Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Process
- Time of Day Name PID Operation Path Result Detail
- Parent PID: 476, Command line: "C:\Users\hackbox\Music\
- C:\Users\hackbox\Music\unpacked\, Environment:
- ; =::=::\
- ; ALLUSERSPROFILE=C:\ProgramData
- ; APPDATA=C:\Users\hackbox\AppData\Roaming
- ; CommonProgramFiles=C:\Program Files\Common Files
- ; COMPUTERNAME=HACKBOX-PC
- ; ComSpec=C:\Windows\system32\cmd.exe
- ; FP_NO_HOST_CHECK=NO
- ; HOMEDRIVE=C:
- ; HOMEPATH=\Users\hackbox
- ; LOCALAPPDATA=C:\Users\hackbox\AppData\Local
- ; LOGONSERVER=\\HACKBOX-PC
- ; NUMBER_OF_PROCESSORS=2
- ; OS=Windows_NT
- ;
- Path=C:\Windows\system32;C:\Windows;C:\Windows\Syst
- ; PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.
- ; PROCESSOR_ARCHITECTURE=x86
- ; PROCESSOR_IDENTIFIER=x86 Family 6 Model 44 Step
- ; PROCESSOR_LEVEL=6
- ; PROCESSOR_REVISION=2c01
- ; ProgramData=C:\ProgramData
- ; ProgramFiles=C:\Program Files
- ; PSModulePath=C:\Windows\system32\WindowsPowerSh
- ; PUBLIC=C:\Users\Public
- ; SESSIONNAME=Console
- ; SystemDrive=C:
- ; SystemRoot=C:\Windows
- ; TEMP=C:\Users\hackbox\AppData\Local\Temp
- ; TMP=C:\Users\hackbox\AppData\Local\Temp
- ; USERDOMAIN=hackbox-PC
- ; USERNAME=hackbox
- ; USERPROFILE=C:\Users\hackbox
- ; windir=C:\Windows
- 2:48:03.0868668 ; windows_tracing_flags=3
- PM unpacked.exe3456Process Start SUCCESS ; windows_tracing_logfile=C:\BVTBin\Tests\installpackage\c
- 2:48:03.0868688
- PM unpacked.exe3456Thread Create SUCCESS Thread ID: 2560
- 2:48:03.0963196
- PM unpacked.exe3456Load Image C:\Users\hackbox\Music\unpacked\unpacked.exe SUCCESS Image Base: 0x400000, Image Size: 0x12000
- 2:48:03.0982563
- PM unpacked.exe3456Load Image C:\Windows\System32\ntdll.dll SUCCESS Image Base: 0x77b80000, Image Size: 0x13c000
- 2:48:03.0984246 Desired Access: Generic Read, Disposition: Open, Options
- PM unpacked.exe3456CreateFile C:\Windows\Prefetch\UNPACKED.EXE-D6A8C3AC.pf NAME NOT FOUND AllocationSize: n/a
- 2:48:03.0985053
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\Session Manager REPARSE Desired Access: Read
- 2:48:03.0985175
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\Session Manager SUCCESS Desired Access: Read
- 2:48:03.0985315
- PM unpacked.exe3456RegQueryValue HKLM\System\CurrentControlSet\Control\Session Manager\CWDIllegalInDLLSearch NAME NOT FOUND Length: 1,024
- 2:48:03.0985384
- PM unpacked.exe3456RegCloseKey HKLM\System\CurrentControlSet\Control\Session Manager SUCCESS
- 2:48:03.0986781 Desired Access: Execute/Traverse, Synchronize, Dispositio
- PM unpacked.exe3456CreateFile C:\Users\hackbox\Music\unpacked SUCCESS Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a
- 2:48:03.0988453
- PM unpacked.exe3456Load Image C:\Windows\System32\kernel32.dll SUCCESS Image Base: 0x778a0000, Image Size: 0xd4000
- 2:48:03.0991404
- PM unpacked.exe3456Load Image C:\Windows\System32\KernelBase.dll SUCCESS Image Base: 0x75d50000, Image Size: 0x4a000
- 2:48:03.1012381
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\Terminal Server REPARSE Desired Access: Read
- 2:48:03.1012505
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\Terminal Server SUCCESS Desired Access: Read
- 2:48:03.1012616
- PM unpacked.exe3456RegQueryValue HKLM\System\CurrentControlSet\Control\Terminal Server\TSAppCompat NAME NOT FOUND Length: 548
- 2:48:03.1012667
- PM unpacked.exe3456RegQueryValue HKLM\System\CurrentControlSet\Control\Terminal Server\TSUserEnabled SUCCESS Type: REG_DWORD, Length: 4, Data: 0
- 2:48:03.1012719
- PM unpacked.exe3456RegCloseKey HKLM\System\CurrentControlSet\Control\Terminal Server SUCCESS
- 2:48:03.1012869
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\SafeBoot\Option REPARSE Desired Access: Query Value, Set Value
- 2:48:03.1012941
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\SafeBoot\Option NAME NOT FOUND Desired Access: Query Value, Set Value
- 2:48:03.1013018
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\Srp\GP\DLL REPARSE Desired Access: Read
- 2:48:03.1013083
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\Srp\GP\DLL NAME NOT FOUND Desired Access: Read
- 2:48:03.1013154
- PM unpacked.exe3456RegOpenKey HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers SUCCESS Desired Access: Query Value
- 2:48:03.1013281
- PM unpacked.exe3456RegQueryValue HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled NAME NOT FOUND Length: 80
- 2:48:03.1013323
- PM unpacked.exe3456RegCloseKey HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers SUCCESS
- 2:48:03.1013450
- PM unpacked.exe3456RegOpenKey HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers NAME NOT FOUND Desired Access: Query Value
- 2:48:03.1014923
- PM unpacked.exe3456Load Image C:\Windows\System32\ws2_32.dll SUCCESS Image Base: 0x77d10000, Image Size: 0x35000
- 2:48:03.1016319
- PM unpacked.exe3456Load Image C:\Windows\System32\msvcrt.dll SUCCESS Image Base: 0x76720000, Image Size: 0xac000
- 2:48:03.1019505
- PM unpacked.exe3456Load Image C:\Windows\System32\rpcrt4.dll SUCCESS Image Base: 0x76670000, Image Size: 0xa1000
- 2:48:03.1021554
- PM unpacked.exe3456Load Image C:\Windows\System32\nsi.dll SUCCESS Image Base: 0x77d00000, Image Size: 0x6000
- 2:48:03.1023824 Desired Access: Read Attributes, Disposition: Open, Option
- PM unpacked.exe3456CreateFile C:\Users\hackbox\Music\unpacked\dbghelp.dll NAME NOT FOUND Write, Delete, AllocationSize: n/a
- 2:48:03.1025221 Desired Access: Read Attributes, Disposition: Open, Option
- PM unpacked.exe3456CreateFile C:\Windows\System32\dbghelp.dll SUCCESS Write, Delete, AllocationSize: n/a, OpenResult: Opened
- 2:48:03.1026246 CreationTime: 11/21/2010 2:59:12 AM, LastAccessTime: 11
- PM unpacked.exe3456QueryBasicInformationFile C:\Windows\System32\dbghelp.dll SUCCESS ChangeTime: 6/30/2018 5:09:17 AM, FileAttributes: A
- 2:48:03.1026289
- PM unpacked.exe3456CloseFile C:\Windows\System32\dbghelp.dll SUCCESS
- 2:48:03.1027141 Desired Access: Read Data/List Directory, Execute/Travers
- PM unpacked.exe3456CreateFile C:\Windows\System32\dbghelp.dll SUCCESS Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: R
- 2:48:03.1027927 FILE LOCKED WITH
- PM unpacked.exe3456CreateFileMapping C:\Windows\System32\dbghelp.dll ONLY READERS SyncType: SyncTypeCreateSection, PageProtection: PAGE
- 2:48:03.1028249
- PM unpacked.exe3456CreateFileMapping C:\Windows\System32\dbghelp.dll SUCCESS SyncType: SyncTypeOther
- 2:48:03.1029163
- PM unpacked.exe3456Load Image C:\Windows\System32\dbghelp.dll SUCCESS Image Base: 0x6cd80000, Image Size: 0xeb000
- 2:48:03.1029271
- PM unpacked.exe3456CloseFile C:\Windows\System32\dbghelp.dll SUCCESS
- 2:48:03.1031051
- PM unpacked.exe3456Load Image C:\Windows\System32\user32.dll SUCCESS Image Base: 0x76ae0000, Image Size: 0xc9000
- 2:48:03.1032307
- PM unpacked.exe3456Load Image C:\Windows\System32\gdi32.dll SUCCESS Image Base: 0x76320000, Image Size: 0x4e000
- 2:48:03.1033268
- PM unpacked.exe3456Load Image C:\Windows\System32\lpk.dll SUCCESS Image Base: 0x762f0000, Image Size: 0xa000
- 2:48:03.1034539
- PM unpacked.exe3456Load Image C:\Windows\System32\usp10.dll SUCCESS Image Base: 0x76bb0000, Image Size: 0x9d000
- 2:48:03.1035599
- PM unpacked.exe3456Load Image C:\Windows\System32\advapi32.dll SUCCESS Image Base: 0x75fd0000, Image Size: 0xa0000
- 2:48:03.1037262 Desired Access: Read Attributes, Disposition: Open, Option
- PM unpacked.exe3456CreateFile C:\Windows\System32\sechost.dll SUCCESS Write, Delete, AllocationSize: n/a, OpenResult: Opened
- 2:48:03.1037969 CreationTime: 7/14/2009 4:41:59 AM, LastAccessTime: 7/14
- PM unpacked.exe3456QueryBasicInformationFile C:\Windows\System32\sechost.dll SUCCESS ChangeTime: 6/30/2018 5:09:52 AM, FileAttributes: A
- 2:48:03.1038014
- PM unpacked.exe3456CloseFile C:\Windows\System32\sechost.dll SUCCESS
- 2:48:03.1038682 Desired Access: Read Data/List Directory, Execute/Travers
- PM unpacked.exe3456CreateFile C:\Windows\System32\sechost.dll SUCCESS Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: R
- 2:48:03.1039353 FILE LOCKED WITH
- PM unpacked.exe3456CreateFileMapping C:\Windows\System32\sechost.dll ONLY READERS SyncType: SyncTypeCreateSection, PageProtection: PAGE
- 2:48:03.1039548
- PM unpacked.exe3456CreateFileMapping C:\Windows\System32\sechost.dll SUCCESS SyncType: SyncTypeOther
- 2:48:03.1040322
- PM unpacked.exe3456Load Image C:\Windows\System32\sechost.dll SUCCESS Image Base: 0x768d0000, Image Size: 0x19000
- 2:48:03.1040428
- PM unpacked.exe3456CloseFile C:\Windows\System32\sechost.dll SUCCESS
- 2:48:03.1042860
- PM unpacked.exe3456Load Image C:\Windows\System32\shell32.dll SUCCESS Image Base: 0x76c50000, Image Size: 0xc4a000
- 2:48:03.1048389
- PM unpacked.exe3456Load Image C:\Windows\System32\shlwapi.dll SUCCESS Image Base: 0x77d50000, Image Size: 0x57000
- 2:48:03.1049907
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions REPARSE Desired Access: Read
- 2:48:03.1050023
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions SUCCESS Desired Access: Read
- 2:48:03.1050171
- PM unpacked.exe3456RegQueryValue HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions\(Default) SUCCESS Type: REG_SZ, Length: 36, Data: 00060101.00060101
- 2:48:03.1052328
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\Session Manager REPARSE Desired Access: Query Value
- 2:48:03.1052419
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\Session Manager SUCCESS Desired Access: Query Value
- 2:48:03.1052503
- PM unpacked.exe3456RegQueryValue HKLM\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode NAME NOT FOUND Length: 16
- 2:48:03.1055695 Desired Access: Read Attributes, Disposition: Open, Option
- PM unpacked.exe3456CreateFile C:\Windows\System32\imm32.dll SUCCESS Write, Delete, AllocationSize: n/a, OpenResult: Opened
- 2:48:03.1056467 CreationTime: 11/21/2010 2:59:20 AM, LastAccessTime: 11
- PM unpacked.exe3456QueryBasicInformationFile C:\Windows\System32\imm32.dll SUCCESS ChangeTime: 6/30/2018 5:09:22 AM, FileAttributes: A
- 2:48:03.1056513
- PM unpacked.exe3456CloseFile C:\Windows\System32\imm32.dll SUCCESS
- 2:48:03.1057424 Desired Access: Read Data/List Directory, Synchronize, Dis
- PM unpacked.exe3456CreateFile C:\Windows\System32\imm32.dll SUCCESS Directory File, Attributes: n/a, ShareMode: Read, Delete, Allo
- 2:48:03.1058415 FILE LOCKED WITH
- PM unpacked.exe3456CreateFileMapping C:\Windows\System32\imm32.dll ONLY READERS SyncType: SyncTypeCreateSection, PageProtection: PAGE
- 2:48:03.1058462
- PM unpacked.exe3456QueryStandardInformationFileC:\Windows\System32\imm32.dll SUCCESS AllocationSize: 118,784, EndOfFile: 118,272, NumberOfLink
- 2:48:03.1058556
- PM unpacked.exe3456CreateFileMapping C:\Windows\System32\imm32.dll SUCCESS SyncType: SyncTypeOther
- 2:48:03.1058843
- PM unpacked.exe3456CloseFile C:\Windows\System32\imm32.dll SUCCESS
- 2:48:03.1060436 Desired Access: Read Attributes, Disposition: Open, Option
- PM unpacked.exe3456CreateFile C:\Windows\System32\imm32.dll SUCCESS Write, Delete, AllocationSize: n/a, OpenResult: Opened
- 2:48:03.1061153 CreationTime: 11/21/2010 2:59:20 AM, LastAccessTime: 11
- PM unpacked.exe3456QueryBasicInformationFile C:\Windows\System32\imm32.dll SUCCESS ChangeTime: 6/30/2018 5:09:22 AM, FileAttributes: A
- 2:48:03.1061196
- PM unpacked.exe3456CloseFile C:\Windows\System32\imm32.dll SUCCESS
- 2:48:03.1062275 Desired Access: Read Data/List Directory, Synchronize, Dis
- PM unpacked.exe3456CreateFile C:\Windows\System32\imm32.dll SUCCESS Directory File, Attributes: n/a, ShareMode: Read, Delete, Allo
- 2:48:03.1063070 FILE LOCKED WITH
- PM unpacked.exe3456CreateFileMapping C:\Windows\System32\imm32.dll ONLY READERS SyncType: SyncTypeCreateSection, PageProtection: PAGE
- 2:48:03.1063109
- PM unpacked.exe3456QueryStandardInformationFileC:\Windows\System32\imm32.dll SUCCESS AllocationSize: 118,784, EndOfFile: 118,272, NumberOfLink
- 2:48:03.1063208
- PM unpacked.exe3456CreateFileMapping C:\Windows\System32\imm32.dll SUCCESS SyncType: SyncTypeOther
- 2:48:03.1063430
- PM unpacked.exe3456CloseFile C:\Windows\System32\imm32.dll SUCCESS
- 2:48:03.1064779 Desired Access: Read Attributes, Disposition: Open, Option
- PM unpacked.exe3456CreateFile C:\Windows\System32\imm32.dll SUCCESS Write, Delete, AllocationSize: n/a, OpenResult: Opened
- 2:48:03.1065700 CreationTime: 11/21/2010 2:59:20 AM, LastAccessTime: 11
- PM unpacked.exe3456QueryBasicInformationFile C:\Windows\System32\imm32.dll SUCCESS ChangeTime: 6/30/2018 5:09:22 AM, FileAttributes: A
- 2:48:03.1065740
- PM unpacked.exe3456CloseFile C:\Windows\System32\imm32.dll SUCCESS
- 2:48:03.1066460 Desired Access: Read Data/List Directory, Execute/Travers
- PM unpacked.exe3456CreateFile C:\Windows\System32\imm32.dll SUCCESS Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: R
- 2:48:03.1067327 FILE LOCKED WITH
- PM unpacked.exe3456CreateFileMapping C:\Windows\System32\imm32.dll ONLY READERS SyncType: SyncTypeCreateSection, PageProtection: PAGE
- 2:48:03.1067530
- PM unpacked.exe3456CreateFileMapping C:\Windows\System32\imm32.dll SUCCESS SyncType: SyncTypeOther
- 2:48:03.1068327
- PM unpacked.exe3456Load Image C:\Windows\System32\imm32.dll SUCCESS Image Base: 0x76300000, Image Size: 0x1f000
- 2:48:03.1068507
- PM unpacked.exe3456CloseFile C:\Windows\System32\imm32.dll SUCCESS
- 2:48:03.1069789
- PM unpacked.exe3456Load Image C:\Windows\System32\msctf.dll SUCCESS Image Base: 0x76370000, Image Size: 0xcc000
- 2:48:03.1071816
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\Error Message Instrument",REPARSE" Desired Access: Read
- 2:48:03.1071949
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\Error Message Instrument NAME NOT FOUND Desired Access: Read
- 2:48:03.1072048unpacked.exe3456RegOpenKey HKLM\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize SUCCESS Desired Access: Read
- PM
- 2:48:03.1072221 HKLM\SOFTWARE\Microsoft\Windows
- PM unpacked.exe3456RegQueryValue NT\CurrentVersion\GRE_Initialize\DisableMetaFiles NAME NOT FOUND Length: 20
- 2:48:03.1072282
- PM unpacked.exe3456RegCloseKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize SUCCESS
- 2:48:03.1072593
- PM unpacked.exe3456RegOpenKey HKLM\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32 SUCCESS Desired Access: Read
- 2:48:03.1072708
- PM unpacked.exe3456RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32\unpacked NAME NOT FOUND Length: 172
- 2:48:03.1072769
- PM unpacked.exe3456RegCloseKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32 SUCCESS
- 2:48:03.1072825
- PM unpacked.exe3456RegOpenKey HKLM\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility NAME NOT FOUND Desired Access: Read
- 2:48:03.1074281
- PM unpacked.exe3456RegOpenKey HKLM SUCCESS Desired Access: Maximum Allowed, Granted Access: Read
- 2:48:03.1074374
- PM unpacked.exe3456RegOpenKey HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows SUCCESS Desired Access: Read
- 2:48:03.1074471
- PM unpacked.exe3456RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs SUCCESS Type: REG_DWORD, Length: 4, Data: 0
- 2:48:03.1074532
- PM unpacked.exe3456RegCloseKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows SUCCESS
- 2:48:03.1075229
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\Terminal Server REPARSE Desired Access: Read
- 2:48:03.1075304
- PM unpacked.exe3456RegOpenKey HKLM\System\CurrentControlSet\Control\Terminal Server SUCCESS Desired Access: Read
- 2:48:03.1075376
- PM unpacked.exe3456RegQueryValue HKLM\System\CurrentControlSet\Control\Terminal Server\TSAppCompat NAME NOT FOUND Length: 548
- 2:48:03.1075412
- PM unpacked.exe3456RegQueryValue HKLM\System\CurrentControlSet\Control\Terminal Server\TSUserEnabled SUCCESS Type: REG_DWORD, Length: 4, Data: 0
- 2:48:03.1075446
- PM unpacked.exe3456RegCloseKey HKLM\System\CurrentControlSet\Control\Terminal Server SUCCESS
- 2:48:03.1075567
- PM unpacked.exe3456RegOpenKey HKLM\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics NAME NOT FOUND Desired Access: Read
- 2:48:03.1077572
- PM unpacked.exe3456QueryNameInformationFile C:\Users\hackbox\Music\unpacked\unpacked.exe SUCCESS Name: \Users\hackbox\Music\unpacked\unpacked.exe
- Desired Access:
- Synchronize, Disposition:
- Open, Options: Directory,
- Synchronous IO Non-
- Alert, Attributes: n/a,
- ShareMode: None,
- 2:48:03.1077938 AllocationSize: n/a,
- PM unpacked.exe3456CreateFile C:",SUCCESS" OpenResult: Opened
- 2:48:03.1078316 Name: "
- PM unpacked.exe3456QueryNameInformationFile C:",SUCCESS" 2:48:03.1078409 PM" unpacked.exe
- 2:48:03.1078475
- PM unpacked.exe3456CloseFile C:",SUCCESS"
- 2:48:03.1078873
- PM unpacked.exe3456RegOpenKey HKCU SUCCESS Desired Access: Maximum Allowed, Granted Access: All A
- 2:48:03.1078979
- PM unpacked.exe3456RegOpenKey HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SUCCESS Desired Access: Query Value
- 2:48:03.1079067
- PM unpacked.exe3456RegQueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MSConfig NAME NOT FOUND Length: 144
- 2:48:03.1079106
- PM unpacked.exe3456RegCloseKey HKCU\Software\Microsoft\Windows\CurrentVersion\Run SUCCESS
- 2:48:03.1080155 Desired Access: Generic Read, Disposition: Open, Options
- PM unpacked.exe3456CreateFile C:\Users\hackbox\Music\unpacked\unpacked.exe SUCCESS ShareMode: Read, Write, AllocationSize: n/a, OpenResult: O
- 2:48:03.1080402
- PM unpacked.exe3456QueryStandardInformationFileC:\Users\hackbox\Music\unpacked\unpacked.exe SUCCESS AllocationSize: 61,440, EndOfFile: 58,880, NumberOfLinks:
- 2:48:03.1080485
- PM unpacked.exe3456ReadFile C:\Users\hackbox\Music\unpacked\unpacked.exe SUCCESS Offset: 0, Length: 64, Priority: Normal
- 2:48:03.1080705
- PM unpacked.exe3456ReadFile C:\Users\hackbox\Music\unpacked\unpacked.exe SUCCESS Offset: 208, Length: 248, Priority: Normal
- 2:48:03.1080794
- PM
- 2:48:03.1080867unpacked.exe3456ReadFile C:\Users\hackbox\Music\unpacked\unpacked.exe SUCCESS Offset: 456, Length: 40, Priority: Normal
- PM unpacked.exe3456ReadFile C:\Users\hackbox\Music\unpacked\unpacked.exe SUCCESS Offset: 496, Length: 40, Priority: Normal
- 2:48:03.1081021
- PM unpacked.exe3456ReadFile C:\Users\hackbox\Music\unpacked\unpacked.exe SUCCESS Offset: 536, Length: 40, Priority: Normal
- 2:48:03.1081091
- PM unpacked.exe3456ReadFile C:\Users\hackbox\Music\unpacked\unpacked.exe SUCCESS Offset: 576, Length: 40, Priority: Normal
- 2:48:03.1081378
- PM unpacked.exe3456ReadFile C:\Users\hackbox\Music\unpacked\unpacked.exe SUCCESS Offset: 0, Length: 58,880, Priority: Normal
- 2:48:03.1081594
- PM unpacked.exe3456CloseFile C:\Users\hackbox\Music\unpacked\unpacked.exe SUCCESS
- 2:48:03.1082840 Desired Access: Generic Write, Read Attributes, Disposition
- PM unpacked.exe3456CreateFile C:\Users\hackbox\phkzamed.exe SUCCESS Directory File, Attributes: N, ShareMode: None, AllocationSi
- 2:48:03.1085662 Desired Access: Write Attributes, Synchronize, Disposition:
- PM unpacked.exe3456CreateFile C:\Users\hackbox\phkzamed.exe SUCCESS Point, Attributes: n/a, ShareMode: Read, Write, Delete, Alloc
- 2:48:03.1086371 CreationTime: 1/1/1601 5:30:00 AM, LastAccessTime: 1/1/1
- PM unpacked.exe3456SetBasicInformationFile C:\Users\hackbox\phkzamed.exe SUCCESS ChangeTime: 1/1/1601 5:30:00 AM, FileAttributes: HN
- 2:48:03.1086656
- PM unpacked.exe3456CloseFile C:\Users\hackbox\phkzamed.exe SUCCESS
- Desired Access:
- Synchronize, Disposition:
- Open, Options: Directory,
- Synchronous IO Non-
- Alert, Open For Free
- Space Query, Attributes:
- n/a, ShareMode: Read,
- 2:48:03.1086951 Write, AllocationSize: n/a,
- PM unpacked.exe3456CreateFile C:",SUCCESS" OpenResult: Opened
- TotalAllocationUnits:
- 5,452,543,
- AvailableAllocationUnits:
- 3,002,704,
- 2:48:03.1087225 SectorsPerAllocationUnit:
- PM unpacked.exe3456QuerySizeInformationVolume C:",SUCCESS" 8, BytesPerSector: 512
- 2:48:03.1087289
- PM unpacked.exe3456CloseFile C:",SUCCESS"
- 2:48:03.1087595
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 0, Length: 55,296, Priority: Normal
- 2:48:03.1088506
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 55,296, Length: 3,584, Priority: Normal
- 2:48:03.1088754
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 58,880, Length: 3,584
- 2:48:03.1088861
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 62,464, Length: 3,584, Priority: Normal
- 2:48:03.1089058
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 66,048, Length: 3,584
- 2:48:03.1089102
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 69,632, Length: 3,584
- 2:48:03.1089144
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 73,216, Length: 3,584
- 2:48:03.1089193
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 76,800, Length: 3,584
- 2:48:03.1089268
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 80,384, Length: 3,584, Priority: Normal
- 2:48:03.1089453
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 83,968, Length: 3,584
- 2:48:03.1089515
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 87,552, Length: 3,584
- 2:48:03.1089562
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 91,136, Length: 3,584
- 2:48:03.1089611
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 94,720, Length: 3,584
- 2:48:03.1089652
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 98,304, Length: 3,584
- 2:48:03.1089709
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 101,888, Length: 3,584
- 2:48:03.1089858
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 105,472, Length: 3,584
- 2:48:03.1089927
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 109,056, Length: 3,584
- 2:48:03.1089984unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 112,640, Length: 3,584
- PM
- 2:48:03.1090034
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 116,224, Length: 3,584
- 2:48:03.1090082
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 119,808, Length: 3,584
- 2:48:03.1090130
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 123,392, Length: 3,584
- 2:48:03.1090169
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 126,976, Length: 3,584
- 2:48:03.1090238
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 130,560, Length: 3,584, Priority: Normal
- 2:48:03.1090441
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 134,144, Length: 3,584
- 2:48:03.1090496
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 137,728, Length: 3,584
- 2:48:03.1090552
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 141,312, Length: 3,584
- 2:48:03.1090626
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 144,896, Length: 3,584
- 2:48:03.1090679
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 148,480, Length: 3,584
- 2:48:03.1090725
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 152,064, Length: 3,584
- 2:48:03.1090766
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 155,648, Length: 3,584
- 2:48:03.1090808
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 159,232, Length: 3,584
- 2:48:03.1090855
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 162,816, Length: 3,584
- 2:48:03.1090924
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 166,400, Length: 3,584
- 2:48:03.1090977
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 169,984, Length: 3,584
- 2:48:03.1091025
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 173,568, Length: 3,584
- 2:48:03.1091071
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 177,152, Length: 3,584
- 2:48:03.1091116
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 180,736, Length: 3,584
- 2:48:03.1091154
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 184,320, Length: 3,584
- 2:48:03.1091195
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 187,904, Length: 3,584
- 2:48:03.1091244
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 191,488, Length: 3,584
- 2:48:03.1091353
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 195,072, Length: 3,584, Priority: Normal
- 2:48:03.1091562
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 198,656, Length: 3,584
- 2:48:03.1091614
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 202,240, Length: 3,584
- 2:48:03.1091663
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 205,824, Length: 3,584
- 2:48:03.1091709
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 209,408, Length: 3,584
- 2:48:03.1091748
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 212,992, Length: 3,584
- 2:48:03.1091791
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 216,576, Length: 3,584
- 2:48:03.1091839
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 220,160, Length: 3,584
- 2:48:03.1091902
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 223,744, Length: 3,584
- 2:48:03.1169408unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,442,176, Length: 3,584
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,445,760, Length: 3,584
- 2:48:03.1169453
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,449,344, Length: 3,584
- 2:48:03.1169494
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,452,928, Length: 3,584
- 2:48:03.1169537
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,456,512, Length: 3,584
- 2:48:03.1169586
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,460,096, Length: 3,584
- 2:48:03.1169633
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,463,680, Length: 3,584
- 2:48:03.1169680
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,467,264, Length: 3,584
- 2:48:03.1169758
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,470,848, Length: 3,584, Priority: Normal
- 2:48:03.1170086
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,474,432, Length: 3,584
- 2:48:03.1170135
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,478,016, Length: 3,584
- 2:48:03.1170174
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,481,600, Length: 3,584
- 2:48:03.1170232
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,485,184, Length: 3,584
- 2:48:03.1170301
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,488,768, Length: 3,584
- 2:48:03.1170446
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,492,352, Length: 3,584
- 2:48:03.1170502
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,495,936, Length: 3,584
- 2:48:03.1170874
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,499,520, Length: 3,584
- 2:48:03.1170931
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,503,104, Length: 3,584
- 2:48:03.1170981
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,506,688, Length: 3,584
- 2:48:03.1171023
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,510,272, Length: 3,584
- 2:48:03.1171066
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,513,856, Length: 3,584
- 2:48:03.1171111
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,517,440, Length: 3,584
- 2:48:03.1171157
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,521,024, Length: 3,584
- 2:48:03.1171219
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,524,608, Length: 3,584
- 2:48:03.1171266
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,528,192, Length: 3,584
- 2:48:03.1171311
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,531,776, Length: 3,584
- 2:48:03.1171365
- PM unpacked.exe3456WriteFile C:\Users\hackbox\phkzamed.exe SUCCESS Offset: 3,535,360, Length: 3,584
- 2:48:03.1171435
Add Comment
Please, Sign In to add comment