paladin316

Gozi_e3af1730c3264c2d91817fab80b927d2_pptx_2019-06-27_21_30.json

Jun 27th, 2019
2,223
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 143.75 KB | None | 0 0
  1.  
  2. [*] MalFamily: "Gozi"
  3.  
  4. [*] MalScore: 10.0
  5.  
  6. [*] File Name: "Gozi_e3af1730c3264c2d91817fab80b927d2.pptx"
  7. [*] File Size: 166696
  8. [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. [*] SHA256: "be342db3ac1a9e12ad2d5a945cd0d4fdba487b0f20f7e7ccd47e81b04074e3b1"
  10. [*] MD5: "e3af1730c3264c2d91817fab80b927d2"
  11. [*] SHA1: "5b6dcd1189940703dd237e06d6282eafd6e68bae"
  12. [*] SHA512: "21381c97de7052482e2e78973f2204e5723940650b6d5bc282647a1907956545c94e86f83cd4fc60219766893a29e2cc9b428f4ed4b1b10ac3fade5fe91532d1"
  13. [*] CRC32: "3E518DFC"
  14. [*] SSDEEP: "3072:QTJbfxTA+vj+BIs5abTjYyz9aAbyTqGINOdmY23qa/2m:uJb1haBcbTjYtD7mj3v"
  15.  
  16. [*] Process Execution: [
  17. "Gozi_e3af1730c3264c2d91817fab80b927d2.pptx",
  18. "svchost.exe",
  19. "WmiPrvSE.exe",
  20. "iexplore.exe",
  21. "iexplore.exe",
  22. "iexplore.exe",
  23. "iexplore.exe",
  24. "iexplore.exe",
  25. "iexplore.exe",
  26. "iexplore.exe",
  27. "iexplore.exe",
  28. "iexplore.exe",
  29. "iexplore.exe",
  30. "iexplore.exe",
  31. "iexplore.exe",
  32. "iexplore.exe",
  33. "iexplore.exe",
  34. "iexplore.exe",
  35. "iexplore.exe",
  36. "iexplore.exe",
  37. "iexplore.exe",
  38. "iexplore.exe",
  39. "iexplore.exe",
  40. "iexplore.exe",
  41. "iexplore.exe",
  42. "iexplore.exe",
  43. "iexplore.exe",
  44. "iexplore.exe",
  45. "iexplore.exe",
  46. "iexplore.exe",
  47. "iexplore.exe",
  48. "iexplore.exe",
  49. "iexplore.exe",
  50. "iexplore.exe",
  51. "iexplore.exe",
  52. "iexplore.exe",
  53. "iexplore.exe",
  54. "iexplore.exe",
  55. "iexplore.exe",
  56. "iexplore.exe",
  57. "iexplore.exe",
  58. "iexplore.exe"
  59. ]
  60.  
  61. [*] Signatures Detected: [
  62. {
  63. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  64. "Details": [
  65. {
  66. "IP": "204.79.197.200:80"
  67. }
  68. ]
  69. },
  70. {
  71. "Description": "Creates RWX memory",
  72. "Details": []
  73. },
  74. {
  75. "Description": "A process attempted to delay the analysis task.",
  76. "Details": [
  77. {
  78. "Process": "Gozi_e3af1730c3264c2d91817fab80b927d2.pptx tried to sleep 1503 seconds, actually delayed analysis time by 0 seconds"
  79. },
  80. {
  81. "Process": "WmiPrvSE.exe tried to sleep 360 seconds, actually delayed analysis time by 0 seconds"
  82. }
  83. ]
  84. },
  85. {
  86. "Description": "Performs some HTTP requests",
  87. "Details": [
  88. {
  89. "url": "http://www.bing.com/favicon.ico"
  90. }
  91. ]
  92. },
  93. {
  94. "Description": "The binary likely contains encrypted or compressed data.",
  95. "Details": [
  96. {
  97. "section": "name: .reloc, entropy: 7.88, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00015000, virtual_size: 0x000141af"
  98. }
  99. ]
  100. },
  101. {
  102. "Description": "Crashed cuckoomon during analysis. Report this error to the Github repo.",
  103. "Details": [
  104. {
  105. "pid": 2576
  106. },
  107. {
  108. "message": "Exception reported at offset 0x1967e in cuckoomon itself while accessing 0x78d5f8 from hook RtlDispatchException"
  109. },
  110. {
  111. "pid": 2576
  112. },
  113. {
  114. "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  115. },
  116. {
  117. "pid": 2576
  118. },
  119. {
  120. "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x78d5fc from hook RtlDispatchException"
  121. },
  122. {
  123. "pid": 2576
  124. },
  125. {
  126. "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  127. },
  128. {
  129. "pid": 2576
  130. },
  131. {
  132. "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x78d5f4 from hook RtlDispatchException"
  133. },
  134. {
  135. "pid": 2576
  136. },
  137. {
  138. "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  139. },
  140. {
  141. "pid": 2576
  142. },
  143. {
  144. "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x78d5f0 from hook RtlDispatchException"
  145. },
  146. {
  147. "pid": 2576
  148. },
  149. {
  150. "message": "Exception reported at offset 0x19689 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  151. },
  152. {
  153. "pid": 2576
  154. },
  155. {
  156. "message": "Exception reported at offset 0x19699 in cuckoomon itself while accessing 0x78d600 from hook RtlDispatchException"
  157. },
  158. {
  159. "pid": 2576
  160. },
  161. {
  162. "message": "Exception reported at offset 0x1969b in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  163. },
  164. {
  165. "pid": 2576
  166. },
  167. {
  168. "message": "Exception reported at offset 0x1969f in cuckoomon itself while accessing 0x78d604 from hook RtlDispatchException"
  169. },
  170. {
  171. "pid": 2576
  172. },
  173. {
  174. "message": "Exception reported at offset 0x196a2 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  175. },
  176. {
  177. "pid": 2576
  178. },
  179. {
  180. "message": "Exception reported at offset 0x196aa in cuckoomon itself while accessing 0x78d608 from hook RtlDispatchException"
  181. },
  182. {
  183. "pid": 2576
  184. },
  185. {
  186. "message": "Exception reported at offset 0x196ad in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  187. },
  188. {
  189. "pid": 2576
  190. },
  191. {
  192. "message": "Exception reported at offset 0x196bd in cuckoomon itself while accessing 0x78d60c from hook RtlDispatchException"
  193. },
  194. {
  195. "pid": 2576
  196. },
  197. {
  198. "message": "Exception reported at offset 0x196c0 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  199. },
  200. {
  201. "pid": 2576
  202. },
  203. {
  204. "message": "Exception reported at offset 0x19bfc in cuckoomon itself while accessing 0x78d5f0 from hook RtlDispatchException"
  205. },
  206. {
  207. "pid": 2576
  208. },
  209. {
  210. "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  211. },
  212. {
  213. "pid": 2576
  214. },
  215. {
  216. "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x78d5f4 from hook RtlDispatchException"
  217. },
  218. {
  219. "pid": 2576
  220. },
  221. {
  222. "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  223. },
  224. {
  225. "pid": 2576
  226. },
  227. {
  228. "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x78d5f8 from hook RtlDispatchException"
  229. },
  230. {
  231. "pid": 2576
  232. },
  233. {
  234. "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  235. },
  236. {
  237. "pid": 2576
  238. },
  239. {
  240. "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x78d5fc from hook RtlDispatchException"
  241. },
  242. {
  243. "pid": 2576
  244. },
  245. {
  246. "message": "Exception reported at offset 0x19c07 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  247. },
  248. {
  249. "pid": 2576
  250. },
  251. {
  252. "message": "Exception reported at offset 0x1967e in cuckoomon itself while accessing 0x78d678 from hook RtlDispatchException"
  253. },
  254. {
  255. "pid": 2576
  256. },
  257. {
  258. "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x78d67c from hook RtlDispatchException"
  259. },
  260. {
  261. "pid": 2576
  262. },
  263. {
  264. "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x78d674 from hook RtlDispatchException"
  265. },
  266. {
  267. "pid": 2576
  268. },
  269. {
  270. "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x78d670 from hook RtlDispatchException"
  271. },
  272. {
  273. "pid": 2576
  274. },
  275. {
  276. "message": "Exception reported at offset 0x19699 in cuckoomon itself while accessing 0x78d630 from hook RtlDispatchException"
  277. },
  278. {
  279. "pid": 2576
  280. },
  281. {
  282. "message": "Exception reported at offset 0x1969f in cuckoomon itself while accessing 0x78d634 from hook RtlDispatchException"
  283. },
  284. {
  285. "pid": 2576
  286. },
  287. {
  288. "message": "Exception reported at offset 0x196aa in cuckoomon itself while accessing 0x78d638 from hook RtlDispatchException"
  289. },
  290. {
  291. "pid": 2576
  292. },
  293. {
  294. "message": "Exception reported at offset 0x196bd in cuckoomon itself while accessing 0x78d63c from hook RtlDispatchException"
  295. },
  296. {
  297. "pid": 2576
  298. },
  299. {
  300. "message": "Exception reported at offset 0x19bfc in cuckoomon itself while accessing 0x78d670 from hook RtlDispatchException"
  301. },
  302. {
  303. "pid": 2576
  304. },
  305. {
  306. "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x78d674 from hook RtlDispatchException"
  307. },
  308. {
  309. "pid": 2576
  310. },
  311. {
  312. "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x78d678 from hook RtlDispatchException"
  313. },
  314. {
  315. "pid": 2576
  316. },
  317. {
  318. "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x78d67c from hook RtlDispatchException"
  319. }
  320. ]
  321. },
  322. {
  323. "Description": "Creates a hidden or system file",
  324. "Details": [
  325. {
  326. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\IETldCache\\Low"
  327. },
  328. {
  329. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11dc4ab.TMP"
  330. },
  331. {
  332. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF12068ce.TMP"
  333. },
  334. {
  335. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF121e344.TMP"
  336. },
  337. {
  338. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF129b13a.TMP"
  339. },
  340. {
  341. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF129e47f.TMP"
  342. },
  343. {
  344. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11c6f3f.TMP"
  345. },
  346. {
  347. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11ca3fb.TMP"
  348. },
  349. {
  350. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11cc483.TMP"
  351. },
  352. {
  353. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11cf799.TMP"
  354. },
  355. {
  356. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d15df.TMP"
  357. },
  358. {
  359. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d450d.TMP"
  360. },
  361. {
  362. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d66ed.TMP"
  363. },
  364. {
  365. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d98da.TMP"
  366. },
  367. {
  368. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11dc2e8.TMP"
  369. },
  370. {
  371. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11ded34.TMP"
  372. },
  373. {
  374. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e2c02.TMP"
  375. },
  376. {
  377. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e6496.TMP"
  378. },
  379. {
  380. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e92bb.TMP"
  381. },
  382. {
  383. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF12d2bda.TMP"
  384. },
  385. {
  386. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11eff50.TMP"
  387. }
  388. ]
  389. },
  390. {
  391. "Description": "File has been identified by 40 Antiviruses on VirusTotal as malicious",
  392. "Details": [
  393. {
  394. "MicroWorld-eScan": "Trojan.GenericKD.41371533"
  395. },
  396. {
  397. "CAT-QuickHeal": "Trojan.Gozi"
  398. },
  399. {
  400. "McAfee": "Artemis!E3AF1730C326"
  401. },
  402. {
  403. "K7AntiVirus": "Spyware ( 0052a6bb1 )"
  404. },
  405. {
  406. "Alibaba": "TrojanBanker:Win32/Gozi.92f777a7"
  407. },
  408. {
  409. "K7GW": "Spyware ( 0052a6bb1 )"
  410. },
  411. {
  412. "Arcabit": "Trojan.Generic.D277478D"
  413. },
  414. {
  415. "Symantec": "Trojan.Gen.2"
  416. },
  417. {
  418. "APEX": "Malicious"
  419. },
  420. {
  421. "Avast": "Win32:Trojan-gen"
  422. },
  423. {
  424. "Kaspersky": "Trojan-Banker.Win32.Gozi.dge"
  425. },
  426. {
  427. "BitDefender": "Trojan.GenericKD.41371533"
  428. },
  429. {
  430. "NANO-Antivirus": "Trojan.Win32.Gozi.frnvpd"
  431. },
  432. {
  433. "Paloalto": "generic.ml"
  434. },
  435. {
  436. "Tencent": "Win32.Trojan-banker.Gozi.Akff"
  437. },
  438. {
  439. "Endgame": "malicious (high confidence)"
  440. },
  441. {
  442. "Emsisoft": "MalCert.D (A)"
  443. },
  444. {
  445. "Comodo": "Malware@#3cufp1sljdt1q"
  446. },
  447. {
  448. "DrWeb": "Trojan.Gozi.499"
  449. },
  450. {
  451. "Invincea": "heuristic"
  452. },
  453. {
  454. "McAfee-GW-Edition": "Artemis"
  455. },
  456. {
  457. "FireEye": "Generic.mg.e3af1730c3264c2d"
  458. },
  459. {
  460. "Sophos": "Mal/Generic-S"
  461. },
  462. {
  463. "SentinelOne": "DFI - Malicious PE"
  464. },
  465. {
  466. "Cyren": "W32/Trojan.EYBA-5385"
  467. },
  468. {
  469. "Microsoft": "Trojan:Win32/Skeeyah.A!bit"
  470. },
  471. {
  472. "ZoneAlarm": "Trojan-Banker.Win32.Gozi.dge"
  473. },
  474. {
  475. "GData": "Trojan.GenericKD.41371533"
  476. },
  477. {
  478. "ALYac": "Trojan.Banker.Gozi"
  479. },
  480. {
  481. "MAX": "malware (ai score=100)"
  482. },
  483. {
  484. "Ad-Aware": "Trojan.GenericKD.41371533"
  485. },
  486. {
  487. "ESET-NOD32": "Win32/Spy.Ursnif.BP"
  488. },
  489. {
  490. "TrendMicro-HouseCall": "TROJ_GEN.R017H0DFE19"
  491. },
  492. {
  493. "Rising": "Malware.Heuristic.MLite(84%) (AI-LITE:vE1Ogx1e+drNGotX/Qk2DQ)"
  494. },
  495. {
  496. "Ikarus": "Trojan-Spy.Agent"
  497. },
  498. {
  499. "Fortinet": "W32/Ursnif.BP!tr.spy"
  500. },
  501. {
  502. "AVG": "Win32:Trojan-gen"
  503. },
  504. {
  505. "Panda": "Trj/CI.A"
  506. },
  507. {
  508. "CrowdStrike": "win/malicious_confidence_60% (W)"
  509. },
  510. {
  511. "Qihoo-360": "HEUR/QVM20.1.E139.Malware.Gen"
  512. }
  513. ]
  514. },
  515. {
  516. "Description": "Attempts to modify proxy settings",
  517. "Details": []
  518. }
  519. ]
  520.  
  521. [*] Started Service: []
  522.  
  523. [*] Executed Commands: [
  524. "C:\\Windows\\sysWOW64\\wbem\\wmiprvse.exe -secured -Embedding",
  525. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" -Embedding",
  526. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2372 CREDAT:79873",
  527. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2372 CREDAT:145409",
  528. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2796 CREDAT:79873",
  529. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:676 CREDAT:79873",
  530. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:292 CREDAT:79873",
  531. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1588 CREDAT:79873",
  532. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1452 CREDAT:79873",
  533. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1388 CREDAT:79873",
  534. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1880 CREDAT:79873",
  535. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2664 CREDAT:79873",
  536. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2440 CREDAT:79873",
  537. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2692 CREDAT:79873",
  538. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:804 CREDAT:79873",
  539. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2716 CREDAT:79873",
  540. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:996 CREDAT:79873",
  541. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2028 CREDAT:79873",
  542. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1528 CREDAT:79873",
  543. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2308 CREDAT:79873",
  544. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2332 CREDAT:79873",
  545. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2852 CREDAT:79873"
  546. ]
  547.  
  548. [*] Mutexes: [
  549. "Local\\9510B8B7-82F5-2171-7207-FC794AD1C6EA",
  550. "Local\\_!MSFTHISTORY!_",
  551. "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
  552. "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
  553. "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
  554. "Local\\WininetStartupMutex",
  555. "Local\\WininetConnectionMutex",
  556. "Local\\WininetProxyRegistryMutex",
  557. "Local\\!IETld!Mutex",
  558. "Local\\!BrowserEmulation!SharedMemory!Mutex",
  559. "Local\\ZoneAttributeCacheCounterMutex",
  560. "Local\\ZonesCacheCounterMutex",
  561. "Local\\ZonesLockedCacheCounterMutex",
  562. "ConnHashTable<2372>_HashTable_Mutex",
  563. "Local\\ZonesCounterMutex",
  564. "Local\\RSS Eventing Connection Database Mutex 00000944",
  565. "Local\\Feed Eventing Shared Memory Mutex S-1-5-21-0000000000-0000000000-0000000000-1000",
  566. "Local\\c:!users!user!appdata!local!microsoft!feeds cache!",
  567. "Local\\c:!users!user!appdata!roaming!microsoft!windows!privacie!",
  568. "ConnHashTable<2796>_HashTable_Mutex",
  569. "Local\\RSS Eventing Connection Database Mutex 00000aec",
  570. "ConnHashTable<676>_HashTable_Mutex",
  571. "Local\\RSS Eventing Connection Database Mutex 000002a4",
  572. "ConnHashTable<292>_HashTable_Mutex",
  573. "Local\\RSS Eventing Connection Database Mutex 00000124",
  574. "ConnHashTable<1588>_HashTable_Mutex",
  575. "Local\\RSS Eventing Connection Database Mutex 00000634",
  576. "MSIMGSIZECacheMutex",
  577. "ConnHashTable<1452>_HashTable_Mutex",
  578. "Local\\RSS Eventing Connection Database Mutex 000005ac",
  579. "ConnHashTable<1388>_HashTable_Mutex",
  580. "Local\\RSS Eventing Connection Database Mutex 0000056c",
  581. "ConnHashTable<1880>_HashTable_Mutex",
  582. "Local\\RSS Eventing Connection Database Mutex 00000758",
  583. "ConnHashTable<2664>_HashTable_Mutex",
  584. "Local\\RSS Eventing Connection Database Mutex 00000a68",
  585. "ConnHashTable<2440>_HashTable_Mutex",
  586. "Local\\RSS Eventing Connection Database Mutex 00000988",
  587. "ConnHashTable<2692>_HashTable_Mutex",
  588. "Local\\RSS Eventing Connection Database Mutex 00000a84",
  589. "ConnHashTable<804>_HashTable_Mutex",
  590. "Local\\RSS Eventing Connection Database Mutex 00000324",
  591. "ConnHashTable<2716>_HashTable_Mutex",
  592. "Local\\RSS Eventing Connection Database Mutex 00000a9c",
  593. "ConnHashTable<996>_HashTable_Mutex",
  594. "Local\\RSS Eventing Connection Database Mutex 000003e4",
  595. "ConnHashTable<2028>_HashTable_Mutex",
  596. "Local\\RSS Eventing Connection Database Mutex 000007ec",
  597. "ConnHashTable<1528>_HashTable_Mutex",
  598. "Local\\RSS Eventing Connection Database Mutex 000005f8",
  599. "ConnHashTable<2308>_HashTable_Mutex",
  600. "Local\\RSS Eventing Connection Database Mutex 00000904",
  601. "Local\\Feed Arbitration Shared Memory Mutex [ User : S-1-5-21-0000000000-0000000000-0000000000-1000 ]",
  602. "Local\\Feeds Store Mutex S-1-5-21-0000000000-0000000000-0000000000-1000",
  603. "ConnHashTable<2332>_HashTable_Mutex",
  604. "Local\\RSS Eventing Connection Database Mutex 0000091c",
  605. "ConnHashTable<2852>_HashTable_Mutex",
  606. "Local\\RSS Eventing Connection Database Mutex 00000b24"
  607. ]
  608.  
  609. [*] Modified Files: [
  610. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  611. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
  612. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
  613. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
  614. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{022A481F-991D-11E9-8070-18C086CD4729}.dat",
  615. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF7039C55C1F26A4FD.TMP",
  616. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{022A4820-991D-11E9-8070-18C086CD4729}.dat",
  617. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF719335267FB80751.TMP",
  618. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon[1].ico",
  619. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon[2].ico",
  620. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon[3].ico",
  621. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon[4].ico",
  622. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{022A4822-991D-11E9-8070-18C086CD4729}.dat",
  623. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF3D71F6405D0A3257.TMP",
  624. "\\??\\pipe\\MsFteWds",
  625. "\\??\\PIPE\\samr",
  626. "\\??\\PIPE\\srvsvc",
  627. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\H58NRIQEF0J49CL9XINB.temp",
  628. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11dc4ab.TMP",
  629. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\favicon[1].ico",
  630. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\favicon[2].ico",
  631. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{022A4823-991D-11E9-8070-18C086CD4729}.dat",
  632. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF6635C3FD1AC9875D.TMP",
  633. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\6FJULFP3RG8Z0DK85E8T.temp",
  634. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF12068ce.TMP",
  635. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\372JPYXKI2ICJNJSCC8U.temp",
  636. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF121e344.TMP",
  637. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Feeds Cache\\index.dat",
  638. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\dnserror[1]",
  639. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\ErrorPageTemplate[1]",
  640. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\ErrorPageTemplate[2]",
  641. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\PrivacIE\\index.dat",
  642. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\errorPageStrings[1]",
  643. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts[1]",
  644. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts[2]",
  645. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\noConnect[1]",
  646. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\noConnect[2]",
  647. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\background_gradient[1]",
  648. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\down[1]",
  649. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favcenter[1]",
  650. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\tools[1]",
  651. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\dnserror[1]",
  652. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\ErrorPageTemplate[1]",
  653. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\errorPageStrings[2]",
  654. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\httpErrorPagesScripts[1]",
  655. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\background_gradient[2]",
  656. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\down[1]",
  657. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\favcenter[1]",
  658. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\tools[1]",
  659. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{0A27E9C3-991D-11E9-8070-18C086CD4729}.dat",
  660. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFFC876E9A36B75E41.TMP",
  661. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{0A27E9C4-991D-11E9-8070-18C086CD4729}.dat",
  662. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFCA5D2930069361D2.TMP",
  663. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon[1].ico",
  664. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon[2].ico",
  665. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon[3].ico",
  666. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon[4].ico",
  667. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\QF1ADM85ATTEYISHIHL6.temp",
  668. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF129b13a.TMP",
  669. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\dnserror[1]",
  670. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\ErrorPageTemplate[1]",
  671. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\errorPageStrings[1]",
  672. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\httpErrorPagesScripts[2]",
  673. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\noConnect[1]",
  674. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\down[2]",
  675. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\tools[1]",
  676. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{115FA839-991D-11E9-8070-18C086CD4729}.dat",
  677. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFC761795D2E4F2253.TMP",
  678. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{115FA83A-991D-11E9-8070-18C086CD4729}.dat",
  679. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF957A61B9B9AA975B.TMP",
  680. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favicon[1].ico",
  681. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\VNMBJ3DH3724KVX1VXUN.temp",
  682. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF129e47f.TMP",
  683. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\dnserror[1]",
  684. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\ErrorPageTemplate[1]",
  685. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\errorPageStrings[1]",
  686. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\httpErrorPagesScripts[1]",
  687. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\background_gradient[1]",
  688. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\down[1]",
  689. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favcenter[2]",
  690. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{1664BBB7-991D-11E9-8070-18C086CD4729}.dat",
  691. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF168D9ACE638B9EBA.TMP",
  692. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{1664BBB8-991D-11E9-8070-18C086CD4729}.dat",
  693. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF67E065919670E2EF.TMP",
  694. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\WDV7W8ZTOVPBKS69GOIG.temp",
  695. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11c6f3f.TMP",
  696. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\errorPageStrings[1]",
  697. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\background_gradient[1]",
  698. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favcenter[1]",
  699. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\tools[2]",
  700. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{1E6BE6C3-991D-11E9-8070-18C086CD4729}.dat",
  701. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF509842DBEFC330EC.TMP",
  702. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{1E6BE6C4-991D-11E9-8070-18C086CD4729}.dat",
  703. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF381661B4BE7FFDF6.TMP",
  704. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\SONNIFFI5HUQDLSOUCAK.temp",
  705. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11ca3fb.TMP",
  706. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\httpErrorPagesScripts[1]",
  707. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\down[1]",
  708. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\MSIMGSIZ.DAT",
  709. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\tools[1]",
  710. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{2337C1D1-991D-11E9-8070-18C086CD4729}.dat",
  711. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF89E0A9BA6FE47FAF.TMP",
  712. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{2337C1D2-991D-11E9-8070-18C086CD4729}.dat",
  713. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF95BB085FAF89F781.TMP",
  714. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\LAS6956X6PRQ1TEVQGW9.temp",
  715. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11cc483.TMP",
  716. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\background_gradient[1]",
  717. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favcenter[1]",
  718. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{2BE5D179-991D-11E9-8070-18C086CD4729}.dat",
  719. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB74A90ACB8B6686D.TMP",
  720. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{2BE5D17A-991D-11E9-8070-18C086CD4729}.dat",
  721. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF9AD394CDBF7D5C13.TMP",
  722. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\H0ISDU3RV36WM6UC81UG.temp",
  723. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11cf799.TMP",
  724. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\noConnect[1]",
  725. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{3054B0D1-991D-11E9-8070-18C086CD4729}.dat",
  726. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF8207C491A85CDE87.TMP",
  727. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{3054B0D2-991D-11E9-8070-18C086CD4729}.dat",
  728. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB1FB8DD00DE1D324.TMP",
  729. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\6I1VU22KEXPW89981D47.temp",
  730. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d15df.TMP",
  731. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\noConnect[1]",
  732. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\down[2]",
  733. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{354DD88D-991D-11E9-8070-18C086CD4729}.dat",
  734. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFAB6654B053047C03.TMP",
  735. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{354DD88E-991D-11E9-8070-18C086CD4729}.dat",
  736. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF6C056DEDAA6BB3EF.TMP",
  737. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\DKJI5ID60HF237TV20ZU.temp",
  738. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d450d.TMP",
  739. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favcenter[2]",
  740. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{3CA2333B-991D-11E9-8070-18C086CD4729}.dat",
  741. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF76D44CDACD6673E7.TMP",
  742. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{3CA2333C-991D-11E9-8070-18C086CD4729}.dat",
  743. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB242AB0679B2FA9D.TMP",
  744. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\CRURTB66JR88ZW3BKW4Q.temp",
  745. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d66ed.TMP",
  746. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\tools[2]",
  747. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{418F6F35-991D-11E9-8070-18C086CD4729}.dat",
  748. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF1CA8D08A73EB6C10.TMP",
  749. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{418F6F36-991D-11E9-8070-18C086CD4729}.dat",
  750. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFDF9910B6BEFF5DBA.TMP",
  751. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\J9UEQ8VSLSZXJH73TNWK.temp",
  752. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d98da.TMP",
  753. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{4ABE3DD9-991D-11E9-8070-18C086CD4729}.dat",
  754. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFC10FD87C451648C0.TMP",
  755. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{4ABE3DDA-991D-11E9-8070-18C086CD4729}.dat",
  756. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFA68A08A4A84C76BC.TMP",
  757. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\2F0597NZ74Z8U4XQZ9NF.temp",
  758. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11dc2e8.TMP",
  759. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\dnserror[2]",
  760. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\background_gradient[2]",
  761. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{502E9B29-991D-11E9-8070-18C086CD4729}.dat",
  762. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF908EE3B49B81668B.TMP",
  763. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{502E9B2A-991D-11E9-8070-18C086CD4729}.dat",
  764. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFDC345CFDF1107CFA.TMP",
  765. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\VVGBUBO8TAHLF2PMFE8J.temp",
  766. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11ded34.TMP",
  767. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\noConnect[2]",
  768. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{5A876FBF-991D-11E9-8070-18C086CD4729}.dat",
  769. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF0155D8FB2E46B312.TMP",
  770. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{5A876FC0-991D-11E9-8070-18C086CD4729}.dat",
  771. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF6D9E848A6C256AE4.TMP",
  772. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\3B9XAEKTDY9QS3E4NNAW.temp",
  773. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e2c02.TMP",
  774. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\down[2]",
  775. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{60382C8D-991D-11E9-8070-18C086CD4729}.dat",
  776. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF2CE555F16FCCAA3E.TMP",
  777. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{60382C8E-991D-11E9-8070-18C086CD4729}.dat",
  778. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF502B8FD847D48AD5.TMP",
  779. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\WZ1BRPAFDEHVLBPW4WZN.temp",
  780. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e6496.TMP",
  781. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favcenter[2]",
  782. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{6A497A97-991D-11E9-8070-18C086CD4729}.dat",
  783. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFEAB84CCEFB2A7E05.TMP",
  784. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{6A497A98-991D-11E9-8070-18C086CD4729}.dat",
  785. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF83E53BFA2A2ECF2A.TMP",
  786. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\R5UMAP16LXDRJ691QC8W.temp",
  787. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e92bb.TMP",
  788. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\tools[2]",
  789. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{702EAB21-991D-11E9-8070-18C086CD4729}.dat",
  790. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB2D3E68F7CBFCF12.TMP",
  791. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{702EAB22-991D-11E9-8070-18C086CD4729}.dat",
  792. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFDF5BAFF2EF7937D1.TMP",
  793. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Feeds\\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\\WebSlices~\\Suggested Sites~.feed-ms",
  794. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF1AF626254D711423.TMP",
  795. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF0C7DDE37D3E9C042.TMP",
  796. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF3728F500A19CFA33.TMP",
  797. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF5C74D2E82B35D492.TMP",
  798. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Feeds\\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\\WebSlices~\\Web Slice Gallery~.feed-ms",
  799. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFBDD952A43DABD60C.TMP",
  800. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF6E1D94A714D93D38.TMP",
  801. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\VY3PX1YTQ44901TOQNR9.temp",
  802. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF12d2bda.TMP",
  803. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{7ADFB6B9-991D-11E9-8070-18C086CD4729}.dat",
  804. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFE155A8FC5F1FF348.TMP",
  805. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{7ADFB6BA-991D-11E9-8070-18C086CD4729}.dat",
  806. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFDA713C653828C049.TMP",
  807. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\VGW54HG7YG91XA1IWJTV.temp",
  808. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11eff50.TMP",
  809. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\dnserror[2]",
  810. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{80EFD197-991D-11E9-8070-18C086CD4729}.dat",
  811. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF4F87479313F2CECF.TMP",
  812. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{80EFD198-991D-11E9-8070-18C086CD4729}.dat",
  813. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF2CFE32E797C42E43.TMP"
  814. ]
  815.  
  816. [*] Deleted Files: [
  817. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\Internet Explorer\\Services\\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico",
  818. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11dc4ab.TMP",
  819. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF12068ce.TMP",
  820. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF121e344.TMP",
  821. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{022A4823-991D-11E9-8070-18C086CD4729}.dat",
  822. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{022A4822-991D-11E9-8070-18C086CD4729}.dat",
  823. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{022A4820-991D-11E9-8070-18C086CD4729}.dat",
  824. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{022A481F-991D-11E9-8070-18C086CD4729}.dat",
  825. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\dnserror[1]",
  826. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\ErrorPageTemplate[1]",
  827. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\errorPageStrings[2]",
  828. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts[1]",
  829. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\noConnect[1]",
  830. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\background_gradient[1]",
  831. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\down[1]",
  832. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favcenter[1]",
  833. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\tools[1]",
  834. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\dnserror[1]",
  835. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\ErrorPageTemplate[2]",
  836. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\errorPageStrings[1]",
  837. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts[2]",
  838. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\noConnect[2]",
  839. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\background_gradient[1]",
  840. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\down[1]",
  841. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favcenter[1]",
  842. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\tools[1]",
  843. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF129b13a.TMP",
  844. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{0A27E9C4-991D-11E9-8070-18C086CD4729}.dat",
  845. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{0A27E9C3-991D-11E9-8070-18C086CD4729}.dat",
  846. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\dnserror[1]",
  847. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\ErrorPageTemplate[1]",
  848. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\errorPageStrings[2]",
  849. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\httpErrorPagesScripts[1]",
  850. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\background_gradient[2]",
  851. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\favcenter[1]",
  852. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\tools[1]",
  853. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF129e47f.TMP",
  854. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{115FA83A-991D-11E9-8070-18C086CD4729}.dat",
  855. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{115FA839-991D-11E9-8070-18C086CD4729}.dat",
  856. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\dnserror[1]",
  857. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\ErrorPageTemplate[1]",
  858. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\errorPageStrings[1]",
  859. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\httpErrorPagesScripts[2]",
  860. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\noConnect[1]",
  861. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\down[2]",
  862. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11c6f3f.TMP",
  863. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{1664BBB8-991D-11E9-8070-18C086CD4729}.dat",
  864. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{1664BBB7-991D-11E9-8070-18C086CD4729}.dat",
  865. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\ErrorPageTemplate[1]",
  866. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\errorPageStrings[1]",
  867. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\httpErrorPagesScripts[1]",
  868. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\background_gradient[1]",
  869. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\down[1]",
  870. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favcenter[2]",
  871. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11ca3fb.TMP",
  872. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{1E6BE6C4-991D-11E9-8070-18C086CD4729}.dat",
  873. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{1E6BE6C3-991D-11E9-8070-18C086CD4729}.dat",
  874. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\errorPageStrings[1]",
  875. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\background_gradient[1]",
  876. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favcenter[1]",
  877. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\tools[2]",
  878. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11cc483.TMP",
  879. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{2337C1D2-991D-11E9-8070-18C086CD4729}.dat",
  880. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{2337C1D1-991D-11E9-8070-18C086CD4729}.dat",
  881. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\httpErrorPagesScripts[1]",
  882. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\down[1]",
  883. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\tools[1]",
  884. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11cf799.TMP",
  885. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{2BE5D17A-991D-11E9-8070-18C086CD4729}.dat",
  886. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{2BE5D179-991D-11E9-8070-18C086CD4729}.dat",
  887. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d15df.TMP",
  888. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{3054B0D2-991D-11E9-8070-18C086CD4729}.dat",
  889. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{3054B0D1-991D-11E9-8070-18C086CD4729}.dat",
  890. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\noConnect[1]",
  891. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d450d.TMP",
  892. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{354DD88E-991D-11E9-8070-18C086CD4729}.dat",
  893. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{354DD88D-991D-11E9-8070-18C086CD4729}.dat",
  894. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\noConnect[1]",
  895. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\down[2]",
  896. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d66ed.TMP",
  897. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{3CA2333C-991D-11E9-8070-18C086CD4729}.dat",
  898. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{3CA2333B-991D-11E9-8070-18C086CD4729}.dat",
  899. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favcenter[2]",
  900. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon[3].png",
  901. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d98da.TMP",
  902. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{418F6F36-991D-11E9-8070-18C086CD4729}.dat",
  903. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{418F6F35-991D-11E9-8070-18C086CD4729}.dat",
  904. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\tools[2]",
  905. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11dc2e8.TMP",
  906. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{4ABE3DDA-991D-11E9-8070-18C086CD4729}.dat",
  907. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{4ABE3DD9-991D-11E9-8070-18C086CD4729}.dat",
  908. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11ded34.TMP",
  909. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{502E9B2A-991D-11E9-8070-18C086CD4729}.dat",
  910. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{502E9B29-991D-11E9-8070-18C086CD4729}.dat",
  911. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\dnserror[2]",
  912. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\background_gradient[2]",
  913. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e2c02.TMP",
  914. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{5A876FC0-991D-11E9-8070-18C086CD4729}.dat",
  915. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{5A876FBF-991D-11E9-8070-18C086CD4729}.dat",
  916. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\noConnect[2]",
  917. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e6496.TMP",
  918. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{60382C8E-991D-11E9-8070-18C086CD4729}.dat",
  919. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{60382C8D-991D-11E9-8070-18C086CD4729}.dat",
  920. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\down[2]",
  921. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon[4].png",
  922. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e92bb.TMP",
  923. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{6A497A98-991D-11E9-8070-18C086CD4729}.dat",
  924. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{6A497A97-991D-11E9-8070-18C086CD4729}.dat",
  925. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favcenter[2]",
  926. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon[5].png",
  927. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF12d2bda.TMP",
  928. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{702EAB22-991D-11E9-8070-18C086CD4729}.dat",
  929. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{702EAB21-991D-11E9-8070-18C086CD4729}.dat",
  930. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\tools[2]",
  931. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11eff50.TMP",
  932. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{7ADFB6BA-991D-11E9-8070-18C086CD4729}.dat",
  933. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{7ADFB6B9-991D-11E9-8070-18C086CD4729}.dat"
  934. ]
  935.  
  936. [*] Modified Registry Keys: [
  937. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE10RunOnceLastShown",
  938. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE10RunOnceLastShown_TIMESTAMP",
  939. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE8RunOnceLastShown",
  940. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE8RunOnceLastShown_TIMESTAMP",
  941. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\Check_Associations",
  942. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\VerCache",
  943. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\VerCache",
  944. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\VerCache",
  945. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\CompatibilityFlags",
  946. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  947. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  948. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\SecuritySafe",
  949. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
  950. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer",
  951. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings",
  952. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{022A481F-991D-11E9-8070-18C086CD4729}",
  953. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{2670000A-7350-4F3C-8081-5663EE0C6C49}\\iexplore\\Type",
  954. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{2670000A-7350-4F3C-8081-5663EE0C6C49}\\iexplore\\Count",
  955. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{2670000A-7350-4F3C-8081-5663EE0C6C49}\\iexplore\\Time",
  956. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\iexplore\\Type",
  957. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\iexplore\\Count",
  958. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\iexplore\\Time",
  959. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\\iexplore\\Type",
  960. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\\iexplore\\Count",
  961. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\\iexplore\\Time",
  962. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FullScreen",
  963. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MenuOrder\\Favorites\\Links\\Order",
  964. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Window_Placement",
  965. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\User Preferences\\88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977",
  966. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\DefaultScope",
  967. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\User Preferences\\2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81",
  968. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\iexplore\\LoadTime",
  969. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\iexplore\\Type",
  970. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\iexplore\\Count",
  971. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\iexplore\\Time",
  972. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\iexplore\\LoadTime",
  973. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\iexplore\\Type",
  974. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\iexplore\\Count",
  975. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\iexplore\\Time",
  976. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\iexplore\\LoadTime",
  977. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{0A27E9C3-991D-11E9-8070-18C086CD4729}",
  978. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{115FA839-991D-11E9-8070-18C086CD4729}",
  979. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{1664BBB7-991D-11E9-8070-18C086CD4729}",
  980. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{1E6BE6C3-991D-11E9-8070-18C086CD4729}",
  981. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{2337C1D1-991D-11E9-8070-18C086CD4729}",
  982. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{2BE5D179-991D-11E9-8070-18C086CD4729}",
  983. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{3054B0D1-991D-11E9-8070-18C086CD4729}",
  984. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{354DD88D-991D-11E9-8070-18C086CD4729}",
  985. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{3CA2333B-991D-11E9-8070-18C086CD4729}",
  986. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{418F6F35-991D-11E9-8070-18C086CD4729}",
  987. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{4ABE3DD9-991D-11E9-8070-18C086CD4729}",
  988. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{502E9B29-991D-11E9-8070-18C086CD4729}",
  989. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{5A876FBF-991D-11E9-8070-18C086CD4729}",
  990. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{60382C8D-991D-11E9-8070-18C086CD4729}",
  991. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{6A497A97-991D-11E9-8070-18C086CD4729}",
  992. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{702EAB21-991D-11E9-8070-18C086CD4729}",
  993. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\Path",
  994. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\Handler",
  995. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\FeedUrl",
  996. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\DisplayName",
  997. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\ErrorState",
  998. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\DisplayMask",
  999. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\Path",
  1000. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\Handler",
  1001. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\FeedUrl",
  1002. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\DisplayName",
  1003. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\ErrorState",
  1004. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\DisplayMask",
  1005. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\Expiration",
  1006. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\Expiration",
  1007. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{7ADFB6B9-991D-11E9-8070-18C086CD4729}",
  1008. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{80EFD197-991D-11E9-8070-18C086CD4729}"
  1009. ]
  1010.  
  1011. [*] Deleted Registry Keys: [
  1012. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  1013. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  1014. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  1015. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  1016. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride",
  1017. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL",
  1018. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{022A481F-991D-11E9-8070-18C086CD4729}",
  1019. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFavoritesInitialSelection",
  1020. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFeedsInitialSelection",
  1021. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{0A27E9C3-991D-11E9-8070-18C086CD4729}",
  1022. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{115FA839-991D-11E9-8070-18C086CD4729}",
  1023. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{1664BBB7-991D-11E9-8070-18C086CD4729}",
  1024. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{1E6BE6C3-991D-11E9-8070-18C086CD4729}",
  1025. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{2337C1D1-991D-11E9-8070-18C086CD4729}",
  1026. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{2BE5D179-991D-11E9-8070-18C086CD4729}",
  1027. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{3054B0D1-991D-11E9-8070-18C086CD4729}",
  1028. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{354DD88D-991D-11E9-8070-18C086CD4729}",
  1029. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{3CA2333B-991D-11E9-8070-18C086CD4729}",
  1030. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{418F6F35-991D-11E9-8070-18C086CD4729}",
  1031. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{4ABE3DD9-991D-11E9-8070-18C086CD4729}",
  1032. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{502E9B29-991D-11E9-8070-18C086CD4729}",
  1033. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{5A876FBF-991D-11E9-8070-18C086CD4729}",
  1034. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{60382C8D-991D-11E9-8070-18C086CD4729}",
  1035. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{6A497A97-991D-11E9-8070-18C086CD4729}",
  1036. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\Expiration",
  1037. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\Expiration",
  1038. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{702EAB21-991D-11E9-8070-18C086CD4729}",
  1039. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{7ADFB6B9-991D-11E9-8070-18C086CD4729}"
  1040. ]
  1041.  
  1042. [*] DNS Communications: [
  1043. {
  1044. "type": "A",
  1045. "request": "www.bing.com",
  1046. "answers": [
  1047. {
  1048. "data": "dual-a-0001.a-msedge.net",
  1049. "type": "CNAME"
  1050. },
  1051. {
  1052. "data": "a-0001.a-afdentry.net.trafficmanager.net",
  1053. "type": "CNAME"
  1054. },
  1055. {
  1056. "data": "204.79.197.200",
  1057. "type": "A"
  1058. },
  1059. {
  1060. "data": "13.107.21.200",
  1061. "type": "A"
  1062. }
  1063. ]
  1064. },
  1065. {
  1066. "type": "A",
  1067. "request": "ch12ozoo.com",
  1068. "answers": [
  1069. {
  1070. "data": "",
  1071. "type": "NXDOMAIN"
  1072. }
  1073. ]
  1074. }
  1075. ]
  1076.  
  1077. [*] Domains: [
  1078. {
  1079. "ip": "13.107.21.200",
  1080. "domain": "www.bing.com"
  1081. },
  1082. {
  1083. "ip": "",
  1084. "domain": "ch12ozoo.com"
  1085. }
  1086. ]
  1087.  
  1088. [*] Network Communication - ICMP: []
  1089.  
  1090. [*] Network Communication - HTTP: [
  1091. {
  1092. "count": 20,
  1093. "body": "",
  1094. "uri": "http://www.bing.com/favicon.ico",
  1095. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  1096. "method": "GET",
  1097. "host": "www.bing.com",
  1098. "version": "1.1",
  1099. "path": "/favicon.ico",
  1100. "data": "GET /favicon.ico HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: www.bing.com\r\nConnection: Keep-Alive\r\nCookie: MUID=055643067C21678412144E247D39664A; SRCHD=AF=NOFORM; SRCHUID=V=2&GUID=5262DC06BBB54635AC9D8A0AD382875E&dmnchg=1; SRCHUSR=DOB=20190317\r\n\r\n",
  1101. "port": 80
  1102. }
  1103. ]
  1104.  
  1105. [*] Network Communication - SMTP: []
  1106.  
  1107. [*] Network Communication - Hosts: []
  1108.  
  1109. [*] Network Communication - IRC: []
  1110.  
  1111. [*] Static Analysis: {
  1112. "pe": {
  1113. "peid_signatures": [
  1114. [
  1115. "Ste@lth PE 1.01 -> BGCorp"
  1116. ]
  1117. ],
  1118. "imports": [
  1119. {
  1120. "imports": [
  1121. {
  1122. "name": "GetClusterFromResource",
  1123. "address": "0x40b038"
  1124. }
  1125. ],
  1126. "dll": "CLUSAPI.dll"
  1127. },
  1128. {
  1129. "imports": [
  1130. {
  1131. "name": "GetCursorPos",
  1132. "address": "0x40b154"
  1133. },
  1134. {
  1135. "name": "GetPriorityClipboardFormat",
  1136. "address": "0x40b158"
  1137. },
  1138. {
  1139. "name": "GetClientRect",
  1140. "address": "0x40b15c"
  1141. },
  1142. {
  1143. "name": "GetTopWindow",
  1144. "address": "0x40b160"
  1145. },
  1146. {
  1147. "name": "GetUserObjectInformationW",
  1148. "address": "0x40b164"
  1149. },
  1150. {
  1151. "name": "GetWindowTextA",
  1152. "address": "0x40b168"
  1153. },
  1154. {
  1155. "name": "DefDlgProcA",
  1156. "address": "0x40b16c"
  1157. },
  1158. {
  1159. "name": "GetUserObjectSecurity",
  1160. "address": "0x40b170"
  1161. },
  1162. {
  1163. "name": "LoadStringA",
  1164. "address": "0x40b174"
  1165. },
  1166. {
  1167. "name": "GetMenuStringA",
  1168. "address": "0x40b178"
  1169. },
  1170. {
  1171. "name": "LockWindowUpdate",
  1172. "address": "0x40b17c"
  1173. },
  1174. {
  1175. "name": "DestroyWindow",
  1176. "address": "0x40b180"
  1177. },
  1178. {
  1179. "name": "GetWindowTextLengthA",
  1180. "address": "0x40b184"
  1181. },
  1182. {
  1183. "name": "GetDlgItemTextW",
  1184. "address": "0x40b188"
  1185. },
  1186. {
  1187. "name": "GetClipboardSequenceNumber",
  1188. "address": "0x40b18c"
  1189. },
  1190. {
  1191. "name": "EnumThreadWindows",
  1192. "address": "0x40b190"
  1193. },
  1194. {
  1195. "name": "DefDlgProcW",
  1196. "address": "0x40b194"
  1197. },
  1198. {
  1199. "name": "LoadAcceleratorsA",
  1200. "address": "0x40b198"
  1201. },
  1202. {
  1203. "name": "GetClassWord",
  1204. "address": "0x40b19c"
  1205. },
  1206. {
  1207. "name": "GetWindowWord",
  1208. "address": "0x40b1a0"
  1209. },
  1210. {
  1211. "name": "GetMenuDefaultItem",
  1212. "address": "0x40b1a4"
  1213. },
  1214. {
  1215. "name": "IsWindow",
  1216. "address": "0x40b1a8"
  1217. },
  1218. {
  1219. "name": "DrawStateA",
  1220. "address": "0x40b1ac"
  1221. },
  1222. {
  1223. "name": "GetWindowModuleFileNameW",
  1224. "address": "0x40b1b0"
  1225. },
  1226. {
  1227. "name": "IsWindowEnabled",
  1228. "address": "0x40b1b4"
  1229. }
  1230. ],
  1231. "dll": "USER32.dll"
  1232. },
  1233. {
  1234. "imports": [
  1235. {
  1236. "name": "vfwprintf",
  1237. "address": "0x40b1e0"
  1238. },
  1239. {
  1240. "name": "fgetws",
  1241. "address": "0x40b1e4"
  1242. },
  1243. {
  1244. "name": "strncmp",
  1245. "address": "0x40b1e8"
  1246. },
  1247. {
  1248. "name": "strftime",
  1249. "address": "0x40b1ec"
  1250. },
  1251. {
  1252. "name": "strtol",
  1253. "address": "0x40b1f0"
  1254. }
  1255. ],
  1256. "dll": "msvcrt.dll"
  1257. },
  1258. {
  1259. "imports": [
  1260. {
  1261. "name": "GetCurrentObject",
  1262. "address": "0x40b048"
  1263. },
  1264. {
  1265. "name": "GetWorldTransform",
  1266. "address": "0x40b04c"
  1267. },
  1268. {
  1269. "name": "GetOutlineTextMetricsW",
  1270. "address": "0x40b050"
  1271. },
  1272. {
  1273. "name": "ExtTextOutW",
  1274. "address": "0x40b054"
  1275. },
  1276. {
  1277. "name": "GdiSetBatchLimit",
  1278. "address": "0x40b058"
  1279. },
  1280. {
  1281. "name": "GetTextExtentExPointW",
  1282. "address": "0x40b05c"
  1283. },
  1284. {
  1285. "name": "GetPixel",
  1286. "address": "0x40b060"
  1287. },
  1288. {
  1289. "name": "GetTextExtentPoint32A",
  1290. "address": "0x40b064"
  1291. },
  1292. {
  1293. "name": "FlattenPath",
  1294. "address": "0x40b068"
  1295. },
  1296. {
  1297. "name": "GetViewportExtEx",
  1298. "address": "0x40b06c"
  1299. }
  1300. ],
  1301. "dll": "GDI32.dll"
  1302. },
  1303. {
  1304. "imports": [
  1305. {
  1306. "name": "GetColorDirectoryW",
  1307. "address": "0x40b1d8"
  1308. }
  1309. ],
  1310. "dll": "mscms.dll"
  1311. },
  1312. {
  1313. "imports": [
  1314. {
  1315. "name": "GetMenuPosFromID",
  1316. "address": "0x40b140"
  1317. }
  1318. ],
  1319. "dll": "SHLWAPI.dll"
  1320. },
  1321. {
  1322. "imports": [
  1323. {
  1324. "name": "FindCloseUrlCache",
  1325. "address": "0x40b1c8"
  1326. }
  1327. ],
  1328. "dll": "WININET.dll"
  1329. },
  1330. {
  1331. "imports": [
  1332. {
  1333. "name": "GetFileTitleA",
  1334. "address": "0x40b040"
  1335. }
  1336. ],
  1337. "dll": "COMDLG32.dll"
  1338. },
  1339. {
  1340. "imports": [
  1341. {
  1342. "name": "GetPrintProcessorDirectoryW",
  1343. "address": "0x40b1d0"
  1344. }
  1345. ],
  1346. "dll": "WINSPOOL.DRV"
  1347. },
  1348. {
  1349. "imports": [
  1350. {
  1351. "name": "EnumerateSecurityPackagesW",
  1352. "address": "0x40b148"
  1353. },
  1354. {
  1355. "name": "GetComputerObjectNameW",
  1356. "address": "0x40b14c"
  1357. }
  1358. ],
  1359. "dll": "Secur32.dll"
  1360. },
  1361. {
  1362. "imports": [
  1363. {
  1364. "name": "GetServiceKeyNameA",
  1365. "address": "0x40b000"
  1366. },
  1367. {
  1368. "name": "GetPrivateObjectSecurity",
  1369. "address": "0x40b004"
  1370. },
  1371. {
  1372. "name": "IsTokenRestricted",
  1373. "address": "0x40b008"
  1374. },
  1375. {
  1376. "name": "DeleteService",
  1377. "address": "0x40b00c"
  1378. },
  1379. {
  1380. "name": "LogonUserA",
  1381. "address": "0x40b010"
  1382. },
  1383. {
  1384. "name": "GetServiceDisplayNameW",
  1385. "address": "0x40b014"
  1386. },
  1387. {
  1388. "name": "LookupAccountSidW",
  1389. "address": "0x40b018"
  1390. },
  1391. {
  1392. "name": "GetSidSubAuthorityCount",
  1393. "address": "0x40b01c"
  1394. },
  1395. {
  1396. "name": "DecryptFileW",
  1397. "address": "0x40b020"
  1398. },
  1399. {
  1400. "name": "GetServiceKeyNameW",
  1401. "address": "0x40b024"
  1402. },
  1403. {
  1404. "name": "EqualSid",
  1405. "address": "0x40b028"
  1406. },
  1407. {
  1408. "name": "GetUserNameA",
  1409. "address": "0x40b02c"
  1410. },
  1411. {
  1412. "name": "IsValidSecurityDescriptor",
  1413. "address": "0x40b030"
  1414. }
  1415. ],
  1416. "dll": "ADVAPI32.dll"
  1417. },
  1418. {
  1419. "imports": [
  1420. {
  1421. "name": "MkParseDisplayName",
  1422. "address": "0x40b1f8"
  1423. }
  1424. ],
  1425. "dll": "ole32.dll"
  1426. },
  1427. {
  1428. "imports": [
  1429. {
  1430. "name": "GetPwrCapabilities",
  1431. "address": "0x40b138"
  1432. }
  1433. ],
  1434. "dll": "POWRPROF.dll"
  1435. },
  1436. {
  1437. "imports": [
  1438. {
  1439. "name": "GetCPInfo",
  1440. "address": "0x40b074"
  1441. },
  1442. {
  1443. "name": "GetFileAttributesA",
  1444. "address": "0x40b078"
  1445. },
  1446. {
  1447. "name": "GetVolumeNameForVolumeMountPointW",
  1448. "address": "0x40b07c"
  1449. },
  1450. {
  1451. "name": "GetUserDefaultUILanguage",
  1452. "address": "0x40b080"
  1453. },
  1454. {
  1455. "name": "LoadLibraryW",
  1456. "address": "0x40b084"
  1457. },
  1458. {
  1459. "name": "GetTapeParameters",
  1460. "address": "0x40b088"
  1461. },
  1462. {
  1463. "name": "FindActCtxSectionStringW",
  1464. "address": "0x40b08c"
  1465. },
  1466. {
  1467. "name": "GetPrivateProfileSectionNamesW",
  1468. "address": "0x40b090"
  1469. },
  1470. {
  1471. "name": "DeactivateActCtx",
  1472. "address": "0x40b094"
  1473. },
  1474. {
  1475. "name": "GetUserDefaultLangID",
  1476. "address": "0x40b098"
  1477. },
  1478. {
  1479. "name": "GetThreadTimes",
  1480. "address": "0x40b09c"
  1481. },
  1482. {
  1483. "name": "DeleteTimerQueue",
  1484. "address": "0x40b0a0"
  1485. },
  1486. {
  1487. "name": "FindResourceExA",
  1488. "address": "0x40b0a4"
  1489. },
  1490. {
  1491. "name": "GetDefaultCommConfigA",
  1492. "address": "0x40b0a8"
  1493. },
  1494. {
  1495. "name": "GetLocalTime",
  1496. "address": "0x40b0ac"
  1497. },
  1498. {
  1499. "name": "GetFileType",
  1500. "address": "0x40b0b0"
  1501. },
  1502. {
  1503. "name": "LoadLibraryExA",
  1504. "address": "0x40b0b4"
  1505. },
  1506. {
  1507. "name": "GetSystemInfo",
  1508. "address": "0x40b0b8"
  1509. },
  1510. {
  1511. "name": "GetLogicalDriveStringsA",
  1512. "address": "0x40b0bc"
  1513. },
  1514. {
  1515. "name": "EnumSystemGeoID",
  1516. "address": "0x40b0c0"
  1517. },
  1518. {
  1519. "name": "GenerateConsoleCtrlEvent",
  1520. "address": "0x40b0c4"
  1521. },
  1522. {
  1523. "name": "EscapeCommFunction",
  1524. "address": "0x40b0c8"
  1525. },
  1526. {
  1527. "name": "lstrcpyW",
  1528. "address": "0x40b0cc"
  1529. },
  1530. {
  1531. "name": "GetLastError",
  1532. "address": "0x40b0d0"
  1533. },
  1534. {
  1535. "name": "GetPrivateProfileStringA",
  1536. "address": "0x40b0d4"
  1537. },
  1538. {
  1539. "name": "FindResourceA",
  1540. "address": "0x40b0d8"
  1541. },
  1542. {
  1543. "name": "GetLongPathNameA",
  1544. "address": "0x40b0dc"
  1545. },
  1546. {
  1547. "name": "EnumResourceTypesA",
  1548. "address": "0x40b0e0"
  1549. },
  1550. {
  1551. "name": "FindAtomA",
  1552. "address": "0x40b0e4"
  1553. },
  1554. {
  1555. "name": "FreeLibrary",
  1556. "address": "0x40b0e8"
  1557. },
  1558. {
  1559. "name": "FindFirstFileA",
  1560. "address": "0x40b0ec"
  1561. },
  1562. {
  1563. "name": "LocalLock",
  1564. "address": "0x40b0f0"
  1565. },
  1566. {
  1567. "name": "FindClose",
  1568. "address": "0x40b0f4"
  1569. },
  1570. {
  1571. "name": "GetCommModemStatus",
  1572. "address": "0x40b0f8"
  1573. },
  1574. {
  1575. "name": "EnumUILanguagesW",
  1576. "address": "0x40b0fc"
  1577. },
  1578. {
  1579. "name": "FreeEnvironmentStringsW",
  1580. "address": "0x40b100"
  1581. },
  1582. {
  1583. "name": "FindFirstVolumeW",
  1584. "address": "0x40b104"
  1585. },
  1586. {
  1587. "name": "GetSystemTimeAsFileTime",
  1588. "address": "0x40b108"
  1589. },
  1590. {
  1591. "name": "LocalHandle",
  1592. "address": "0x40b10c"
  1593. },
  1594. {
  1595. "name": "GetSystemDefaultLangID",
  1596. "address": "0x40b110"
  1597. },
  1598. {
  1599. "name": "GetExitCodeThread",
  1600. "address": "0x40b114"
  1601. },
  1602. {
  1603. "name": "GetACP",
  1604. "address": "0x40b118"
  1605. },
  1606. {
  1607. "name": "FindFirstVolumeMountPointW",
  1608. "address": "0x40b11c"
  1609. },
  1610. {
  1611. "name": "LocalUnlock",
  1612. "address": "0x40b120"
  1613. },
  1614. {
  1615. "name": "GetTickCount",
  1616. "address": "0x40b124"
  1617. },
  1618. {
  1619. "name": "GetShortPathNameA",
  1620. "address": "0x40b128"
  1621. }
  1622. ],
  1623. "dll": "KERNEL32.dll"
  1624. },
  1625. {
  1626. "imports": [
  1627. {
  1628. "name": "LoadRegTypeLib",
  1629. "address": "0x40b130"
  1630. }
  1631. ],
  1632. "dll": "OLEAUT32.dll"
  1633. },
  1634. {
  1635. "imports": [
  1636. {
  1637. "name": "GetFileVersionInfoA",
  1638. "address": "0x40b1bc"
  1639. },
  1640. {
  1641. "name": "GetFileVersionInfoSizeA",
  1642. "address": "0x40b1c0"
  1643. }
  1644. ],
  1645. "dll": "VERSION.dll"
  1646. }
  1647. ],
  1648. "digital_signers": null,
  1649. "exported_dll_name": null,
  1650. "actual_checksum": "0x00034b17",
  1651. "overlay": {
  1652. "size": "0x00001b28",
  1653. "offset": "0x00027000"
  1654. },
  1655. "imagebase": "0x00400000",
  1656. "reported_checksum": "0x00034b17",
  1657. "icon_hash": null,
  1658. "entrypoint": "0x00405e40",
  1659. "timestamp": "2019-06-13 06:15:17",
  1660. "osversion": "5.0",
  1661. "sections": [
  1662. {
  1663. "name": ".text",
  1664. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
  1665. "virtual_address": "0x00001000",
  1666. "size_of_data": "0x0000a000",
  1667. "entropy": "6.24",
  1668. "raw_address": "0x00001000",
  1669. "virtual_size": "0x00009e52",
  1670. "characteristics_raw": "0x60000020"
  1671. },
  1672. {
  1673. "name": ".rdata",
  1674. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  1675. "virtual_address": "0x0000b000",
  1676. "size_of_data": "0x00002000",
  1677. "entropy": "4.10",
  1678. "raw_address": "0x0000b000",
  1679. "virtual_size": "0x00001500",
  1680. "characteristics_raw": "0x40000040"
  1681. },
  1682. {
  1683. "name": ".data",
  1684. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1685. "virtual_address": "0x0000d000",
  1686. "size_of_data": "0x00003000",
  1687. "entropy": "4.27",
  1688. "raw_address": "0x0000d000",
  1689. "virtual_size": "0x00003128",
  1690. "characteristics_raw": "0xc0000040"
  1691. },
  1692. {
  1693. "name": ".reloc",
  1694. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1695. "virtual_address": "0x00011000",
  1696. "size_of_data": "0x00015000",
  1697. "entropy": "7.88",
  1698. "raw_address": "0x00010000",
  1699. "virtual_size": "0x000141af",
  1700. "characteristics_raw": "0xc0000040"
  1701. },
  1702. {
  1703. "name": ".rsrc",
  1704. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  1705. "virtual_address": "0x00026000",
  1706. "size_of_data": "0x00002000",
  1707. "entropy": "2.95",
  1708. "raw_address": "0x00025000",
  1709. "virtual_size": "0x00001b70",
  1710. "characteristics_raw": "0x40000040"
  1711. }
  1712. ],
  1713. "resources": [],
  1714. "dirents": [
  1715. {
  1716. "virtual_address": "0x00000000",
  1717. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  1718. "size": "0x00000000"
  1719. },
  1720. {
  1721. "virtual_address": "0x0000b84c",
  1722. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  1723. "size": "0x00000154"
  1724. },
  1725. {
  1726. "virtual_address": "0x00026000",
  1727. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  1728. "size": "0x00001b70"
  1729. },
  1730. {
  1731. "virtual_address": "0x00000000",
  1732. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  1733. "size": "0x00000000"
  1734. },
  1735. {
  1736. "virtual_address": "0x00027000",
  1737. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  1738. "size": "0x00001b28"
  1739. },
  1740. {
  1741. "virtual_address": "0x00000000",
  1742. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  1743. "size": "0x00000000"
  1744. },
  1745. {
  1746. "virtual_address": "0x00000000",
  1747. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  1748. "size": "0x00000000"
  1749. },
  1750. {
  1751. "virtual_address": "0x00000000",
  1752. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  1753. "size": "0x00000000"
  1754. },
  1755. {
  1756. "virtual_address": "0x00000000",
  1757. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  1758. "size": "0x00000000"
  1759. },
  1760. {
  1761. "virtual_address": "0x00000000",
  1762. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  1763. "size": "0x00000000"
  1764. },
  1765. {
  1766. "virtual_address": "0x00000000",
  1767. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  1768. "size": "0x00000000"
  1769. },
  1770. {
  1771. "virtual_address": "0x00000000",
  1772. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  1773. "size": "0x00000000"
  1774. },
  1775. {
  1776. "virtual_address": "0x0000b000",
  1777. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  1778. "size": "0x00000200"
  1779. },
  1780. {
  1781. "virtual_address": "0x00000000",
  1782. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  1783. "size": "0x00000000"
  1784. },
  1785. {
  1786. "virtual_address": "0x00000000",
  1787. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  1788. "size": "0x00000000"
  1789. },
  1790. {
  1791. "virtual_address": "0x00000000",
  1792. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  1793. "size": "0x00000000"
  1794. }
  1795. ],
  1796. "exports": [],
  1797. "guest_signers": {},
  1798. "imphash": "82b133201a2a706828cfe4416a0ef7e7",
  1799. "icon_fuzzy": null,
  1800. "icon": null,
  1801. "pdbpath": null,
  1802. "imported_dll_count": 16,
  1803. "versioninfo": []
  1804. }
  1805. }
  1806.  
  1807. [*] Resolved APIs: [
  1808. "kernel32.dll.VirtualAlloc",
  1809. "kernel32.dll.LoadLibraryA",
  1810. "kernel32.dll.GetProcAddress",
  1811. "kernel32.dll.VirtualProtect",
  1812. "kernel32.dll.UnmapViewOfFile",
  1813. "kernel32.dll.AddVectoredExceptionHandler",
  1814. "kernel32.dll.RemoveVectoredExceptionHandler",
  1815. "kernel32.dll.FreeConsole",
  1816. "kernel32.dll.ExitProcess",
  1817. "kernel32.dll.GetLastError",
  1818. "kernel32.dll.HeapDestroy",
  1819. "kernel32.dll.HeapCreate",
  1820. "kernel32.dll.GetModuleHandleA",
  1821. "kernel32.dll.GetTickCount",
  1822. "kernel32.dll.VirtualFree",
  1823. "kernel32.dll.lstrlenW",
  1824. "kernel32.dll.lstrlenA",
  1825. "kernel32.dll.HeapAlloc",
  1826. "kernel32.dll.HeapFree",
  1827. "kernel32.dll.WaitForSingleObject",
  1828. "kernel32.dll.CloseHandle",
  1829. "kernel32.dll.CreateEventA",
  1830. "ntdll.dll.memcpy",
  1831. "ntdll.dll.memset",
  1832. "ntdll.dll.RtlUnwind",
  1833. "ntdll.dll.NtQueryVirtualMemory",
  1834. "ntdll.dll.sprintf",
  1835. "ntdll.dll._snprintf",
  1836. "ntdll.dll.strchr",
  1837. "ntdll.dll.strcpy",
  1838. "ntdll.dll.NtCreateKey",
  1839. "ntdll.dll.NtDeleteValueKey",
  1840. "ntdll.dll.RtlInitUnicodeString",
  1841. "ntdll.dll.NtSetValueKey",
  1842. "ntdll.dll.memmove",
  1843. "ntdll.dll.RtlAddVectoredExceptionHandler",
  1844. "ntdll.dll.RtlRemoveVectoredExceptionHandler",
  1845. "ntdll.dll.wcstombs",
  1846. "ntdll.dll.NtQueryInformationToken",
  1847. "ntdll.dll._allmul",
  1848. "ntdll.dll._aulldiv",
  1849. "ntdll.dll.NtOpenProcessToken",
  1850. "ntdll.dll.NtClose",
  1851. "ntdll.dll._wcsupr",
  1852. "ntdll.dll._snwprintf",
  1853. "ntdll.dll.RtlNtStatusToDosError",
  1854. "ntdll.dll.wcsrchr",
  1855. "ntdll.dll.NtQueryInformationProcess",
  1856. "ntdll.dll.mbstowcs",
  1857. "ntdll.dll.RtlImageNtHeader",
  1858. "ntdll.dll.wcschr",
  1859. "shlwapi.dll.StrChrW",
  1860. "shlwapi.dll.StrStrA",
  1861. "shlwapi.dll.StrStrIW",
  1862. "shlwapi.dll.StrChrA",
  1863. "shlwapi.dll.StrStrIA",
  1864. "shlwapi.dll.StrTrimA",
  1865. "shlwapi.dll.#176",
  1866. "shlwapi.dll.PathCombineW",
  1867. "shlwapi.dll.StrToIntExA",
  1868. "kernel32.dll.CreateWaitableTimerW",
  1869. "kernel32.dll.Sleep",
  1870. "kernel32.dll.CreateWaitableTimerA",
  1871. "kernel32.dll.SwitchToThread",
  1872. "kernel32.dll.TlsSetValue",
  1873. "kernel32.dll.TlsFree",
  1874. "kernel32.dll.WaitForMultipleObjects",
  1875. "kernel32.dll.SetWaitableTimer",
  1876. "kernel32.dll.GetSystemTimeAsFileTime",
  1877. "kernel32.dll.CreateEventW",
  1878. "kernel32.dll.CreateMutexW",
  1879. "kernel32.dll.TlsAlloc",
  1880. "kernel32.dll.LeaveCriticalSection",
  1881. "kernel32.dll.EnterCriticalSection",
  1882. "kernel32.dll.OpenProcess",
  1883. "kernel32.dll.TlsGetValue",
  1884. "kernel32.dll.DeleteCriticalSection",
  1885. "kernel32.dll.InitializeCriticalSection",
  1886. "kernel32.dll.lstrcatW",
  1887. "kernel32.dll.lstrcpyA",
  1888. "kernel32.dll.ExpandEnvironmentStringsW",
  1889. "kernel32.dll.InterlockedIncrement",
  1890. "kernel32.dll.QueryPerformanceFrequency",
  1891. "kernel32.dll.QueryPerformanceCounter",
  1892. "kernel32.dll.GetComputerNameW",
  1893. "kernel32.dll.InterlockedDecrement",
  1894. "kernel32.dll.lstrcmpW",
  1895. "kernel32.dll.ProcessIdToSessionId",
  1896. "kernel32.dll.GetCurrentProcessId",
  1897. "kernel32.dll.SetEvent",
  1898. "kernel32.dll.ResetEvent",
  1899. "kernel32.dll.GetModuleFileNameW",
  1900. "kernel32.dll.MultiByteToWideChar",
  1901. "kernel32.dll.lstrcpyW",
  1902. "kernel32.dll.lstrcatA",
  1903. "user32.dll.wsprintfW",
  1904. "user32.dll.wsprintfA",
  1905. "advapi32.dll.OpenProcessToken",
  1906. "advapi32.dll.RegEnumKeyExW",
  1907. "advapi32.dll.GetUserNameW",
  1908. "advapi32.dll.GetSidSubAuthorityCount",
  1909. "advapi32.dll.RegCloseKey",
  1910. "advapi32.dll.GetTokenInformation",
  1911. "advapi32.dll.GetSidSubAuthority",
  1912. "advapi32.dll.RegSetValueExW",
  1913. "advapi32.dll.RegCreateKeyW",
  1914. "shell32.dll.ShellExecuteW",
  1915. "ws2_32.dll.#12",
  1916. "ws2_32.dll.#11",
  1917. "winhttp.dll.WinHttpOpenRequest",
  1918. "winhttp.dll.WinHttpSetOption",
  1919. "winhttp.dll.WinHttpSendRequest",
  1920. "winhttp.dll.WinHttpWriteData",
  1921. "winhttp.dll.WinHttpReadData",
  1922. "winhttp.dll.WinHttpConnect",
  1923. "winhttp.dll.WinHttpQueryOption",
  1924. "winhttp.dll.WinHttpReceiveResponse",
  1925. "winhttp.dll.WinHttpOpen",
  1926. "winhttp.dll.WinHttpQueryDataAvailable",
  1927. "winhttp.dll.WinHttpSetTimeouts",
  1928. "winhttp.dll.WinHttpQueryHeaders",
  1929. "winhttp.dll.WinHttpCloseHandle",
  1930. "dnsapi.dll.DnsQuery_A",
  1931. "dnsapi.dll.DnsFree",
  1932. "ole32.dll.CoInitializeEx",
  1933. "ole32.dll.CoUninitialize",
  1934. "ole32.dll.CoSetProxyBlanket",
  1935. "ole32.dll.CoCreateInstance",
  1936. "ole32.dll.CreateStreamOnHGlobal",
  1937. "oleaut32.dll.#6",
  1938. "oleaut32.dll.#2",
  1939. "oleaut32.dll.#15",
  1940. "oleaut32.dll.#16",
  1941. "cryptbase.dll.SystemFunction036",
  1942. "uxtheme.dll.ThemeInitApiHook",
  1943. "user32.dll.IsProcessDPIAware",
  1944. "kernel32.dll.GetThreadPreferredUILanguages",
  1945. "kernel32.dll.SetThreadPreferredUILanguages",
  1946. "kernel32.dll.LocaleNameToLCID",
  1947. "kernel32.dll.GetLocaleInfoEx",
  1948. "kernel32.dll.LCIDToLocaleName",
  1949. "kernel32.dll.GetSystemDefaultLocaleName",
  1950. "oleaut32.dll.#283",
  1951. "oleaut32.dll.#284",
  1952. "kernel32.dll.RegOpenKeyExW",
  1953. "oleaut32.dll.BSTR_UserSize",
  1954. "oleaut32.dll.BSTR_UserMarshal",
  1955. "oleaut32.dll.BSTR_UserUnmarshal",
  1956. "oleaut32.dll.BSTR_UserFree",
  1957. "oleaut32.dll.VARIANT_UserSize",
  1958. "oleaut32.dll.VARIANT_UserMarshal",
  1959. "oleaut32.dll.VARIANT_UserUnmarshal",
  1960. "oleaut32.dll.VARIANT_UserFree",
  1961. "oleaut32.dll.LPSAFEARRAY_UserSize",
  1962. "oleaut32.dll.LPSAFEARRAY_UserMarshal",
  1963. "oleaut32.dll.LPSAFEARRAY_UserUnmarshal",
  1964. "oleaut32.dll.LPSAFEARRAY_UserFree",
  1965. "ws2_32.dll.GetAddrInfoW",
  1966. "rpcrt4.dll.RpcBindingFree",
  1967. "ws2_32.dll.#116",
  1968. "kernel32.dll.SortGetHandle",
  1969. "kernel32.dll.SortCloseHandle",
  1970. "ntmarta.dll.GetMartaExtensionInterface",
  1971. "sechost.dll.LookupAccountNameLocalW",
  1972. "advapi32.dll.LookupAccountSidW",
  1973. "sechost.dll.LookupAccountSidLocalW",
  1974. "kernel32.dll.RegQueryValueExW",
  1975. "kernel32.dll.RegCloseKey",
  1976. "oleaut32.dll.#285",
  1977. "advapi32.dll.RegOpenKeyW",
  1978. "sechost.dll.ConvertSidToStringSidW",
  1979. "kernel32.dll.RegSetValueExW",
  1980. "oleaut32.dll.#286",
  1981. "ntdll.dll.EtwUnregisterTraceGuids",
  1982. "oleaut32.dll.#500",
  1983. "cryptsp.dll.CryptReleaseContext",
  1984. "advapi32.dll.EventWrite",
  1985. "advapi32.dll.EventRegister",
  1986. "advapi32.dll.EventUnregister",
  1987. "kernel32.dll.InitializeSRWLock",
  1988. "kernel32.dll.AcquireSRWLockExclusive",
  1989. "kernel32.dll.AcquireSRWLockShared",
  1990. "kernel32.dll.ReleaseSRWLockExclusive",
  1991. "kernel32.dll.ReleaseSRWLockShared",
  1992. "kernel32.dll.SetProcessDEPPolicy",
  1993. "user32.dll.SetProcessDPIAware",
  1994. "shell32.dll.SetCurrentProcessExplicitAppUserModelID",
  1995. "user32.dll.GetShellWindow",
  1996. "user32.dll.GetWindowThreadProcessId",
  1997. "ieframe.dll.#250",
  1998. "wininet.dll.InternetQueryOptionW",
  1999. "advapi32.dll.EventActivityIdControl",
  2000. "advapi32.dll.EventWriteTransfer",
  2001. "kernel32.dll.SetFileInformationByHandle",
  2002. "shell32.dll.SHGetFolderPathW",
  2003. "kernel32.dll.GetModuleHandleW",
  2004. "advapi32.dll.AddMandatoryAce",
  2005. "ws2_32.dll.accept",
  2006. "ws2_32.dll.bind",
  2007. "ws2_32.dll.closesocket",
  2008. "ws2_32.dll.connect",
  2009. "ws2_32.dll.getpeername",
  2010. "ws2_32.dll.getsockname",
  2011. "ws2_32.dll.getsockopt",
  2012. "ws2_32.dll.ntohl",
  2013. "ws2_32.dll.htonl",
  2014. "ws2_32.dll.htons",
  2015. "ws2_32.dll.inet_addr",
  2016. "ws2_32.dll.inet_ntoa",
  2017. "ws2_32.dll.ioctlsocket",
  2018. "ws2_32.dll.listen",
  2019. "ws2_32.dll.ntohs",
  2020. "ws2_32.dll.recv",
  2021. "ws2_32.dll.recvfrom",
  2022. "ws2_32.dll.select",
  2023. "ws2_32.dll.send",
  2024. "ws2_32.dll.sendto",
  2025. "ws2_32.dll.setsockopt",
  2026. "ws2_32.dll.shutdown",
  2027. "ws2_32.dll.socket",
  2028. "ws2_32.dll.gethostbyname",
  2029. "ws2_32.dll.gethostname",
  2030. "ws2_32.dll.WSAIoctl",
  2031. "ws2_32.dll.WSAGetLastError",
  2032. "ws2_32.dll.WSASetLastError",
  2033. "ws2_32.dll.WSAStartup",
  2034. "ws2_32.dll.WSACleanup",
  2035. "ws2_32.dll.__WSAFDIsSet",
  2036. "ws2_32.dll.getaddrinfo",
  2037. "ws2_32.dll.freeaddrinfo",
  2038. "ws2_32.dll.getnameinfo",
  2039. "ws2_32.dll.WSALookupServiceBeginW",
  2040. "ws2_32.dll.WSALookupServiceNextW",
  2041. "ws2_32.dll.WSALookupServiceEnd",
  2042. "ws2_32.dll.WSANSPIoctl",
  2043. "ws2_32.dll.WSAStringToAddressA",
  2044. "ws2_32.dll.WSAStringToAddressW",
  2045. "ws2_32.dll.WSAAddressToStringA",
  2046. "dnsapi.dll.DnsGetProxyInformation",
  2047. "dnsapi.dll.DnsFreeProxyName",
  2048. "iphlpapi.dll.GetIpForwardTable2",
  2049. "iphlpapi.dll.FreeMibTable",
  2050. "iphlpapi.dll.GetIfEntry2",
  2051. "iphlpapi.dll.ConvertInterfaceGuidToLuid",
  2052. "iphlpapi.dll.ResolveIpNetEntry2",
  2053. "iphlpapi.dll.GetIpNetEntry2",
  2054. "shlwapi.dll.#260",
  2055. "ws2_32.dll.#115",
  2056. "urlmon.dll.CreateUri",
  2057. "version.dll.GetFileVersionInfoSizeW",
  2058. "version.dll.GetFileVersionInfoW",
  2059. "version.dll.VerQueryValueW",
  2060. "comctl32.dll.PropertySheetW",
  2061. "comctl32.dll.PropertySheetA",
  2062. "comdlg32.dll.PageSetupDlgW",
  2063. "comdlg32.dll.PrintDlgW",
  2064. "urlmon.dll.#101",
  2065. "urlmon.dll.#400",
  2066. "advapi32.dll.TraceMessage",
  2067. "advapi32.dll.TraceMessageVa",
  2068. "kernel32.dll.IsWow64Process",
  2069. "sqmapi.dll.SqmGetSession",
  2070. "sqmapi.dll.SqmEndSession",
  2071. "sqmapi.dll.SqmStartSession",
  2072. "sqmapi.dll.SqmStartUpload",
  2073. "sqmapi.dll.SqmWaitForUploadComplete",
  2074. "sqmapi.dll.SqmSet",
  2075. "sqmapi.dll.SqmSetBool",
  2076. "sqmapi.dll.SqmSetBits",
  2077. "sqmapi.dll.SqmSetString",
  2078. "sqmapi.dll.SqmIncrement",
  2079. "sqmapi.dll.SqmSetIfMax",
  2080. "sqmapi.dll.SqmSetIfMin",
  2081. "sqmapi.dll.SqmAddToAverage",
  2082. "sqmapi.dll.SqmAddToStreamDWord",
  2083. "sqmapi.dll.SqmAddToStreamString",
  2084. "sqmapi.dll.SqmSetAppId",
  2085. "sqmapi.dll.SqmSetAppVersion",
  2086. "sqmapi.dll.SqmSetMachineId",
  2087. "sqmapi.dll.SqmSetUserId",
  2088. "sqmapi.dll.SqmCreateNewId",
  2089. "sqmapi.dll.SqmReadSharedMachineId",
  2090. "sqmapi.dll.SqmReadSharedUserId",
  2091. "sqmapi.dll.SqmWriteSharedMachineId",
  2092. "sqmapi.dll.SqmWriteSharedUserId",
  2093. "sqmapi.dll.SqmIsWindowsOptedIn",
  2094. "urlmon.dll.#442",
  2095. "kernel32.dll.WerRegisterMemoryBlock",
  2096. "kernel32.dll.WerUnregisterMemoryBlock",
  2097. "user32.dll.RegisterWindowMessageW",
  2098. "rpcrt4.dll.UuidCreateSequential",
  2099. "rpcrt4.dll.RpcServerUseProtseqW",
  2100. "rpcrt4.dll.RpcServerRegisterIfEx",
  2101. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  2102. "rpcrt4.dll.RpcServerInqBindings",
  2103. "rpcrt4.dll.RpcEpRegisterW",
  2104. "rpcrt4.dll.RpcServerListen",
  2105. "ntdll.dll.NtQuerySystemInformation",
  2106. "user32.dll.RegisterClassExW",
  2107. "user32.dll.CreateWindowExW",
  2108. "user32.dll.DefWindowProcW",
  2109. "user32.dll.SetWindowLongW",
  2110. "dwmapi.dll.DwmIsCompositionEnabled",
  2111. "urlmon.dll.#416",
  2112. "kernel32.dll.RegisterApplicationRestart",
  2113. "shell32.dll.#165",
  2114. "urlmon.dll.CoInternetCreateZoneManager",
  2115. "ws2_32.dll.FreeAddrInfoW",
  2116. "user32.dll.AllowSetForegroundWindow",
  2117. "wininet.dll.InternetInitializeAutoProxyDll",
  2118. "rasapi32.dll.RasConnectionNotificationW",
  2119. "rasapi32.dll.RasEnumEntriesW",
  2120. "rtutils.dll.TracePrintfExA",
  2121. "profapi.dll.#104",
  2122. "shlwapi.dll.PathCanonicalizeW",
  2123. "shlwapi.dll.PathRemoveFileSpecW",
  2124. "shlwapi.dll.PathFindFileNameW",
  2125. "sensapi.dll.IsNetworkAlive",
  2126. "rpcrt4.dll.RpcBindingFromStringBindingW",
  2127. "rpcrt4.dll.RpcBindingSetAuthInfoExW",
  2128. "rpcrt4.dll.NdrClientCall2",
  2129. "sechost.dll.NotifyServiceStatusChangeA",
  2130. "nlaapi.dll.NSPStartup",
  2131. "iphlpapi.dll.GetAdapterIndex",
  2132. "user32.dll.PostThreadMessageW",
  2133. "comctl32.dll.LoadIconWithScaleDown",
  2134. "ieui.dll.InitGadgets",
  2135. "cryptsp.dll.CryptAcquireContextW",
  2136. "cryptsp.dll.CryptGenRandom",
  2137. "ieproxy.dll.DllGetClassObject",
  2138. "ieproxy.dll.DllCanUnloadNow",
  2139. "ole32.dll.CoGetClassObject",
  2140. "ole32.dll.CoGetMarshalSizeMax",
  2141. "ole32.dll.CoMarshalInterface",
  2142. "ole32.dll.CoUnmarshalInterface",
  2143. "ole32.dll.StringFromIID",
  2144. "ole32.dll.CoGetPSClsid",
  2145. "ole32.dll.CoTaskMemAlloc",
  2146. "ole32.dll.CoTaskMemFree",
  2147. "ole32.dll.CoReleaseMarshalData",
  2148. "ole32.dll.DcomChannelSetHResult",
  2149. "gdi32.dll.GetLayout",
  2150. "gdi32.dll.GdiRealizationInfo",
  2151. "gdi32.dll.FontIsLinked",
  2152. "advapi32.dll.RegOpenKeyExW",
  2153. "advapi32.dll.RegQueryInfoKeyW",
  2154. "gdi32.dll.GetTextFaceAliasW",
  2155. "advapi32.dll.RegEnumValueW",
  2156. "advapi32.dll.RegQueryValueExW",
  2157. "gdi32.dll.GetFontAssocStatus",
  2158. "advapi32.dll.RegQueryValueExA",
  2159. "gdi32.dll.GdiIsMetaPrintDC",
  2160. "user32.dll.MsgWaitForMultipleObjectsEx",
  2161. "uxtheme.dll.OpenThemeData",
  2162. "uxtheme.dll.GetThemeMargins",
  2163. "uxtheme.dll.GetThemePartSize",
  2164. "uxtheme.dll.GetThemeTextMetrics",
  2165. "uxtheme.dll.GetThemeBool",
  2166. "comctl32.dll.#410",
  2167. "comctl32.dll.#413",
  2168. "uxtheme.dll.IsAppThemed",
  2169. "uxtheme.dll.GetThemeBackgroundExtent",
  2170. "comctl32.dll.ImageList_LoadImageW",
  2171. "comctl32.dll.ImageList_GetIconSize",
  2172. "uxtheme.dll.GetThemeFont",
  2173. "uxtheme.dll.IsCompositionActive",
  2174. "uxtheme.dll.SetWindowTheme",
  2175. "comctl32.dll.ImageList_Create",
  2176. "comctl32.dll.ImageList_ReplaceIcon",
  2177. "oleaut32.dll.#10",
  2178. "comctl32.dll.ImageList_AddMasked",
  2179. "uxtheme.dll.IsThemePartDefined",
  2180. "uxtheme.dll.GetThemeColor",
  2181. "imm32.dll.ImmIsIME",
  2182. "urlmon.dll.CoInternetCreateSecurityManager",
  2183. "msctf.dll.SetInputScopes2",
  2184. "uxtheme.dll.CloseThemeData",
  2185. "uxtheme.dll.GetThemeBackgroundContentRect",
  2186. "uxtheme.dll.GetThemeTextExtent",
  2187. "uxtheme.dll.EnableThemeDialogTexture",
  2188. "urlmon.dll.#408",
  2189. "uxtheme.dll.IsThemeActive",
  2190. "ieui.dll.CreateGadget",
  2191. "ieui.dll.SetGadgetMessageFilter",
  2192. "ieui.dll.SetGadgetStyle",
  2193. "ole32.dll.CreateBindCtx",
  2194. "ieui.dll.SetGadgetRootInfo",
  2195. "ole32.dll.CoGetApartmentType",
  2196. "ole32.dll.CoRegisterInitializeSpy",
  2197. "uxtheme.dll.GetThemeAppProperties",
  2198. "xmllite.dll.CreateXmlReader",
  2199. "xmllite.dll.CreateXmlReaderInputWithEncodingName",
  2200. "comctl32.dll.#236",
  2201. "ole32.dll.CoGetMalloc",
  2202. "comctl32.dll.#320",
  2203. "comctl32.dll.#324",
  2204. "comctl32.dll.#323",
  2205. "comctl32.dll.#328",
  2206. "comctl32.dll.#334",
  2207. "advapi32.dll.RegEnumKeyW",
  2208. "ieui.dll.FindStdColor",
  2209. "ieui.dll.InvalidateGadget",
  2210. "ieui.dll.SetGadgetParent",
  2211. "ieui.dll.GetGadgetTicket",
  2212. "ieui.dll.SetGadgetRect",
  2213. "urlmon.dll.#103",
  2214. "urlmon.dll.#105",
  2215. "kernel32.dll.GetThreadUILanguage",
  2216. "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
  2217. "setupapi.dll.CM_Get_Device_Interface_List_ExW",
  2218. "advapi32.dll.InitializeSecurityDescriptor",
  2219. "advapi32.dll.SetEntriesInAclW",
  2220. "advapi32.dll.SetSecurityDescriptorDacl",
  2221. "advapi32.dll.IsTextUnicode",
  2222. "comctl32.dll.#332",
  2223. "comctl32.dll.#338",
  2224. "comctl32.dll.#339",
  2225. "shell32.dll.#102",
  2226. "propsys.dll.PSCreateMemoryPropertyStore",
  2227. "propsys.dll.PSPropertyBag_WriteStr",
  2228. "ole32.dll.PropVariantClear",
  2229. "oleaut32.dll.#9",
  2230. "propsys.dll.PSPropertyBag_WriteGUID",
  2231. "propsys.dll.PSPropertyBag_ReadGUID",
  2232. "comctl32.dll.#386",
  2233. "shell32.dll.SHGetInstanceExplorer",
  2234. "wininet.dll.InternetSetOptionW",
  2235. "comctl32.dll.ImageList_Read",
  2236. "comctl32.dll.ImageList_GetImageCount",
  2237. "ole32.dll.CoRevokeInitializeSpy",
  2238. "comctl32.dll.#388",
  2239. "rpcrt4.dll.RpcBindingToStringBindingW",
  2240. "rpcrt4.dll.RpcStringBindingParseW",
  2241. "rpcrt4.dll.RpcStringFreeW",
  2242. "rpcrt4.dll.I_RpcBindingInqLocalClientPID",
  2243. "rpcrt4.dll.RpcServerInqCallAttributesW",
  2244. "rpcrt4.dll.RpcImpersonateClient",
  2245. "rpcrt4.dll.RpcRevertToSelf",
  2246. "rpcrt4.dll.NdrServerCall2",
  2247. "rpcrt4.dll.RpcBindingInqObject",
  2248. "rpcrt4.dll.RpcStringBindingComposeW",
  2249. "user32.dll.PostMessageW",
  2250. "oleaut32.dll.DllGetClassObject",
  2251. "oleaut32.dll.DllCanUnloadNow",
  2252. "sxs.dll.SxsOleAut32MapIIDToProxyStubCLSID",
  2253. "advapi32.dll.RegQueryValueW",
  2254. "sxs.dll.SxsOleAut32MapIIDToTLBPath",
  2255. "sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid",
  2256. "sxs.dll.SxsOleAut32RedirectTypeLibrary",
  2257. "ieui.dll.PeekMessageExW",
  2258. "ole32.dll.CoInitialize",
  2259. "ole32.dll.RegisterDragDrop",
  2260. "msfeeds.dll.MsfeedsCreateInstance",
  2261. "shell32.dll.SHGetSpecialFolderPathW",
  2262. "shell32.dll.#66",
  2263. "shell32.dll.SHCreateDirectoryExW",
  2264. "wininet.dll.FindFirstUrlCacheContainerW",
  2265. "wininet.dll.FindNextUrlCacheContainerW",
  2266. "wininet.dll.FindCloseUrlCache",
  2267. "user32.dll.GetWindowLongW",
  2268. "user32.dll.IsWindow",
  2269. "user32.dll.SendMessageW",
  2270. "user32.dll.PeekMessageW",
  2271. "propsys.dll.PSStringFromPropertyKey",
  2272. "propsys.dll.PSGetPropertyDescription",
  2273. "propsys.dll.PropVariantToString",
  2274. "propsys.dll.InitPropVariantFromStringAsVector",
  2275. "propsys.dll.PSCoerceToCanonicalValue",
  2276. "shell32.dll.SHGetKnownFolderPath",
  2277. "urlmon.dll.#458",
  2278. "urlmon.dll.URLDownloadToFileW",
  2279. "ieui.dll.WaitMessageEx",
  2280. "urlmon.dll.CoInternetIsFeatureEnabledForUrl",
  2281. "oleaut32.dll.#23",
  2282. "oleaut32.dll.#22",
  2283. "urlmon.dll.#441",
  2284. "urlmon.dll.#395",
  2285. "urlmon.dll.#351",
  2286. "mlang.dll.#112",
  2287. "wininet.dll.GetUrlCacheEntryInfoA",
  2288. "wininet.dll.GetUrlCacheEntryInfoExW",
  2289. "wininet.dll.GetUrlCacheEntryInfoExA",
  2290. "uxtheme.dll.BufferedPaintInit",
  2291. "uxtheme.dll.BeginBufferedPaint",
  2292. "uxtheme.dll.DrawThemeParentBackgroundEx",
  2293. "uxtheme.dll.DrawThemeParentBackground",
  2294. "uxtheme.dll.IsThemeBackgroundPartiallyTransparent",
  2295. "uxtheme.dll.DrawThemeBackground",
  2296. "uxtheme.dll.EndBufferedPaint",
  2297. "usp10.dll.ScriptIsComplex",
  2298. "urlmon.dll.#420",
  2299. "user32.dll.TranslateMessage",
  2300. "user32.dll.DispatchMessageW",
  2301. "ieui.dll.DUserPostEvent",
  2302. "ieui.dll.DeleteHandle",
  2303. "comctl32.dll.#412",
  2304. "uxtheme.dll.BufferedPaintUnInit",
  2305. "ieui.dll.DUserFlushMessages",
  2306. "ieui.dll.DUserFlushDeferredMessages",
  2307. "comctl32.dll.ImageList_Destroy",
  2308. "ole32.dll.RevokeDragDrop",
  2309. "ieui.dll.DisableContainerHwnd",
  2310. "ole32.dll.CoWaitForMultipleHandles",
  2311. "comctl32.dll.#326",
  2312. "urlmon.dll.#412",
  2313. "urlmon.dll.#414",
  2314. "ntdll.dll.RtlDllShutdownInProgress",
  2315. "comctl32.dll.#329",
  2316. "linkinfo.dll.IsValidLinkInfo",
  2317. "propsys.dll.#417",
  2318. "propsys.dll.PSGetNameFromPropertyKey",
  2319. "propsys.dll.InitVariantFromBuffer",
  2320. "propsys.dll.PropVariantToGUID",
  2321. "apphelp.dll.ApphelpCheckShellObject",
  2322. "advapi32.dll.OpenThreadToken",
  2323. "propsys.dll.PSGetPropertyDescriptionByName",
  2324. "urlmon.dll.#325",
  2325. "sechost.dll.ConvertStringSidToSidW",
  2326. "samcli.dll.NetUserGetLocalGroups",
  2327. "samlib.dll.SamConnect",
  2328. "samlib.dll.SamEnumerateDomainsInSamServer",
  2329. "samlib.dll.SamLookupDomainInSamServer",
  2330. "samlib.dll.SamFreeMemory",
  2331. "samlib.dll.SamOpenDomain",
  2332. "advapi32.dll.LsaOpenPolicy",
  2333. "advapi32.dll.LsaLookupNames2",
  2334. "advapi32.dll.LsaClose",
  2335. "advapi32.dll.LsaFreeMemory",
  2336. "samlib.dll.SamGetAliasMembership",
  2337. "samlib.dll.SamLookupIdsInDomain",
  2338. "samlib.dll.SamCloseHandle",
  2339. "netutils.dll.NetApiBufferFree",
  2340. "linkinfo.dll.CreateLinkInfoW",
  2341. "user32.dll.IsCharAlphaW",
  2342. "user32.dll.CharPrevW",
  2343. "ntshrui.dll.GetNetResourceFromLocalPathW",
  2344. "srvcli.dll.NetShareEnum",
  2345. "cscapi.dll.CscNetApiGetInterface",
  2346. "slc.dll.SLGetWindowsInformationDWORD",
  2347. "linkinfo.dll.DestroyLinkInfo",
  2348. "propsys.dll.PropVariantToBoolean",
  2349. "urlmon.dll.#364",
  2350. "shell32.dll.SHCreateShellItemArrayFromIDLists",
  2351. "ole32.dll.CoTaskMemRealloc",
  2352. "shell32.dll.SHAssocEnumHandlersForProtocolByApplication",
  2353. "urlmon.dll.#397",
  2354. "urlmon.dll.#398",
  2355. "propsys.dll.PSPropertyBag_ReadBOOL",
  2356. "advapi32.dll.GetSecurityInfo",
  2357. "advapi32.dll.SetSecurityInfo",
  2358. "advapi32.dll.GetSecurityDescriptorControl",
  2359. "user32.dll.CharLowerW",
  2360. "cryptsp.dll.CryptCreateHash",
  2361. "cryptsp.dll.CryptHashData",
  2362. "cryptsp.dll.CryptGetHashParam",
  2363. "cryptsp.dll.CryptDestroyHash",
  2364. "crypt32.dll.CryptUnprotectData",
  2365. "crypt32.dll.CryptProtectData",
  2366. "cryptbase.dll.SystemFunction040",
  2367. "cryptbase.dll.SystemFunction041",
  2368. "comctl32.dll.#321",
  2369. "user32.dll.DestroyWindow",
  2370. "user32.dll.PostQuitMessage",
  2371. "urlmon.dll.#456",
  2372. "urlmon.dll.#451",
  2373. "user32.dll.UnregisterClassW",
  2374. "rpcrt4.dll.RpcEpUnregister",
  2375. "rpcrt4.dll.RpcBindingVectorFree",
  2376. "rpcrt4.dll.RpcServerUnregisterIf",
  2377. "urlmon.dll.#401",
  2378. "advapi32.dll.UnregisterTraceGuids",
  2379. "ieframe.dll.#251",
  2380. "kernel32.dll.WerSetFlags",
  2381. "ieshims.dll.IEShims_Initialize",
  2382. "user32.dll.SetWindowsHookExW",
  2383. "user32.dll.FindWindowExA",
  2384. "kernel32.dll.CreateProcessW",
  2385. "kernel32.dll.CreateProcessA",
  2386. "advapi32.dll.RegQueryValueA",
  2387. "ntdll.dll.LdrRegisterDllNotification",
  2388. "ole32.dll.NdrOleInitializeExtension",
  2389. "shell32.dll.SHChangeNotifyRegisterThread",
  2390. "comctl32.dll.#4",
  2391. "comctl32.dll.ImageList_Add",
  2392. "wininet.dll.InternetQueryOptionA",
  2393. "gdi32.dll.GetTextExtentExPointWPri",
  2394. "urlmon.dll.#104",
  2395. "user32.dll.LoadCursorW",
  2396. "user32.dll.GetClassInfoExW",
  2397. "kernel32.dll.QueryActCtxW",
  2398. "kernel32.dll.ActivateActCtx",
  2399. "kernel32.dll.FindActCtxSectionStringW",
  2400. "kernel32.dll.DeactivateActCtx",
  2401. "user32.dll.CallWindowProcW",
  2402. "user32.dll.ChangeWindowMessageFilter",
  2403. "dwmapi.dll.DwmSetWindowAttribute",
  2404. "urlmon.dll.#111",
  2405. "wininet.dll.GetUrlCacheEntryInfoW",
  2406. "urlmon.dll.UrlMkGetSessionOption",
  2407. "mlang.dll.#121",
  2408. "urlmon.dll.ReleaseBindInfo",
  2409. "oleaut32.dll.#11",
  2410. "ieshims.dll.IEShims_SetRedirectRegistryForThread",
  2411. "comctl32.dll.#8",
  2412. "uxtheme.dll.GetThemeInt",
  2413. "urlmon.dll.CreateURLMonikerEx",
  2414. "urlmon.dll.CreateAsyncBindCtxEx",
  2415. "urlmon.dll.RegisterBindStatusCallback",
  2416. "urlmon.dll.CreateFormatEnumerator",
  2417. "rasadhlp.dll.WSAttemptAutodialAddr",
  2418. "rasadhlp.dll.WSAttemptAutodialName",
  2419. "rasadhlp.dll.WSNoteSuccessfulHostentLookup",
  2420. "urlmon.dll.#444",
  2421. "urlmon.dll.#445",
  2422. "dwmapi.dll.DwmInvalidateIconicBitmaps",
  2423. "urlmon.dll.RevokeBindStatusCallback",
  2424. "urlmon.dll.CreateIUriBuilder",
  2425. "urlmon.dll.#330",
  2426. "urlmon.dll.RegisterFormatEnumerator",
  2427. "oleaut32.dll.#201",
  2428. "oleaut32.dll.#3",
  2429. "wininet.dll.CreateUrlCacheEntryA",
  2430. "wininet.dll.CommitUrlCacheEntryA",
  2431. "oleaut32.dll.#7",
  2432. "urlmon.dll.CoInternetIsFeatureEnabled",
  2433. "oleaut32.dll.#8",
  2434. "ieframe.dll.#302",
  2435. "wininet.dll.CreateUrlCacheContainerW",
  2436. "oleaut32.dll.#4",
  2437. "oleaut32.dll.VariantClear",
  2438. "urlmon.dll.IntlPercentEncodeNormalize",
  2439. "shlwapi.dll.PathGetDriveNumberW",
  2440. "urlmon.dll.#335",
  2441. "oleaut32.dll.#19",
  2442. "oleaut32.dll.#17",
  2443. "oleaut32.dll.#20",
  2444. "ole32.dll.CoGetObjectContext",
  2445. "imgutil.dll.DecodeImage",
  2446. "uxtheme.dll.#61",
  2447. "oleaut32.dll.#147",
  2448. "ieshims.dll.IEShims_GetOriginatingThreadId",
  2449. "user32.dll.UnregisterClassA",
  2450. "ieshims.dll.IEShims_Uninitialize",
  2451. "ntdll.dll.LdrUnregisterDllNotification",
  2452. "rtutils.dll.TraceRegisterExA",
  2453. "sechost.dll.OpenServiceA",
  2454. "urlmon.dll.#326",
  2455. "urlmon.dll.#327",
  2456. "ole32.dll.StgOpenStorageEx"
  2457. ]
  2458.  
  2459. [*] Static Analysis: {
  2460. "pe": {
  2461. "peid_signatures": [
  2462. [
  2463. "Ste@lth PE 1.01 -> BGCorp"
  2464. ]
  2465. ],
  2466. "imports": [
  2467. {
  2468. "imports": [
  2469. {
  2470. "name": "GetClusterFromResource",
  2471. "address": "0x40b038"
  2472. }
  2473. ],
  2474. "dll": "CLUSAPI.dll"
  2475. },
  2476. {
  2477. "imports": [
  2478. {
  2479. "name": "GetCursorPos",
  2480. "address": "0x40b154"
  2481. },
  2482. {
  2483. "name": "GetPriorityClipboardFormat",
  2484. "address": "0x40b158"
  2485. },
  2486. {
  2487. "name": "GetClientRect",
  2488. "address": "0x40b15c"
  2489. },
  2490. {
  2491. "name": "GetTopWindow",
  2492. "address": "0x40b160"
  2493. },
  2494. {
  2495. "name": "GetUserObjectInformationW",
  2496. "address": "0x40b164"
  2497. },
  2498. {
  2499. "name": "GetWindowTextA",
  2500. "address": "0x40b168"
  2501. },
  2502. {
  2503. "name": "DefDlgProcA",
  2504. "address": "0x40b16c"
  2505. },
  2506. {
  2507. "name": "GetUserObjectSecurity",
  2508. "address": "0x40b170"
  2509. },
  2510. {
  2511. "name": "LoadStringA",
  2512. "address": "0x40b174"
  2513. },
  2514. {
  2515. "name": "GetMenuStringA",
  2516. "address": "0x40b178"
  2517. },
  2518. {
  2519. "name": "LockWindowUpdate",
  2520. "address": "0x40b17c"
  2521. },
  2522. {
  2523. "name": "DestroyWindow",
  2524. "address": "0x40b180"
  2525. },
  2526. {
  2527. "name": "GetWindowTextLengthA",
  2528. "address": "0x40b184"
  2529. },
  2530. {
  2531. "name": "GetDlgItemTextW",
  2532. "address": "0x40b188"
  2533. },
  2534. {
  2535. "name": "GetClipboardSequenceNumber",
  2536. "address": "0x40b18c"
  2537. },
  2538. {
  2539. "name": "EnumThreadWindows",
  2540. "address": "0x40b190"
  2541. },
  2542. {
  2543. "name": "DefDlgProcW",
  2544. "address": "0x40b194"
  2545. },
  2546. {
  2547. "name": "LoadAcceleratorsA",
  2548. "address": "0x40b198"
  2549. },
  2550. {
  2551. "name": "GetClassWord",
  2552. "address": "0x40b19c"
  2553. },
  2554. {
  2555. "name": "GetWindowWord",
  2556. "address": "0x40b1a0"
  2557. },
  2558. {
  2559. "name": "GetMenuDefaultItem",
  2560. "address": "0x40b1a4"
  2561. },
  2562. {
  2563. "name": "IsWindow",
  2564. "address": "0x40b1a8"
  2565. },
  2566. {
  2567. "name": "DrawStateA",
  2568. "address": "0x40b1ac"
  2569. },
  2570. {
  2571. "name": "GetWindowModuleFileNameW",
  2572. "address": "0x40b1b0"
  2573. },
  2574. {
  2575. "name": "IsWindowEnabled",
  2576. "address": "0x40b1b4"
  2577. }
  2578. ],
  2579. "dll": "USER32.dll"
  2580. },
  2581. {
  2582. "imports": [
  2583. {
  2584. "name": "vfwprintf",
  2585. "address": "0x40b1e0"
  2586. },
  2587. {
  2588. "name": "fgetws",
  2589. "address": "0x40b1e4"
  2590. },
  2591. {
  2592. "name": "strncmp",
  2593. "address": "0x40b1e8"
  2594. },
  2595. {
  2596. "name": "strftime",
  2597. "address": "0x40b1ec"
  2598. },
  2599. {
  2600. "name": "strtol",
  2601. "address": "0x40b1f0"
  2602. }
  2603. ],
  2604. "dll": "msvcrt.dll"
  2605. },
  2606. {
  2607. "imports": [
  2608. {
  2609. "name": "GetCurrentObject",
  2610. "address": "0x40b048"
  2611. },
  2612. {
  2613. "name": "GetWorldTransform",
  2614. "address": "0x40b04c"
  2615. },
  2616. {
  2617. "name": "GetOutlineTextMetricsW",
  2618. "address": "0x40b050"
  2619. },
  2620. {
  2621. "name": "ExtTextOutW",
  2622. "address": "0x40b054"
  2623. },
  2624. {
  2625. "name": "GdiSetBatchLimit",
  2626. "address": "0x40b058"
  2627. },
  2628. {
  2629. "name": "GetTextExtentExPointW",
  2630. "address": "0x40b05c"
  2631. },
  2632. {
  2633. "name": "GetPixel",
  2634. "address": "0x40b060"
  2635. },
  2636. {
  2637. "name": "GetTextExtentPoint32A",
  2638. "address": "0x40b064"
  2639. },
  2640. {
  2641. "name": "FlattenPath",
  2642. "address": "0x40b068"
  2643. },
  2644. {
  2645. "name": "GetViewportExtEx",
  2646. "address": "0x40b06c"
  2647. }
  2648. ],
  2649. "dll": "GDI32.dll"
  2650. },
  2651. {
  2652. "imports": [
  2653. {
  2654. "name": "GetColorDirectoryW",
  2655. "address": "0x40b1d8"
  2656. }
  2657. ],
  2658. "dll": "mscms.dll"
  2659. },
  2660. {
  2661. "imports": [
  2662. {
  2663. "name": "GetMenuPosFromID",
  2664. "address": "0x40b140"
  2665. }
  2666. ],
  2667. "dll": "SHLWAPI.dll"
  2668. },
  2669. {
  2670. "imports": [
  2671. {
  2672. "name": "FindCloseUrlCache",
  2673. "address": "0x40b1c8"
  2674. }
  2675. ],
  2676. "dll": "WININET.dll"
  2677. },
  2678. {
  2679. "imports": [
  2680. {
  2681. "name": "GetFileTitleA",
  2682. "address": "0x40b040"
  2683. }
  2684. ],
  2685. "dll": "COMDLG32.dll"
  2686. },
  2687. {
  2688. "imports": [
  2689. {
  2690. "name": "GetPrintProcessorDirectoryW",
  2691. "address": "0x40b1d0"
  2692. }
  2693. ],
  2694. "dll": "WINSPOOL.DRV"
  2695. },
  2696. {
  2697. "imports": [
  2698. {
  2699. "name": "EnumerateSecurityPackagesW",
  2700. "address": "0x40b148"
  2701. },
  2702. {
  2703. "name": "GetComputerObjectNameW",
  2704. "address": "0x40b14c"
  2705. }
  2706. ],
  2707. "dll": "Secur32.dll"
  2708. },
  2709. {
  2710. "imports": [
  2711. {
  2712. "name": "GetServiceKeyNameA",
  2713. "address": "0x40b000"
  2714. },
  2715. {
  2716. "name": "GetPrivateObjectSecurity",
  2717. "address": "0x40b004"
  2718. },
  2719. {
  2720. "name": "IsTokenRestricted",
  2721. "address": "0x40b008"
  2722. },
  2723. {
  2724. "name": "DeleteService",
  2725. "address": "0x40b00c"
  2726. },
  2727. {
  2728. "name": "LogonUserA",
  2729. "address": "0x40b010"
  2730. },
  2731. {
  2732. "name": "GetServiceDisplayNameW",
  2733. "address": "0x40b014"
  2734. },
  2735. {
  2736. "name": "LookupAccountSidW",
  2737. "address": "0x40b018"
  2738. },
  2739. {
  2740. "name": "GetSidSubAuthorityCount",
  2741. "address": "0x40b01c"
  2742. },
  2743. {
  2744. "name": "DecryptFileW",
  2745. "address": "0x40b020"
  2746. },
  2747. {
  2748. "name": "GetServiceKeyNameW",
  2749. "address": "0x40b024"
  2750. },
  2751. {
  2752. "name": "EqualSid",
  2753. "address": "0x40b028"
  2754. },
  2755. {
  2756. "name": "GetUserNameA",
  2757. "address": "0x40b02c"
  2758. },
  2759. {
  2760. "name": "IsValidSecurityDescriptor",
  2761. "address": "0x40b030"
  2762. }
  2763. ],
  2764. "dll": "ADVAPI32.dll"
  2765. },
  2766. {
  2767. "imports": [
  2768. {
  2769. "name": "MkParseDisplayName",
  2770. "address": "0x40b1f8"
  2771. }
  2772. ],
  2773. "dll": "ole32.dll"
  2774. },
  2775. {
  2776. "imports": [
  2777. {
  2778. "name": "GetPwrCapabilities",
  2779. "address": "0x40b138"
  2780. }
  2781. ],
  2782. "dll": "POWRPROF.dll"
  2783. },
  2784. {
  2785. "imports": [
  2786. {
  2787. "name": "GetCPInfo",
  2788. "address": "0x40b074"
  2789. },
  2790. {
  2791. "name": "GetFileAttributesA",
  2792. "address": "0x40b078"
  2793. },
  2794. {
  2795. "name": "GetVolumeNameForVolumeMountPointW",
  2796. "address": "0x40b07c"
  2797. },
  2798. {
  2799. "name": "GetUserDefaultUILanguage",
  2800. "address": "0x40b080"
  2801. },
  2802. {
  2803. "name": "LoadLibraryW",
  2804. "address": "0x40b084"
  2805. },
  2806. {
  2807. "name": "GetTapeParameters",
  2808. "address": "0x40b088"
  2809. },
  2810. {
  2811. "name": "FindActCtxSectionStringW",
  2812. "address": "0x40b08c"
  2813. },
  2814. {
  2815. "name": "GetPrivateProfileSectionNamesW",
  2816. "address": "0x40b090"
  2817. },
  2818. {
  2819. "name": "DeactivateActCtx",
  2820. "address": "0x40b094"
  2821. },
  2822. {
  2823. "name": "GetUserDefaultLangID",
  2824. "address": "0x40b098"
  2825. },
  2826. {
  2827. "name": "GetThreadTimes",
  2828. "address": "0x40b09c"
  2829. },
  2830. {
  2831. "name": "DeleteTimerQueue",
  2832. "address": "0x40b0a0"
  2833. },
  2834. {
  2835. "name": "FindResourceExA",
  2836. "address": "0x40b0a4"
  2837. },
  2838. {
  2839. "name": "GetDefaultCommConfigA",
  2840. "address": "0x40b0a8"
  2841. },
  2842. {
  2843. "name": "GetLocalTime",
  2844. "address": "0x40b0ac"
  2845. },
  2846. {
  2847. "name": "GetFileType",
  2848. "address": "0x40b0b0"
  2849. },
  2850. {
  2851. "name": "LoadLibraryExA",
  2852. "address": "0x40b0b4"
  2853. },
  2854. {
  2855. "name": "GetSystemInfo",
  2856. "address": "0x40b0b8"
  2857. },
  2858. {
  2859. "name": "GetLogicalDriveStringsA",
  2860. "address": "0x40b0bc"
  2861. },
  2862. {
  2863. "name": "EnumSystemGeoID",
  2864. "address": "0x40b0c0"
  2865. },
  2866. {
  2867. "name": "GenerateConsoleCtrlEvent",
  2868. "address": "0x40b0c4"
  2869. },
  2870. {
  2871. "name": "EscapeCommFunction",
  2872. "address": "0x40b0c8"
  2873. },
  2874. {
  2875. "name": "lstrcpyW",
  2876. "address": "0x40b0cc"
  2877. },
  2878. {
  2879. "name": "GetLastError",
  2880. "address": "0x40b0d0"
  2881. },
  2882. {
  2883. "name": "GetPrivateProfileStringA",
  2884. "address": "0x40b0d4"
  2885. },
  2886. {
  2887. "name": "FindResourceA",
  2888. "address": "0x40b0d8"
  2889. },
  2890. {
  2891. "name": "GetLongPathNameA",
  2892. "address": "0x40b0dc"
  2893. },
  2894. {
  2895. "name": "EnumResourceTypesA",
  2896. "address": "0x40b0e0"
  2897. },
  2898. {
  2899. "name": "FindAtomA",
  2900. "address": "0x40b0e4"
  2901. },
  2902. {
  2903. "name": "FreeLibrary",
  2904. "address": "0x40b0e8"
  2905. },
  2906. {
  2907. "name": "FindFirstFileA",
  2908. "address": "0x40b0ec"
  2909. },
  2910. {
  2911. "name": "LocalLock",
  2912. "address": "0x40b0f0"
  2913. },
  2914. {
  2915. "name": "FindClose",
  2916. "address": "0x40b0f4"
  2917. },
  2918. {
  2919. "name": "GetCommModemStatus",
  2920. "address": "0x40b0f8"
  2921. },
  2922. {
  2923. "name": "EnumUILanguagesW",
  2924. "address": "0x40b0fc"
  2925. },
  2926. {
  2927. "name": "FreeEnvironmentStringsW",
  2928. "address": "0x40b100"
  2929. },
  2930. {
  2931. "name": "FindFirstVolumeW",
  2932. "address": "0x40b104"
  2933. },
  2934. {
  2935. "name": "GetSystemTimeAsFileTime",
  2936. "address": "0x40b108"
  2937. },
  2938. {
  2939. "name": "LocalHandle",
  2940. "address": "0x40b10c"
  2941. },
  2942. {
  2943. "name": "GetSystemDefaultLangID",
  2944. "address": "0x40b110"
  2945. },
  2946. {
  2947. "name": "GetExitCodeThread",
  2948. "address": "0x40b114"
  2949. },
  2950. {
  2951. "name": "GetACP",
  2952. "address": "0x40b118"
  2953. },
  2954. {
  2955. "name": "FindFirstVolumeMountPointW",
  2956. "address": "0x40b11c"
  2957. },
  2958. {
  2959. "name": "LocalUnlock",
  2960. "address": "0x40b120"
  2961. },
  2962. {
  2963. "name": "GetTickCount",
  2964. "address": "0x40b124"
  2965. },
  2966. {
  2967. "name": "GetShortPathNameA",
  2968. "address": "0x40b128"
  2969. }
  2970. ],
  2971. "dll": "KERNEL32.dll"
  2972. },
  2973. {
  2974. "imports": [
  2975. {
  2976. "name": "LoadRegTypeLib",
  2977. "address": "0x40b130"
  2978. }
  2979. ],
  2980. "dll": "OLEAUT32.dll"
  2981. },
  2982. {
  2983. "imports": [
  2984. {
  2985. "name": "GetFileVersionInfoA",
  2986. "address": "0x40b1bc"
  2987. },
  2988. {
  2989. "name": "GetFileVersionInfoSizeA",
  2990. "address": "0x40b1c0"
  2991. }
  2992. ],
  2993. "dll": "VERSION.dll"
  2994. }
  2995. ],
  2996. "digital_signers": null,
  2997. "exported_dll_name": null,
  2998. "actual_checksum": "0x00034b17",
  2999. "overlay": {
  3000. "size": "0x00001b28",
  3001. "offset": "0x00027000"
  3002. },
  3003. "imagebase": "0x00400000",
  3004. "reported_checksum": "0x00034b17",
  3005. "icon_hash": null,
  3006. "entrypoint": "0x00405e40",
  3007. "timestamp": "2019-06-13 06:15:17",
  3008. "osversion": "5.0",
  3009. "sections": [
  3010. {
  3011. "name": ".text",
  3012. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
  3013. "virtual_address": "0x00001000",
  3014. "size_of_data": "0x0000a000",
  3015. "entropy": "6.24",
  3016. "raw_address": "0x00001000",
  3017. "virtual_size": "0x00009e52",
  3018. "characteristics_raw": "0x60000020"
  3019. },
  3020. {
  3021. "name": ".rdata",
  3022. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  3023. "virtual_address": "0x0000b000",
  3024. "size_of_data": "0x00002000",
  3025. "entropy": "4.10",
  3026. "raw_address": "0x0000b000",
  3027. "virtual_size": "0x00001500",
  3028. "characteristics_raw": "0x40000040"
  3029. },
  3030. {
  3031. "name": ".data",
  3032. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  3033. "virtual_address": "0x0000d000",
  3034. "size_of_data": "0x00003000",
  3035. "entropy": "4.27",
  3036. "raw_address": "0x0000d000",
  3037. "virtual_size": "0x00003128",
  3038. "characteristics_raw": "0xc0000040"
  3039. },
  3040. {
  3041. "name": ".reloc",
  3042. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  3043. "virtual_address": "0x00011000",
  3044. "size_of_data": "0x00015000",
  3045. "entropy": "7.88",
  3046. "raw_address": "0x00010000",
  3047. "virtual_size": "0x000141af",
  3048. "characteristics_raw": "0xc0000040"
  3049. },
  3050. {
  3051. "name": ".rsrc",
  3052. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  3053. "virtual_address": "0x00026000",
  3054. "size_of_data": "0x00002000",
  3055. "entropy": "2.95",
  3056. "raw_address": "0x00025000",
  3057. "virtual_size": "0x00001b70",
  3058. "characteristics_raw": "0x40000040"
  3059. }
  3060. ],
  3061. "resources": [],
  3062. "dirents": [
  3063. {
  3064. "virtual_address": "0x00000000",
  3065. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  3066. "size": "0x00000000"
  3067. },
  3068. {
  3069. "virtual_address": "0x0000b84c",
  3070. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  3071. "size": "0x00000154"
  3072. },
  3073. {
  3074. "virtual_address": "0x00026000",
  3075. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  3076. "size": "0x00001b70"
  3077. },
  3078. {
  3079. "virtual_address": "0x00000000",
  3080. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  3081. "size": "0x00000000"
  3082. },
  3083. {
  3084. "virtual_address": "0x00027000",
  3085. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  3086. "size": "0x00001b28"
  3087. },
  3088. {
  3089. "virtual_address": "0x00000000",
  3090. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  3091. "size": "0x00000000"
  3092. },
  3093. {
  3094. "virtual_address": "0x00000000",
  3095. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  3096. "size": "0x00000000"
  3097. },
  3098. {
  3099. "virtual_address": "0x00000000",
  3100. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  3101. "size": "0x00000000"
  3102. },
  3103. {
  3104. "virtual_address": "0x00000000",
  3105. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  3106. "size": "0x00000000"
  3107. },
  3108. {
  3109. "virtual_address": "0x00000000",
  3110. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  3111. "size": "0x00000000"
  3112. },
  3113. {
  3114. "virtual_address": "0x00000000",
  3115. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  3116. "size": "0x00000000"
  3117. },
  3118. {
  3119. "virtual_address": "0x00000000",
  3120. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  3121. "size": "0x00000000"
  3122. },
  3123. {
  3124. "virtual_address": "0x0000b000",
  3125. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  3126. "size": "0x00000200"
  3127. },
  3128. {
  3129. "virtual_address": "0x00000000",
  3130. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  3131. "size": "0x00000000"
  3132. },
  3133. {
  3134. "virtual_address": "0x00000000",
  3135. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  3136. "size": "0x00000000"
  3137. },
  3138. {
  3139. "virtual_address": "0x00000000",
  3140. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  3141. "size": "0x00000000"
  3142. }
  3143. ],
  3144. "exports": [],
  3145. "guest_signers": {},
  3146. "imphash": "82b133201a2a706828cfe4416a0ef7e7",
  3147. "icon_fuzzy": null,
  3148. "icon": null,
  3149. "pdbpath": null,
  3150. "imported_dll_count": 16,
  3151. "versioninfo": []
  3152. }
  3153. }
Advertisement
Add Comment
Please, Sign In to add comment