Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [code]
- HitmanPro 3.8.11.300
- www.hitmanpro.com
- Computer name . . . . : CHRISTOFF-PC
- Windows . . . . . . . : 6.1.1.7601.X64/2
- User name . . . . . . : CHRISTOFF-PC\CHRISTOFF
- UAC . . . . . . . . . : Enabled
- License . . . . . . . : Free
- Scan date . . . . . . : 2019-05-07 14:25:51
- Scan mode . . . . . . : Normal
- Scan duration . . . . : 5m 48s
- Disk access mode . . : Direct disk access (SRB)
- Cloud . . . . . . . . : Internet
- Reboot . . . . . . . : No
- Threats . . . . . . . : 0
- Traces . . . . . . . : 58
- Objects scanned . . . : 1 199 820
- Files scanned . . . . : 50 914
- Remnants scanned . . : 260 772 files / 888 134 keys
- Suspicious files ____________________________________________________________
- C:\Users\CHRISTOFF\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RPJRAC0X\FRST64[1].exe
- Size . . . . . . . : 2 430 464 bytes
- Age . . . . . . . : 6.0 days (2019-05-01 13:40:36)
- Entropy . . . . . : 7.6
- SHA-256 . . . . . : 30B4D620FDEB7343BE41E2B7213B03375280138CE771BC139E8E9A8ADD4DE7D5
- Needs elevation . : Yes
- Fuzzy . . . . . . : 24.0
- Program has no publisher information but prompts the user for permission elevation.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Time indicates that the file appeared recently on this computer.
- Forensic Cluster
- -3.1s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\72f733dcf1b6e483_0
- -3.1s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\74479683eaa273b1_0
- -1.3s C:\Users\CHRISTOFF\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RPJRAC0X\82[1].htm
- -0.3s C:\Users\CHRISTOFF\AppData\Roaming\Microsoft\Windows\Cookies\DYJEM6M1.txt
- -0.3s C:\Users\CHRISTOFF\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYN119HE\82[1].htm
- 0.0s C:\Users\CHRISTOFF\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RPJRAC0X\FRST64[1].exe
- 0.0s C:\Users\CHRISTOFF\Downloads\FRST64.exe
- 0.8s C:\Users\CHRISTOFF\Downloads\FRST-OlderVersion\
- 4.5s C:\Users\CHRISTOFF\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MQG6WKD\up64[3]
- C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar.exe
- Size . . . . . . . : 18 653 984 bytes
- Age . . . . . . . : 2.8 days (2019-05-04 19:33:36)
- Entropy . . . . . : 6.5
- SHA-256 . . . . . : 171562A0B0680E2FD9A0C358D8C13D3F28849E51E7D62C106BED8B8EE3FDDE65
- Version . . . . . : 5.0.0.6002871
- RSA Key Size . . . : 2048
- Authenticode . . . : Invalid
- Fuzzy . . . . . . : 25.0
- Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
- Authors name is missing in version info. This is not common to most programs.
- Time indicates that the file appeared recently on this computer.
- Forensic Cluster
- -1.6s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\
- -0.3s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\CD\
- -0.3s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\CD\coverart.png
- -0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\changelog.txt
- -0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\controls.txt
- -0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\IGG-GAMES.COM.url
- -0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Images\
- -0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Images\flag_garage.png
- -0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Images\How to use car template.txt
- -0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Images\jonnez_template.png
- -0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Images\mugshot.png
- -0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Images\poster1.png
- -0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Images\poster2.png
- -0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Images\poster3.png
- -0.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Images\spraycolormap.png
- -0.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Images\template.png
- -0.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Images\window_sticker.png
- -0.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\LAUNCHER.exe
- 0.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar.exe
- 0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\
- 0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\level0
- 0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\level1
- 0.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\level2
- 0.8s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\level3
- 0.8s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\mainData
- 0.8s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\
- 0.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\Assembly-CSharp-firstpass.dll
- 0.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\Assembly-CSharp.dll
- 0.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\Assembly-UnityScript-firstpass.dll
- 0.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\Assembly-UnityScript.dll
- 0.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\Boo.Lang.dll
- 0.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\cInput.dll
- 0.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\ES2.dll
- 0.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\HOTween.dll
- 0.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\Mono.Security.dll
- 0.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\MoodkieSecurity.dll
- 0.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\mscorlib.dll
- 0.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\PlayMaker.dll
- 0.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\System.Core.dll
- 0.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\System.dll
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\System.Drawing.dll
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\UnityEngine.dll
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\UnityEngine.UI.dll
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Managed\UnityScript.Lang.dll
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\1.0\
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\1.0\DefaultWsdlHelpGenerator.aspx
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\1.0\machine.config
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\2.0\
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\2.0\Browsers\
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\2.0\Browsers\Compat.browser
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\2.0\DefaultWsdlHelpGenerator.aspx
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\2.0\machine.config
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\2.0\settings.map
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\2.0\web.config
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\browscap.ini
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\config
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\mconfig\
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\etc\mono\mconfig\config.xml
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Mono\mono.dll
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Plugins\
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Plugins\CSteamworks.bundle\
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Plugins\CSteamworks.bundle\Contents\
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Plugins\CSteamworks.bundle\Contents\Info.plist
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Plugins\CSteamworks.bundle\Contents\MacOS\
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Plugins\CSteamworks.bundle\Contents\MacOS\CSteamworks
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Plugins\CSteamworks.bundle\Contents\MacOS\libsteam_api.dylib
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Plugins\CSteamworks.dll
- 1.0s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Plugins\libCSteamworks.so
- 1.1s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Plugins\libsteam_api.so
- 1.1s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Plugins\steam_api64.dll
- 1.1s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Plugins\UnityForceFeedback.dll
- 1.1s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Resources\
- 1.1s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Resources\unity default resources
- 1.1s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\Resources\unity_builtin_extra
- 1.1s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\resources.assets
- 1.1s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\resources.resource
- 1.1s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\ScreenSelector.bmp
- 1.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\sharedassets0.assets
- 1.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\sharedassets1.assets
- 1.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\sharedassets1.resource
- 1.9s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\sharedassets2.assets
- 2.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\sharedassets2.resource
- 2.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\sharedassets3.assets
- 6.6s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\sharedassets3.resource
- 8.2s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\sharedassets4.assets
- 8.3s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\mysummercar_Data\sharedassets4.resource
- 8.3s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\PCGAMESTORRENTS.COM.url
- 8.3s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\README.txt
- 8.3s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Redist\
- 8.3s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Redist\vcredist_x64.exe
- 8.4s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Redist\vcredist_x86.exe
- 8.5s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\SmartSteamEmu.dll
- 8.6s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\SmartSteamEmu.ini
- 8.6s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\SmartSteamEmu64.dll
- 8.6s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\steam_api.dll
- 8.6s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\steam_api64.dll
- 8.7s C:\Users\CHRISTOFF\Desktop\My.Summer.Car.v25.04.2019\Radio\
- C:\Users\CHRISTOFF\Downloads\FRST-OlderVersion\FRST64 (1).exe
- Size . . . . . . . : 2 429 952 bytes
- Age . . . . . . . : 8.0 days (2019-04-29 14:36:50)
- Entropy . . . . . : 7.6
- SHA-256 . . . . . : 39A89FF51DE6D5D38B5B937467D985F014C8A606C5EEFC9CF7E1BC4657730D6E
- Needs elevation . : Yes
- Fuzzy . . . . . . : 23.0
- Program has no publisher information but prompts the user for permission elevation.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Time indicates that the file appeared recently on this computer.
- Forensic Cluster
- -10.0s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\2d8ab10edb25aa14_0
- -8.2s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\f6b887849b1c7a5a_0
- -7.2s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\23826188159746d3_0
- -3.7s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\aee04ee3b48fedf7_0
- -3.5s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\dbbe5e2cdc1a1410_0
- -3.4s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\5419f122a5284ee7_0
- -3.1s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\5226d75d9265d0fb_0
- -2.9s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\a18e941962e5ed3c_0
- -2.0s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\c44c65cb377678f0_0
- -2.0s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\3289b09011dc1f1f_0
- -2.0s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\f688146b3892a917_0
- -2.0s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\8955d25904bb4457_0
- -0.5s C:\Users\CHRISTOFF\Downloads\FRST-OlderVersion\FRST64.exe
- 0.0s C:\Users\CHRISTOFF\Downloads\FRST-OlderVersion\FRST64 (1).exe
- C:\Users\CHRISTOFF\Downloads\FRST-OlderVersion\FRST64.exe
- Size . . . . . . . : 2 429 952 bytes
- Age . . . . . . . : 8.0 days (2019-04-29 14:36:50)
- Entropy . . . . . : 7.6
- SHA-256 . . . . . : 39A89FF51DE6D5D38B5B937467D985F014C8A606C5EEFC9CF7E1BC4657730D6E
- Needs elevation . : Yes
- Fuzzy . . . . . . : 23.0
- Program has no publisher information but prompts the user for permission elevation.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Time indicates that the file appeared recently on this computer.
- Forensic Cluster
- -9.5s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\2d8ab10edb25aa14_0
- -7.7s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\f6b887849b1c7a5a_0
- -6.7s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\23826188159746d3_0
- -3.2s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\aee04ee3b48fedf7_0
- -2.9s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\dbbe5e2cdc1a1410_0
- -2.9s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\5419f122a5284ee7_0
- -2.6s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\5226d75d9265d0fb_0
- -2.4s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\a18e941962e5ed3c_0
- -1.5s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\c44c65cb377678f0_0
- -1.5s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\3289b09011dc1f1f_0
- -1.5s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\f688146b3892a917_0
- -1.4s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\8955d25904bb4457_0
- 0.0s C:\Users\CHRISTOFF\Downloads\FRST-OlderVersion\FRST64.exe
- 0.5s C:\Users\CHRISTOFF\Downloads\FRST-OlderVersion\FRST64 (1).exe
- C:\Users\CHRISTOFF\Downloads\FRST64.exe
- Size . . . . . . . : 2 430 464 bytes
- Age . . . . . . . : 6.0 days (2019-05-01 13:40:36)
- Entropy . . . . . : 7.6
- SHA-256 . . . . . : 30B4D620FDEB7343BE41E2B7213B03375280138CE771BC139E8E9A8ADD4DE7D5
- Needs elevation . : Yes
- Fuzzy . . . . . . : 24.0
- Program has no publisher information but prompts the user for permission elevation.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Time indicates that the file appeared recently on this computer.
- Forensic Cluster
- -3.1s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\72f733dcf1b6e483_0
- -3.1s C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\74479683eaa273b1_0
- -1.3s C:\Users\CHRISTOFF\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RPJRAC0X\82[1].htm
- -0.3s C:\Users\CHRISTOFF\AppData\Roaming\Microsoft\Windows\Cookies\DYJEM6M1.txt
- -0.3s C:\Users\CHRISTOFF\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYN119HE\82[1].htm
- 0.0s C:\Users\CHRISTOFF\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RPJRAC0X\FRST64[1].exe
- 0.0s C:\Users\CHRISTOFF\Downloads\FRST64.exe
- 0.8s C:\Users\CHRISTOFF\Downloads\FRST-OlderVersion\
- 4.5s C:\Users\CHRISTOFF\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MQG6WKD\up64[3]
- Cookies _____________________________________________________________________
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:360yield.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:abmr.net
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:addthis.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:adform.net
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:adnxs.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.linkedin.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.lvbetpartners.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.stickyadstv.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:adsrvr.org
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:agkn.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:appnexus-partners.tremorhub.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:bidr.io
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:bidswitch.net
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:bluekai.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:cdn.taboola.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:creative-serving.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:crwdcntrl.net
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:demdex.net
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:dpm.demdex.net
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:erne.co
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:eus.rubiconproject.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:everesttech.net
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:imrworldwide.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:ipredictive.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:mathtag.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:mookie1.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:mxptint.net
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:openx.net
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:oracle.112.2o7.net
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:pagefair.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:pixel.rubiconproject.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:postrelease.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:pubmatic.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:rfihub.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:rlcdn.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:rubiconproject.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:rundsp.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:scorecardresearch.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:simpli.fi
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:stats.paypal.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:taboola.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:tapad.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:tidaltv.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.adform.net
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:tribalfusion.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:turn.com
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:w55c.net
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:weborama.fr
- C:\Users\CHRISTOFF\AppData\Local\Google\Chrome\User Data\Default\Cookies:yieldlab.net
- [/code]
Advertisement
Add Comment
Please, Sign In to add comment