e7713c9 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\UcMapi.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  829.  
  830.  
  831. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:f93f83c0cdf496ee620ed85075329c6f9e940956601a1b38022c5a74d07e74d0 , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\Google_DisabledUpdate.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  832.  
  833.  
  834. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:8349368189fb5c09e4449650c692f7f87076f3767253654dc5ebcb4d16a4e407 , guest_paths:C:\\Program Files (x86)\\Microsoft Analysis Services\\AS OLEDB\\110\\SQLDumper.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  835.  
  836.  
  837.  
  838.  
  839.  
  840.  
  841. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:2c35c0c38ef5831080f331a8cb11f13d336fcaa54b816559d8a1807396de0ae8 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\DW\\DW20.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  842.  
  843.  
  844. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:ae631ff5c823943333c015767bf2f75120bd3eaee6dc4300145546d842cf4b4e , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\FIRSTRUN.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  845.  
  846.  
  847. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:5546be6a6bf4550c1474d6a0770e5d71dc724faf869e1cb73a08baf2ecf1a6a4 , guest_paths:C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\elevation_service.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  848.  
  849.  
  850. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:53c581cd602c26a0a2e083526ae542134b190f5af5def89373a4023d22b06cef , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\SETLANG.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  851.  
  852.  
  853. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:7b945c7e6b8bfbb489f003ecd1d0dcd4803042003de4646d4206114361a0fbbb , guest_paths:C:\\ProgramData\\Adobe\\Setup\\AC76BA86-7AD7-1033-7B44-AC0F074E4100\\setup.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  854.  
  855.  
  856. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:4c7ff6812cb9f902f41fc4bfdfbd3957f513089476317344bec3d450f2fb1e77 , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateCore.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  857.  
  858.  
  859. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:81210303bcc7d17cdaaab8127a21fbb63546c14b0d500eda041003a6da838aaa , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\protocolhandler.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  860.  
  861.  
  862.  
  863.  
  864. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:fe56a759976a51d32dac5beb3007d46ec0d33e039ed3f9db153706ba53384764 , guest_paths:C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  865.  
  866.  
  867. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:efd423639bfc9e29a2b2c5a67379129f13ff526b800dff8ab59bfc618c3f48bd , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\LICLUA.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  868.  
  869.  
  870.  
  871.  
  872. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:8c00a5ad372e9640237170a81091c68d277c84ac87cbac160d93e3a2292773d1 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AdobeCollabSync.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  873.  
  874.  
  875.  
  876.  
  877. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:ca4925b76cbf600bb139f1e0ea0d1dd41f3f6a624c5db4183e2b21f321f120e2 , guest_paths:C:\\Program Files (x86)\\Google\\Update\\Google_Disabled_Update.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  878.  
  879.  
  880. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:04f5259484d61831754af098e42d147c25d61f692a6da69bb88e2f01bf7c1679 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\VSTO\\10.0\\VSTOInstaller.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  881.  
  882.  
  883. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:e5691950da34f55769713edbf363e0fbb30ad4033adff24274de064c6a4b2d2e , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\POWERPNT.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  884.  
  885.  
  886. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:b3c7e32e6d1c27bc9e67060e68acd8ccfe46e44c48a210d00a0d6cae09421ff8 , guest_paths:C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\notification_helper.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  887.  
  888.  
  889.  
  890.  
  891. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:7f61f059580b9725b0958e03680d47c810c9b8a2a9ea2560efe96e9231923227 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\MSOICONS.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  892.  
  893.  
  894. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:f007e668f327693c4b383dfc9f4182ff594e9567919599060566e3cb400ad3ef , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateBroker.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  895.  
  896.  
  897.  
  898.  
  899. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:4282942497c44db2858e9c87133df1ad38a141bc6b537dc39b2d8f416bf68d4c , guest_paths:C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jaureg.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  900.  
  901.  
  902. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:e09f9db05d7d0d7290b75a57d3ef039671403dea5129d1d4ba2c92da3f3b4a9e , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\NAMECONTROLSERVER.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  903.  
  904.  
  905. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:a12ca2ab6343a74478e269d104197a9b2da37e0bf982fff61e82786a52e6be66 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\CSISYNCCLIENT.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  906.  
  907.  
  908. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:58c679487241af3293eda35aded7f24f3de1dde970aecc8373513f6ff8526d51 , guest_paths:C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\Installer\\chrmstp.exe*C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\Installer\\setup.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  909.  
  910.  
  911. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:1b2523e1f7bc39d7edcc98b0d7da53f27aca6c42cc8e06c35579079759ad9b67 , guest_paths:C:\\Users\\user\\Volumeid.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  912.  
  913.  
  914.  
  915.  
  916. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:20f85a55cbf22da9bfebb0b7f91d8090c87ec0d0b12e34a60a38081bea4f9e16 , guest_paths:C:\\Users\\user\\AppData\\Local\\Apps\\2.0\\Z0GKGT47.ZK6\\LG8N4V75.0O7\\clic...exe_9ae46cec200785df_0001.0003_none_a8944a4a5d6278ab\\GoogleUpdateSetup.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  917.  
  918.  
  919. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:13a4d12283f7fb8d3e716f9f83bb4009714eb4ccec6a93ad906545b8075ef0de , guest_paths:C:\\Users\\user\\AppData\\Local\\Package Cache\\c0f1e976-f585-48f8-968d-48c870496d4e\\python-3.7.2-amd64.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  920.  
  921.  
  922. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:baeea6b31fba79056eae2d04be496939b9105d10a870b3d3faff3c6f0645d159 , guest_paths:C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  923.  
  924.  
  925. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:888a1dd0033e5d758a4e731e3e55357de866e80d03b1b194375f714e1fd4351d , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroBroker.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  926.  
  927.  
  928.  
  929.  
  930. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:6b89693de25bd3a520e36d912f7ae5ada83d38101ebdf58fe0893dc9d25d65bf , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleCrashHandler.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  931.  
  932.  
  933.  
  934.  
  935. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:abbcff4ad295f2ce06c12ee70f49eabc029941de9d1c58dabfe6076400598225 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\FLTLDR.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  936.  
  937.  
  938.  
  939.  
  940. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:d89519fdfda1997aea4f2f85fdf909dc321635b192c7349d25047208aafd55d2 , guest_paths:C:\\MSOCache\\All Users\\91150000-0011-0000-0000-0000000FF1CE-C\\ose.exe*C:\\Program Files (x86)\\Common Files\\microsoft shared\\Source Engine\\OSE.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  941.  
  942.  
  943. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:b8f73f402b1664d7299999aa163264633988bfe5bfe0792bc3b8c5c7ac7e49c9 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\IEContentService.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  944.  
  945.  
  946. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:67367a327fb9f2730454bbed6ba558367cd3b95c6b19605763898ec5c45ecc9a , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\PDFREFLOW.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  947.  
  948.  
  949. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:e99e627bd16a06c30acaa3c2684abe3580c6c91e96f316dcc0db7e9125e2ce7f , guest_paths:C:\\Program Files (x86)\\Microsoft OneDrive\\OneDriveSetup.exe*C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120\\OneDriveSetup.exe*C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120_1\\OneDriveSetup.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  950.  
  951.  
  952. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:c9f2b59a9e7bddb95d4d1a137a19f27cfc3e5264a4a07552297ec288120cca11 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\DCF\\SPREADSHEETCOMPARE.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  953.  
  954.  
  955. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:663f7670be2c446f936d7c8d49b7a53f0b1e19faaa224719a751586aa3ca6749 , guest_paths:C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120\\FileSyncConfig.exe*C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120_1\\FileSyncConfig.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  956.  
  957.  
  958. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:990542871801e2c96b3ae82ce8c09bccb51eeef54965a0d72294483a6a546dff , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOSYNC.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  959.  
  960.  
  961. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:447780d418acf453f40c70b5389d07458d33056ff8f4185aec14851423ed62e6 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\VPREVIEW.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  962.  
  963.  
  964.  
  965.  
  966. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:d29ca7a2971d69e770e9b37653ea87092144b395125ba9d0be5128dcdd9da1a5 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\CNFNOT32.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  967.  
  968.  
  969. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:7513dd45316fe6eb1f7ab31ae8f048cf8492c38c26fe1a2080cb77bc74fc2868 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\DCF\\DATABASECOMPARE.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  970.  
  971.  
  972. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:8268d3fefe8ca96a25a73690d14bacf644170ab5e9e70d2f8eeb350a4c83f9f6 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroRd32.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  973.  
  974.  
  975. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:473eb551101caeaf2d18f811342e21de323c8dd19ed21011997716871defe997 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\LogTransport2.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  976.  
  977.  
  978. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:3709c99303695da84943b667960035706664d63f956f641ccbcc8b77f3bfe82c , guest_paths:C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome_proxy.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  979.  
  980.  
  981. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:35c7b6d9104df263883586d19819bf4e5e5ff95a3ae6b65b6f244e8828a2ddb0 , guest_paths:C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  982.  
  983.  
  984. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:097bf0f5b07c4834e4c65be0ad645362ce641e8cb72dfb46711ca254da70511d , guest_paths:C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\OneDrive.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  985.  
  986.  
  987.  
  988.  
  989. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:fe44ca8d5050932851aa54c23133277e66db939501af58e5aeb7b67ec1dde7b5 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\arh.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  990.  
  991.  
  992.  
  993.  
  994. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:7166949b9f878abc41422a8db12557c0ab415d23be363b427a058879507ff2a9 , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateComRegisterShell64.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  995.  
  996.  
  997. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:f80a3f3c95af2bcbaa559004e90de1e44810d26966ca93b4d1f2e269db743fb6 , guest_paths:C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath\\java.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  998.  
  999.  
  1000. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:86d23a419e95475b718488d022d4d7e22834f37d4d9d50d1bbd5743aee16aff5 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\DCF\\filecompare.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1001.  
  1002.  
  1003. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:b78d0aecf7b8bf5f3e171cd4a8b77cffbb00f8a1298ec4ec468e92de8515d905 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSQRY32.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1004.  
  1005.  
  1006. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:a89d31919609e00c9310adf1c465cfa948fa7689b8b09757a1751b671f235497 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\WORDICON.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1007.  
  1008.  
  1009. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:3e9da97a7106122245e77f13f3f3cc96c055d732ab841eb848d03ac25401c1bc , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\plug_ins\\pi_brokers\\32BitMAPIBroker.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1010.  
  1011.  
  1012. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:2f947e3ca624ce7373080b4a3934e21644fb070a53feeaae442b15b849c2954f , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\reader_sl.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1013.  
  1014.  
  1015. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:22a585c183e27b3c732028ff193733c2f9d03700a0e95e65c556b0592c43d880 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\plug_ins\\pi_brokers\\64BitMAPIBroker.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1016.  
  1017.  
  1018. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:a1e2d00be0f429ffa9543477370437256c6349ac7afacd2986b473d3edf53e88 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\OLicenseHeartbeat.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1019.  
  1020.  
  1021. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:72add3ab0d6b63f41eced2678370b93db65f8dfee4ae689ffafdf934e1f28f3b , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\Oarpmany.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1022.  
  1023.  
  1024. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:15beb2ed451fb7112081bd1d7bbdd6c3f0f3729743defe6db63c3eecf3fd63ae , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\ONENOTEM.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1025.  
  1026.  
  1027.  
  1028.  
  1029. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:d65f1a5a32138675659fc4271ecf34e7bd38928df6a920d53e5ef34e091403c2 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\OcPubMgr.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1030.  
  1031.  
  1032. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:28b61729de64e1f05978a0e992679c5331a33962219dd6c5f7eb5837267e0312 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\CMigrate.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1033.  
  1034.  
  1035. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:4dbe244a4fd91ed0957a51d903aad2e44f3735a378fe8e63def66ad6053ee8b0 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\ONENOTE.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1036.  
  1037.  
  1038. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:9288dea70d841fb45585d590b2b6a77a92466df8264161a0b76d5d6d58d0b0c5 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\GROOVE.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1039.  
  1040.  
  1041.  
  1042.  
  1043. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:980bac6c9afe8efc9c6fe459a5f77213b0d8524eb00de82437288eb96138b9a2 , guest_paths:C:\\Windows\\svchost.com, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1044.  
  1045.  
  1046. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:d21aad8e6916247dea8fe1be2341cf2ccefc7138b70a46d12f0229574d87a99b , guest_paths:C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath\\javaws.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1047.  
  1048.  
  1049. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:f6337da1d94005ad9e7db5f14734745b0cca171a84fbc689a1ba5071261a9751 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\Office Setup Controller\\ODeploy.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1050.  
  1051.  
  1052. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:cbbe90f7370a9658e56ddf446024df6cb5456700048511ba9ba0681c3c409fb3 , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateSetup.exe*C:\\Program Files (x86)\\Google\\Update\\Download\\430FD4D0-B729-4F61-AA34-91526481799D\\1.3.34.11\\GoogleUpdateSetup.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1053.  
  1054.  
  1055. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:ecd5e94da88c653e4c34b6ab325e0aca8824247b290336f75c410caa16381bc5 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Browser\\WCChromeExtn\\WCChromeNativeMessagingHost.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1056.  
  1057.  
  1058.  
  1059.  
  1060. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:5b26d41634ea456ab4a1594fdc0c483fec821a8d9105688e8060ae9628e8a1fd , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\Office Setup Controller\\Setup.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1061.  
  1062.  
  1063. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:c4dba9e0f68b7efc3f5ab014552ca7d96e62f6bcbcce09ab8e4b59cbce979e99 , guest_paths:C:\\MSOCache\\All Users\\91150000-0011-0000-0000-0000000FF1CE-C\\setup.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1064.  
  1065.  
  1066. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:19576842dd832bc3e7f617b86dfac0aeeefcbb5831cebc5227f731ecdeaafb96 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\lynchtmlconv.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1067.  
  1068.  
  1069. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:750824b5f75c91a6c2eeb8c5e60ae28d7a81e323d3762c8652255bfea5cba0bb , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\wow_helper.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1070.  
  1071.  
  1072. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:c8767dd56208c45a116b6b66e988fa436a055ba45202e09203af62696055307b , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\XLICONS.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1073.  
  1074.  
  1075. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:7f474c8c7643ab7a5aa9cdb27a93ecb7ca3f23ed8af916cb7fc5905f572cf732 , guest_paths:C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARMHelper.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1076.  
  1077.  
  1078.  
  1079.  
  1080.  
  1081.  
  1082. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:4b45150cb6145bd3c56bc3d950ae93db301adc74f604c820664d13868dad7e25 , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateOnDemand.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1083.  
  1084.  
  1085. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:5994fc2f0442124a9fe9db07b1c418350dd3cde7ca2d0cbf5dc92eb2c4086845 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\MSOXMLED.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1086.  
  1087.  
  1088.  
  1089.  
  1090.  
  1091.  
  1092. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:3f00404dd591c2856e6f71bd78423ed47199902e0b85f228e6c4de72c59ddffe , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\ADelRCP.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1093.  
  1094.  
  1095. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:d3257b833c29649f13b0a3da80fce9b814c0d79c11c56420e6e16eb22ef2b46b , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\SELFCERT.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1096.  
  1097.  
  1098. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:b08c170ee7fe714073486ad71706c9f5d23d7fad8b673ec65269fe7b9784cec5 , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleCrashHandler64.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1099.  
  1100.  
  1101. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:db023545a5c2653ab825e59b498486b29de128b805e2e1807c272a7f6c4390c3 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\misc.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1102.  
  1103.  
  1104. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:161f13cacf1df4a08b4f0a28e6869aafe08c37c3bde7e27c784be6e6523f686a , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\ACCICONS.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1105.  
  1106.  
  1107. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:16d65f2463658a72dba205dcaa18bc3d0bab4453e726233d68bc176e69db0950 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\FullTrustNotifier.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1108.  
  1109.  
  1110.  
  1111.  
  1112. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:18e7c31c2f44d6b49942717871d4b5a541e3472133d31665e1a71f5f26180841 , guest_paths:C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jucheck.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1113.  
  1114.  
  1115.  
  1116.  
  1117. "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:0da0b61e1c65ce4799f7a8b7a7d0d0c0ac896e373ec148ef13088b991bdfff6f , guest_paths:C:\\ProgramData\\Microsoft\\ClickToRun\\9AC08E99-230B-47e8-9721-4577B7F124EA\\integrator.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  1118.  
  1119.  
  1120.  
  1121.  
  1122. "Description": "Creates a copy of itself",
  1123. "Details":
  1124.  
  1125.  
  1126.  
  1127.  
  1128.  
  1129.  
  1130.  
  1131.  
  1132.  
  1133.  
  1134.  
  1135. "Description": "Creates a slightly modified copy of itself",
  1136. "Details":
  1137.  
  1138.  
  1139.  
  1140.  
  1141.  
  1142. "percent_match": 43
  1143.  
  1144.  
  1145.  
  1146.  
  1147.  
  1148.  
  1149.  
  1150.  
  1151.  
  1152.  
  1153. "percent_match": 46
  1154.  
  1155.  
  1156.  
  1157.  
  1158. "Description": "Anomalous binary characteristics",
  1159. "Details":
  1160.  
  1161. "anomaly": "Timestamp on binary predates the release date of the OS version it requires by at least a year"
  1162.  
  1163.  
  1164.  
  1165.  
  1166.  
  1167. * Started Service:
  1168.  
  1169. * Mutexes:
  1170. "MutexPolesskayaGlush*.*\\xc2\\x90svchost.com\\xc2\\x90exefile\\shell\\open\\command\\xe2\\x80\\xb9\\xc3\\x80 \"%1\" %*\\xc5\\x93\\xe2\\x80\\x98@"
  1171.  
  1172.  
  1173. * Modified Files:
  1174. "C:\\Users\\user\\AppData\\Local\\Temp\\3582-490\\cli-32.exe",
  1175. "C:\\Windows\\svchost.com",
  1176. "C:\\MSOCache\\All Users\\91150000-0011-0000-0000-0000000FF1CE-C\\ose.exe",
  1177. "C:\\MSOCache\\All Users\\91150000-0011-0000-0000-0000000FF1CE-C\\setup.exe",
  1178. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroBroker.exe",
  1179. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroCEF\\RdrCEF.exe",
  1180. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroRd32.exe",
  1181. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroTextExtractor.exe",
  1182. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\ADelRCP.exe",
  1183. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AdobeCollabSync.exe",
  1184. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\arh.exe",
  1185. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Browser\\WCChromeExtn\\WCChromeNativeMessagingHost.exe",
  1186. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Eula.exe",
  1187. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\FullTrustNotifier.exe",
  1188. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\LogTransport2.exe",
  1189. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\plug_ins\\pi_brokers\\32BitMAPIBroker.exe",
  1190. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\plug_ins\\pi_brokers\\64BitMAPIBroker.exe",
  1191. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\reader_sl.exe",
  1192. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\wow_helper.exe",
  1193. "C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe",
  1194. "C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARMHelper.exe",
  1195. "C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\armsvc.exe",
  1196. "C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jaureg.exe",
  1197. "C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jucheck.exe",
  1198. "C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe",
  1199. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\DW\\DW20.EXE",
  1200. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\DW\\DWTRIG20.EXE",
  1201. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\EQUATION\\EQNEDT32.EXE",
  1202. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\ink\\mip.exe",
  1203. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\MSInfo\\msinfo32.exe",
  1204. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\CMigrate.exe",
  1205. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\CSISYNCCLIENT.EXE",
  1206. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\FLTLDR.EXE",
  1207. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\LICLUA.EXE",
  1208. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\MSOICONS.EXE",
  1209. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\MSOSQM.EXE",
  1210. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\MSOXMLED.EXE",
  1211. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\Oarpmany.exe",
  1212. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\Office Setup Controller\\ODeploy.exe",
  1213. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\Office Setup Controller\\Setup.exe",
  1214. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\OLicenseHeartbeat.exe",
  1215. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\Source Engine\\OSE.EXE",
  1216. "C:\\Program Files (x86)\\Common Files\\microsoft shared\\VSTO\\10.0\\VSTOInstaller.exe",
  1217. "C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath\\java.exe",
  1218. "C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath\\javaw.exe",
  1219. "C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath\\javaws.exe",
  1220. "C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\elevation_service.exe",
  1221. "C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\Installer\\chrmstp.exe",
  1222. "C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\Installer\\setup.exe",
  1223. "C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\notification_helper.exe",
  1224. "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe",
  1225. "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome_proxy.exe",
  1226. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleCrashHandler.exe",
  1227. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleCrashHandler64.exe",
  1228. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateBroker.exe",
  1229. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateComRegisterShell64.exe",
  1230. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateCore.exe",
  1231. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateOnDemand.exe",
  1232. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateSetup.exe",
  1233. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateWebPlugin.exe",
  1234. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\Google_DisabledUpdate.exe",
  1235. "C:\\Program Files (x86)\\Google\\Update\\Download\\430FD4D0-B729-4F61-AA34-91526481799D\\1.3.34.11\\GoogleUpdateSetup.exe",
  1236. "C:\\Program Files (x86)\\Google\\Update\\Google_Disabled_Update.exe",
  1237. "C:\\Program Files (x86)\\Internet Explorer\\ExtExport.exe",
  1238. "C:\\Program Files (x86)\\Internet Explorer\\ieinstal.exe",
  1239. "C:\\Program Files (x86)\\Internet Explorer\\ielowutil.exe",
  1240. "C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
  1241. "C:\\Program Files (x86)\\Microsoft Analysis Services\\AS OLEDB\\110\\SQLDumper.exe",
  1242. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\ACCICONS.EXE",
  1243. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\CLVIEW.EXE",
  1244. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\CNFNOT32.EXE",
  1245. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\DCF\\DATABASECOMPARE.EXE",
  1246. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\DCF\\filecompare.exe",
  1247. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\DCF\\SPREADSHEETCOMPARE.EXE",
  1248. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\FIRSTRUN.EXE",
  1249. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\GRAPH.EXE",
  1250. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\GROOVE.EXE",
  1251. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\IEContentService.exe",
  1252. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\INFOPATH.EXE",
  1253. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\lynchtmlconv.exe",
  1254. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\misc.exe",
  1255. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOHTMED.EXE",
  1256. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOSYNC.EXE",
  1257. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOUC.EXE",
  1258. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSQRY32.EXE",
  1259. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\NAMECONTROLSERVER.EXE",
  1260. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\OcPubMgr.exe",
  1261. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\ONENOTE.EXE",
  1262. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\ONENOTEM.EXE",
  1263. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\PDFREFLOW.EXE",
  1264. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\POWERPNT.EXE",
  1265. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\PPTICO.EXE",
  1266. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\protocolhandler.exe",
  1267. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\SELFCERT.EXE",
  1268. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\SETLANG.EXE",
  1269. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\UcMapi.exe",
  1270. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\VPREVIEW.EXE",
  1271. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\WINWORD.EXE",
  1272. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\WORDICON.EXE",
  1273. "C:\\Program Files (x86)\\Microsoft Office\\Office15\\XLICONS.EXE",
  1274. "C:\\Program Files (x86)\\Microsoft OneDrive\\OneDriveSetup.exe",
  1275. "C:\\Program Files (x86)\\Windows Mail\\wab.exe",
  1276. "C:\\Program Files (x86)\\Windows Mail\\wabmig.exe",
  1277. "C:\\Program Files (x86)\\Windows Mail\\WinMail.exe",
  1278. "C:\\Program Files (x86)\\Windows NT\\Accessories\\wordpad.exe",
  1279. "C:\\Program Files (x86)\\Windows Photo Viewer\\ImagingDevices.exe",
  1280. "C:\\Program Files (x86)\\Windows Sidebar\\sidebar.exe",
  1281. "C:\\ProgramData\\Adobe\\Setup\\AC76BA86-7AD7-1033-7B44-AC0F074E4100\\setup.exe",
  1282. "C:\\ProgramData\\Microsoft\\ClickToRun\\9AC08E99-230B-47e8-9721-4577B7F124EA\\integrator.exe",
  1283. "C:\\Users\\user\\AppData\\Local\\Apps\\2.0\\Z0GKGT47.ZK6\\LG8N4V75.0O7\\clic...exe_9ae46cec200785df_0001.0003_none_a8944a4a5d6278ab\\GoogleUpdateSetup.exe",
  1284. "C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120\\FileSyncConfig.exe",
  1285. "C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120\\OneDriveSetup.exe",
  1286. "C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120_1\\FileSyncConfig.exe",
  1287. "C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120_1\\OneDriveSetup.exe",
  1288. "C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\OneDrive.exe",
  1289. "C:\\Users\\user\\AppData\\Local\\Package Cache\\c0f1e976-f585-48f8-968d-48c870496d4e\\python-3.7.2-amd64.exe",
  1290. "C:\\Users\\user\\DevManView.exe",
  1291. "C:\\Users\\user\\Volumeid.exe",
  1292. "C:\\Users\\user\\AppData\\Local\\Temp\\tmp5023.tmp"
  1293.  
  1294.  
  1295. * Deleted Files:
  1296.  
  1297. * Modified Registry Keys:
  1298. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)"
  1299.  
  1300.  
  1301. * Deleted Registry Keys:
  1302.  
  1303. * DNS Communications:
  1304.  
  1305. * Domains:
  1306.  
  1307. * Network Communication - ICMP:
  1308.  
  1309. * Network Communication - HTTP:
  1310.  
  1311. * Network Communication - SMTP:
  1312.  
  1313. * Network Communication - Hosts:
  1314.  
  1315. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment