Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Ispy"
- * MalScore: 10.0
- * File Name: "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html?file=mega_521d6c7c88"
- * File Size: 3007136
- * File Type: "PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
- * SHA256: "32b03a66f2d3381829c8b31d4a704c849cc6f842f458bf0f4510b8aa5d6d4c64"
- * MD5: "e949c0e6ba9e052fc3b696e61cbe067a"
- * SHA1: "00f375fdd11817887e202adfe3d2366bd890cff8"
- * SHA512: "7c1e5fe51985acb2370267165aa571d6ff64f7df3648f9aa8913885f773764f44fcc308d067763b1365942927fcd40e959c0503a980898825a0b2a05e2cb14c3"
- * CRC32: "245F4892"
- * SSDEEP: "49152:kx6dP4+zOrOHgrEyKN8RoBSxtfh8KGQXxbD3Wa8HyoKqKoe:Xe0FHyEyKNg48tfh/GQXVDN8HyoKqKoe"
- * Process Execution:
- "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88",
- "AcroRd32.exe",
- "Eula.exe",
- "AdobeARM.exe",
- "Reader_sl.exe",
- "cmd.exe",
- "cmd.exe",
- "cmd.exe",
- "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88",
- "csc.exe",
- "cvtres.exe",
- "prgyj.exe",
- "prgyj.exe",
- "prgyj.exe",
- "prgyj.exe",
- "prgyj.exe",
- "svchost.exe",
- "WmiPrvSE.exe",
- "WmiPrvSE.exe",
- "svchost.exe",
- "WMIADAP.exe"
- * Executed Commands:
- "\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroRd32.exe\" \"C:\\Users\\user\\AppData\\Local\\Temp\\bbb.pdf\"",
- "C:\\Users\\user\\AppData\\Local\\Temp\\bbb.pdf ",
- "cmd.exe /c copy \"C:/Users/user/AppData/Local/Temp/Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88\" \"%appdata%\\ltigho\\lttdyd.exe\" /Y",
- "cmd.exe /c echo zoneTransferZoneID = 2 > %appdata%\\ltigho\\lttdyd.exe:Zone.Identifier",
- "cmd.exe /c ren \"%appdata%\\ltigho\\lttdyd.exe.jpg\" lttdyd.exe",
- "\"C:/Users/user/AppData/Local/Temp/Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88\"",
- "\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroRd32.exe\" --type=renderer \"C:\\Users\\user\\AppData\\Local\\Temp\\bbb.pdf\"",
- "\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroCEF\\RdrCEF.exe\" --backgroundcolor=16514043",
- "\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Eula.exe\" Adobe Acrobat Reader DC;655786;1033",
- "\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\" /PRODUCT:Reader /VERSION:19.0 /MODE:3",
- "\"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.cmdline\"",
- "C:\\Users\\user\\AppData\\Roaming\\prgyj.exe /launchSelfAndExit \"C:\\Users\\user\\AppData\\Local\\Temp\\Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88\" 2412 /protectFile",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\user\\AppData\\Local\\Temp\\RES6EAA.tmp\" \"c:\\Users\\user\\AppData\\Local\\Temp\\CSC6E99.tmp\"",
- "C:\\Users\\user\\AppData\\Roaming\\prgyj.exe /watchProcess \"C:\\Users\\user\\AppData\\Local\\Temp\\Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88\" 2412 \"/protectFile\"",
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -Embedding",
- "\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE wmiadap.exe /F /T /R",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Reader_sl.exe "
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Attempts to connect to a dead IP:Port (6 unique times)",
- "Details":
- "IP": "13.107.4.50:80"
- "IP": "193.161.193.99:44611"
- "IP": "184.28.188.179:80"
- "IP": "23.208.143.3:443"
- "IP": "193.161.193.99:2928"
- "IP": "72.21.91.29:80"
- "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
- "Details":
- "ioc": "v2.0.50727"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: Eula.exe, pid: 348, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: Eula.exe, pid: 348, offset: 0x00000100, length: 0x00000018"
- "self_read": "process: Eula.exe, pid: 348, offset: 0x000001f8, length: 0x000000a0"
- "self_read": "process: Eula.exe, pid: 348, offset: 0x00012600, length: 0x00000010"
- "Description": "A process created a hidden window",
- "Details":
- "Process": "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88 -> cmd.exe"
- "Process": "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88 -> cmd.exe"
- "Process": "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88 -> cmd.exe"
- "Process": "svchost.exe -> \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Users\\user\\AppData\\Roaming\\prgyj.exe"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
- "url": "http://acroipm2.adobe.com/19/rdr/ENU/win/nooem/none/consumer/message.zip"
- "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D"
- "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAiybqFfIme0q2SePjjqIls%3D"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: .text, entropy: 7.97, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x00236200, virtual_size: 0x0023614c"
- "Description": "Anomalous .NET characteristics",
- "Details":
- "anomalous_version": "Assembly version is set to 0"
- "Description": "Executed a process and injected code into it, probably while unpacking",
- "Details":
- "Injection": "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88(2272) -> Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88(2412)"
- "Description": "A process attempted to delay the analysis task by a long amount of time.",
- "Details":
- "Process": "WmiPrvSE.exe tried to sleep 546 seconds, actually delayed analysis time by 0 seconds"
- "Process": "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88 tried to sleep 2608 seconds, actually delayed analysis time by 0 seconds"
- "Process": "prgyj.exe tried to sleep 474 seconds, actually delayed analysis time by 0 seconds"
- "Description": "A process was set to shut the system down when terminated",
- "Details":
- "process": "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88:2412"
- "Description": "A potential decoy document was displayed to the user",
- "Details":
- "disguised_executable": "The submitted file was an executable indicative of an attempt to get a user to run executable content disguised as a document"
- "Decoy Document": "\"c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\acrord32.exe\" \"c:\\users\\user\\appdata\\local\\temp\\bbb.pdf\""
- "Description": "Exhibits behavior characteristic of iSpy Keylogger",
- "Details":
- "Description": "A document file initiated network communications indicative of a potential exploit or payload download",
- "Details":
- "http_request": "acrord32.exe_WSASend_get /mfewtzbnmeswstajbgurdgmcgguabbsauqybmq2awn1rh6doh%2fsbygfv7gqua95qnvbrtltm8kpigxvdl7i90vuceah9o%2btuynxiieolckvpvje%3d http/1.1\r\ncache-control: max-age = 142986\r\nconnection: keep-alive\r\naccept: */*\r\nif-modified-since: tue, 28 may 2019 07:40:28 gmt\r\nif"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\lttdyd.exe.lnk"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\lttdyd.exe.lnk"
- "Description": "Creates a hidden or system file",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\ltigho"
- "Description": "File has been identified by 22 Antiviruses on VirusTotal as malicious",
- "Details":
- "CrowdStrike": "win/malicious_confidence_100% (D)"
- "Symantec": "ML.Attribute.HighConfidence"
- "ESET-NOD32": "a variant of MSIL/Kryptik.LSD"
- "APEX": "Malicious"
- "Kaspersky": "HEUR:Trojan.MSIL.Dnoper.gen"
- "Emsisoft": "Trojan.Crypt (A)"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.vc"
- "Trapmine": "malicious.high.ml.score"
- "FireEye": "Generic.mg.e949c0e6ba9e052f"
- "Avira": "TR/Dropper.Gen"
- "Endgame": "malicious (high confidence)"
- "ZoneAlarm": "HEUR:Trojan.MSIL.Dnoper.gen"
- "Microsoft": "Trojan:Win32/Fuery.B!cl"
- "Cylance": "Unsafe"
- "SentinelOne": "DFI - Malicious PE"
- "eGambit": "Unsafe.AI_Score_67%"
- "Fortinet": "MSIL/Kryptik.SHS!tr"
- "AVG": "MSIL:GenMalicious-CMG Trj"
- "Cybereason": "malicious.dd1181"
- "Avast": "MSIL:GenMalicious-CMG Trj"
- "Qihoo-360": "HEUR/QVM03.0.004A.Malware.Gen"
- "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
- "Details":
- "Description": "Attempts to modify proxy settings",
- "Details":
- "Description": "Attempts to modify browser security settings",
- "Details":
- "Description": "Creates a copy of itself",
- "Details":
- "copy": "C:\\Users\\user\\AppData\\Roaming\\ltigho\\lttdyd.exe"
- "Description": "Attempts to interact with an Alternate Data Stream (ADS)",
- "Details":
- "file": "C:Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88"
- "file": "C:\\$Extend\\$Quota:$Q:$INDEX_ALLOCATION"
- * Started Service:
- * Mutexes:
- "Global\\CLR_CASOFF_MUTEX",
- "Global\\ARM Update Mutex",
- "Global\\Acro Update Mutex",
- "100184D2-BDC3-477a-B8D3-65548B67914C_3000",
- "Global\\100184D2-BDC3-477a-B8D3-65548B67914C_552",
- "com.adobe.acrobat.rna.RdrCefBrowserLock.DC",
- "f51ea9ec4b9a46168304433794509147",
- "Global\\.net clr networking",
- "Local\\WininetStartupMutex",
- "Local\\ZonesCounterMutex",
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex",
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1",
- "Local\\_!MSFTHISTORY!_",
- "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
- "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
- "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
- "Local\\!IETld!Mutex",
- "_!SHMSFTHISTORY!_",
- "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!mshist012019080520190806!",
- "Global\\ADAP_WMI_ENTRY",
- "Global\\RefreshRA_Mutex",
- "Global\\RefreshRA_Mutex_Lib",
- "Global\\RefreshRA_Mutex_Flag"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\bbb.pdf",
- "\\??\\PIPE\\srvsvc",
- "C:\\Users\\user\\AppData\\Roaming\\ltigho\\lttdyd.exe.lnk",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\lttdyd.exe.lnk",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ltigho\\lttdyd.exe.jpg",
- "C:\\Users\\user\\AppData\\Local\\Temp\\svhost.exe",
- "C:\\Users\\user\\AppData\\Local\\Adobe\\Color\\Profiles\\wscRGB.icc",
- "C:\\Users\\user\\AppData\\Local\\Adobe\\Color\\Profiles\\wsRGB.icc",
- "C:\\Users\\user\\AppData\\Local\\Adobe\\Color\\ACECache11.lst",
- "C:\\Users\\user\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\ReaderMessages",
- "C:\\Users\\user\\AppData\\Local\\Adobe\\Acrobat\\DC\\UserCache.bin",
- "\\??\\pipe\\com.adobe.reader.rna.user.DC.0",
- "C:\\Users\\user\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\Reader\\DesktopNotification\\NotificationsDB\\notificationsDB",
- "C:\\Users\\user\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\Reader\\DesktopNotification\\NotificationsDB\\notificationsDB-journal",
- "C:\\Users\\user\\AppData\\Local\\Adobe\\Acrobat\\DC\\SharedDataEvents",
- "C:\\Users\\user\\AppData\\Local\\Adobe\\Acrobat\\DC\\SharedDataEvents-journal",
- "C:\\Users\\user\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\ConnectorIcons\\icon-190805175448Z-2308.bmp",
- "C:\\Users\\user\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\ReaderMessages-journal",
- "C:\\Users\\user\\AppData\\Local\\Temp\\acrord32_sbx\\A9Rpe9h49_1yeyp7y_1mg.tmp",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\1E11E75149C17A93653DA7DC0B8CF53F_7A951BF9CD37814D9F57998C0A161B5B",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\1E11E75149C17A93653DA7DC0B8CF53F_7A951BF9CD37814D9F57998C0A161B5B",
- "C:\\Users\\user\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\CRLCache\\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl",
- "C:\\Users\\user\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\CRLCache\\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl",
- "C:\\Users\\user\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\addressbook.acrodata",
- "C:\\Users\\user\\AppData\\Roaming\\ltigho\\lttdyd.exe",
- "C:\\Users\\user\\AppData\\Roaming\\ltigho\\lttdyd.exe:Zone.Identifier",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.0.cs",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.cmdline",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.out",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.err",
- "C:\\Users\\user\\AppData\\Roaming\\prgyj.exe",
- "C:\\Users\\user\\AppData\\Roaming\\prgyj.exe.config",
- "C:\\Users\\user\\AppData\\Local\\Temp\\CabA74D.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TarA74E.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\CabA868.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TarA869.tmp",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
- "C:\\Users\\user\\AppData\\Local\\Temp\\CabAA5E.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TarAA5F.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\CSC6E99.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\RES6EAA.tmp",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012019080520190806\\index.dat",
- "\\??\\PIPE\\samr",
- "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
- "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
- "\\??\\WMIDataDevice",
- "C:\\$Extend\\$Quota:$Q:$INDEX_ALLOCATION",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdobeARM.log",
- "\\??\\pipe\\32B6B37A-4A7D-4e00-95F2-6F0BF3DE3E001599590523thsnYaVieBoda",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ArmUI.ini",
- "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\FindMe",
- "C:\\Users\\user\\AppData\\Roaming\\svhost.exe",
- "C:\\Users\\user\\AppData\\Roaming\\ltigho\\FZQR27Y43sDbON97KOJGAg==.bat",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.2272.14622203",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2272.14622203",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.2272.14622203",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.0.cs",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.cmdline",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.err",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.pdb",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.out",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\CabA74D.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TarA74E.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\CabA868.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TarA869.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\CabAA5E.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TarAA5F.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\RES6EAA.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\CSC6E99.tmp",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.1560.14626078",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1560.14626078",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.1560.14626078",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.1596.14626609",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1596.14626609",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.1596.14626609",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012019052620190527\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012019052620190527\\",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.4056.14930656",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.4056.14930656",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.4056.14930656"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Acrobat\\DC\\DiskCabs",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Synchronizer\\DC",
- "HKEY_CURRENT_USER\\Software\\Adobe\\CommonFiles\\Usage\\AcrobatDC",
- "HKEY_CURRENT_USER\\Software\\Adobe\\CommonFiles\\Usage\\Reader DC",
- "HKEY_CURRENT_USER\\Software\\Adobe\\CommonFiles\\Usage\\Reader 19_Acrobat19_Reader_19.10.20069",
- "HKEY_LOCAL_MACHINE\\System\\Acrobatbrokerserverdispatchercpp789",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Installer",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Installer\\Migrated",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Language",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Language\\UseMUI",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Language\\next",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Language\\current",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Originals",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\ExitSection",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Synchronizer\\DC\\Acrobat.com",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Synchronizer\\DC\\Acrobat.com.v2",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVConnector",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVConnector\\cv1",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cTaskPanes",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cTaskPanes\\cBasicCommentPane",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\FTEDialog",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\FlashDebug",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\OnBoardingSection",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\OnBoardingSection\\chomeView",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\SDI",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Selection",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Window",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Window\\cAVUIPopupList",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\aFS",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\tDIText",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\tFileName",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\sFileAncestors",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\sDI",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\sDate",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVEntitlement",
- "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION\\AcroRd32.exe",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Synchronizer\\DC\\CredentialsV3",
- "HKEY_CURRENT_USER\\SOFTWARE\\Adobe\\Acrobat Reader\\DC\\Privileged",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Privileged\\bOldRecentFilesMigrated",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Workflows",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Workflows\\cServices",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVConnector\\cIconCache",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\UsageMeasurement",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\AcroRd32_RASAPI32",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\AcroRd32_RASAPI32\\EnableFileTracing",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\AcroRd32_RASAPI32\\EnableConsoleTracing",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\AcroRd32_RASAPI32\\FileTracingMask",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\AcroRd32_RASAPI32\\ConsoleTracingMask",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\AcroRd32_RASAPI32\\MaxFileSize",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\AcroRd32_RASAPI32\\FileDirectory",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab\\cDocumentCenter",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab\\cDocumentCenter\\cSettings",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab\\cEmailDistribution",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab\\cEmailDistribution\\cSettings",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab\\cInternalServer",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab\\cInternalServer\\cSettings",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab\\cInitiationWizardFirstLaunch",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cHandlers",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c290FA7E61053E8763C6055E6333A99EFB83ECACB",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c290FA7E61053E8763C6055E6333A99EFB83ECACB\\cAdobe_OCSPRevChecker",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c290FA7E61053E8763C6055E6333A99EFB83ECACB\\cAdobe_OCSPRevChecker\\cAuthorizedResponder",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c290FA7E61053E8763C6055E6333A99EFB83ECACB\\cAdobe_OCSPRevChecker\\cAuthorizedResponder\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_ChainBuilder",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c0\\cValue",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c1",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c1\\cValue",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cAuthorizedResponder",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cAuthorizedResponder\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cSendNonce",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cSendNonce\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cSignCertOID",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cSignCertOID\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cSignRequest",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cSignRequest\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cURLToConsult",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cURLToConsult\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_ChainBuilder",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c0\\cValue",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c1",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c1\\cValue",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cAuthorizedResponder",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cAuthorizedResponder\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cSendNonce",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cSendNonce\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cSignCertOID",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cSignCertOID\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cSignRequest",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cSignRequest\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cURLToConsult",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cURLToConsult\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_CRLRevChecker",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_CRLRevChecker\\cRequireAKI",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_CRLRevChecker\\cRequireAKI\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_ChainBuilder",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_ChainBuilder\\cAllowCAToIssueAC",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_ChainBuilder\\cAllowCAToIssueAC\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_ChainBuilder\\cCheckCABasicConstraints",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_ChainBuilder\\cCheckCABasicConstraints\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_OCSPRevChecker",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_OCSPRevChecker\\cAllowOCSPNoCheck",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_OCSPRevChecker\\cAllowOCSPNoCheck\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_OCSPRevChecker\\cRequireOCSPCertHash",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_OCSPRevChecker\\cRequireOCSPCertHash\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_Validation",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_Validation\\cValidityModel",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_Validation\\cValidityModel\\c0",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cPPKHandler",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\SystemCertificates\\ADDRESSBOOK",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\SystemCertificates\\ADDRESSBOOK\\Certificates",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\SystemCertificates\\ADDRESSBOOK\\CRLs",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\SystemCertificates\\ADDRESSBOOK\\CTLs",
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019080520190806",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019080520190806\\CachePath",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019080520190806\\CachePrefix",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019080520190806\\CacheLimit",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019080520190806\\CacheOptions",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019080520190806\\CacheRepair",
- "HKEY_LOCAL_MACHINE\\Software\\Adobe\\Acrobat Reader\\DC\\AdobeViewer",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Adobe\\Acrobat Reader\\DC\\AdobeViewer\\EULA",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AdobeViewer",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AdobeViewer\\EULA",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe ARM\\1.0\\ARM\\iSpeedLauncherLogonTime",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\IDE\\DiskVBOX_HARDDISK___________________________1.0_____\\5&33d1638a&0&0.0.0_0-00000000-0000-0000-0000-000000000000",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\advapi32.dllMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\en-US\\advapi32.dll.muiMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ACPI.sysACPIMOFResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ACPI.sys.muiACPIMOFResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ndis.sysMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ndis.sys.muiMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\mssmbios.sysMofResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\mssmbios.sys.muiMofResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\HDAudBus.sysHDAudioMofName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\HDAudBus.sys.muiHDAudioMofName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\intelppm.sysPROCESSORWMI",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\intelppm.sys.muiPROCESSORWMI",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\portcls.SYSPortclsMof",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\en-US\\portcls.SYS.muiPortclsMof",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Adobe\\CommonFiles\\Usage\\Reader DC\\OptIn",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFavoritesInitialSelection",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFeedsInitialSelection",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe ARM\\1.0\\ARM\\iNotify",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
- * DNS Communications:
- "type": "A",
- "request": "qstorm.chickenkiller.com",
- "answers":
- "data": "193.161.193.99",
- "type": "A"
- * Domains:
- "ip": "193.161.193.99",
- "domain": "qstorm.chickenkiller.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "www.download.windowsupdate.com",
- "version": "1.1",
- "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
- "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86403\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Fri, 22 Feb 2019 16:53:13 GMT\r\nIf-None-Match: \"80e22c19cfcad41:0\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://acroipm2.adobe.com/19/rdr/ENU/win/nooem/none/consumer/message.zip",
- "user-agent": "IPM",
- "method": "GET",
- "host": "acroipm2.adobe.com",
- "version": "1.1",
- "path": "/19/rdr/ENU/win/nooem/none/consumer/message.zip",
- "data": "GET /19/rdr/ENU/win/nooem/none/consumer/message.zip HTTP/1.1\r\nAccept: */*\r\nIf-Modified-Since: Mon, 01 Jan 1970 00:00:00 GMT\r\nUser-Agent: IPM\r\nHost: acroipm2.adobe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp.digicert.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D HTTP/1.1\r\nCache-Control: max-age = 142986\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 07:40:28 GMT\r\nIf-None-Match: \"5cece5ec-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAiybqFfIme0q2SePjjqIls%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp.digicert.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAiybqFfIme0q2SePjjqIls%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAiybqFfIme0q2SePjjqIls%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment