Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Gozi"
- [*] MalScore: 10.0
- [*] File Name: "Gozi_e3af1730c3264c2d91817fab80b927d2.pptx"
- [*] File Size: 166696
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "be342db3ac1a9e12ad2d5a945cd0d4fdba487b0f20f7e7ccd47e81b04074e3b1"
- [*] MD5: "e3af1730c3264c2d91817fab80b927d2"
- [*] SHA1: "5b6dcd1189940703dd237e06d6282eafd6e68bae"
- [*] SHA512: "21381c97de7052482e2e78973f2204e5723940650b6d5bc282647a1907956545c94e86f83cd4fc60219766893a29e2cc9b428f4ed4b1b10ac3fade5fe91532d1"
- [*] CRC32: "3E518DFC"
- [*] SSDEEP: "3072:QTJbfxTA+vj+BIs5abTjYyz9aAbyTqGINOdmY23qa/2m:uJb1haBcbTjYtD7mj3v"
- [*] Process Execution: [
- "Gozi_e3af1730c3264c2d91817fab80b927d2.pptx",
- "svchost.exe",
- "WmiPrvSE.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details": [
- {
- "IP": "204.79.197.200:80"
- }
- ]
- },
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "A process attempted to delay the analysis task.",
- "Details": [
- {
- "Process": "Gozi_e3af1730c3264c2d91817fab80b927d2.pptx tried to sleep 1503 seconds, actually delayed analysis time by 0 seconds"
- },
- {
- "Process": "WmiPrvSE.exe tried to sleep 360 seconds, actually delayed analysis time by 0 seconds"
- }
- ]
- },
- {
- "Description": "Performs some HTTP requests",
- "Details": [
- {
- "url": "http://www.bing.com/favicon.ico"
- }
- ]
- },
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .reloc, entropy: 7.88, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00015000, virtual_size: 0x000141af"
- }
- ]
- },
- {
- "Description": "Crashed cuckoomon during analysis. Report this error to the Github repo.",
- "Details": [
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x1967e in cuckoomon itself while accessing 0x78d5f8 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x78d5fc from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x78d5f4 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x78d5f0 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19689 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19699 in cuckoomon itself while accessing 0x78d600 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x1969b in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x1969f in cuckoomon itself while accessing 0x78d604 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x196a2 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x196aa in cuckoomon itself while accessing 0x78d608 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x196ad in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x196bd in cuckoomon itself while accessing 0x78d60c from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x196c0 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19bfc in cuckoomon itself while accessing 0x78d5f0 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x78d5f4 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x78d5f8 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x78d5fc from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19c07 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x1967e in cuckoomon itself while accessing 0x78d678 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x78d67c from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x78d674 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x78d670 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19699 in cuckoomon itself while accessing 0x78d630 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x1969f in cuckoomon itself while accessing 0x78d634 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x196aa in cuckoomon itself while accessing 0x78d638 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x196bd in cuckoomon itself while accessing 0x78d63c from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19bfc in cuckoomon itself while accessing 0x78d670 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x78d674 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x78d678 from hook RtlDispatchException"
- },
- {
- "pid": 2576
- },
- {
- "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x78d67c from hook RtlDispatchException"
- }
- ]
- },
- {
- "Description": "Creates a hidden or system file",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\IETldCache\\Low"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11dc4ab.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF12068ce.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF121e344.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF129b13a.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF129e47f.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11c6f3f.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11ca3fb.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11cc483.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11cf799.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d15df.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d450d.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d66ed.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d98da.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11dc2e8.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11ded34.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e2c02.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e6496.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e92bb.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF12d2bda.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11eff50.TMP"
- }
- ]
- },
- {
- "Description": "File has been identified by 40 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "MicroWorld-eScan": "Trojan.GenericKD.41371533"
- },
- {
- "CAT-QuickHeal": "Trojan.Gozi"
- },
- {
- "McAfee": "Artemis!E3AF1730C326"
- },
- {
- "K7AntiVirus": "Spyware ( 0052a6bb1 )"
- },
- {
- "Alibaba": "TrojanBanker:Win32/Gozi.92f777a7"
- },
- {
- "K7GW": "Spyware ( 0052a6bb1 )"
- },
- {
- "Arcabit": "Trojan.Generic.D277478D"
- },
- {
- "Symantec": "Trojan.Gen.2"
- },
- {
- "APEX": "Malicious"
- },
- {
- "Avast": "Win32:Trojan-gen"
- },
- {
- "Kaspersky": "Trojan-Banker.Win32.Gozi.dge"
- },
- {
- "BitDefender": "Trojan.GenericKD.41371533"
- },
- {
- "NANO-Antivirus": "Trojan.Win32.Gozi.frnvpd"
- },
- {
- "Paloalto": "generic.ml"
- },
- {
- "Tencent": "Win32.Trojan-banker.Gozi.Akff"
- },
- {
- "Endgame": "malicious (high confidence)"
- },
- {
- "Emsisoft": "MalCert.D (A)"
- },
- {
- "Comodo": "Malware@#3cufp1sljdt1q"
- },
- {
- "DrWeb": "Trojan.Gozi.499"
- },
- {
- "Invincea": "heuristic"
- },
- {
- "McAfee-GW-Edition": "Artemis"
- },
- {
- "FireEye": "Generic.mg.e3af1730c3264c2d"
- },
- {
- "Sophos": "Mal/Generic-S"
- },
- {
- "SentinelOne": "DFI - Malicious PE"
- },
- {
- "Cyren": "W32/Trojan.EYBA-5385"
- },
- {
- "Microsoft": "Trojan:Win32/Skeeyah.A!bit"
- },
- {
- "ZoneAlarm": "Trojan-Banker.Win32.Gozi.dge"
- },
- {
- "GData": "Trojan.GenericKD.41371533"
- },
- {
- "ALYac": "Trojan.Banker.Gozi"
- },
- {
- "MAX": "malware (ai score=100)"
- },
- {
- "Ad-Aware": "Trojan.GenericKD.41371533"
- },
- {
- "ESET-NOD32": "Win32/Spy.Ursnif.BP"
- },
- {
- "TrendMicro-HouseCall": "TROJ_GEN.R017H0DFE19"
- },
- {
- "Rising": "Malware.Heuristic.MLite(84%) (AI-LITE:vE1Ogx1e+drNGotX/Qk2DQ)"
- },
- {
- "Ikarus": "Trojan-Spy.Agent"
- },
- {
- "Fortinet": "W32/Ursnif.BP!tr.spy"
- },
- {
- "AVG": "Win32:Trojan-gen"
- },
- {
- "Panda": "Trj/CI.A"
- },
- {
- "CrowdStrike": "win/malicious_confidence_60% (W)"
- },
- {
- "Qihoo-360": "HEUR/QVM20.1.E139.Malware.Gen"
- }
- ]
- },
- {
- "Description": "Attempts to modify proxy settings",
- "Details": []
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: [
- "C:\\Windows\\sysWOW64\\wbem\\wmiprvse.exe -secured -Embedding",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" -Embedding",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2372 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2372 CREDAT:145409",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2796 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:676 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:292 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1588 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1452 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1388 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1880 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2664 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2440 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2692 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:804 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2716 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:996 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2028 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1528 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2308 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2332 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2852 CREDAT:79873"
- ]
- [*] Mutexes: [
- "Local\\9510B8B7-82F5-2171-7207-FC794AD1C6EA",
- "Local\\_!MSFTHISTORY!_",
- "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
- "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
- "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
- "Local\\WininetStartupMutex",
- "Local\\WininetConnectionMutex",
- "Local\\WininetProxyRegistryMutex",
- "Local\\!IETld!Mutex",
- "Local\\!BrowserEmulation!SharedMemory!Mutex",
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex",
- "ConnHashTable<2372>_HashTable_Mutex",
- "Local\\ZonesCounterMutex",
- "Local\\RSS Eventing Connection Database Mutex 00000944",
- "Local\\Feed Eventing Shared Memory Mutex S-1-5-21-0000000000-0000000000-0000000000-1000",
- "Local\\c:!users!user!appdata!local!microsoft!feeds cache!",
- "Local\\c:!users!user!appdata!roaming!microsoft!windows!privacie!",
- "ConnHashTable<2796>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000aec",
- "ConnHashTable<676>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 000002a4",
- "ConnHashTable<292>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000124",
- "ConnHashTable<1588>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000634",
- "MSIMGSIZECacheMutex",
- "ConnHashTable<1452>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 000005ac",
- "ConnHashTable<1388>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 0000056c",
- "ConnHashTable<1880>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000758",
- "ConnHashTable<2664>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000a68",
- "ConnHashTable<2440>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000988",
- "ConnHashTable<2692>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000a84",
- "ConnHashTable<804>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000324",
- "ConnHashTable<2716>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000a9c",
- "ConnHashTable<996>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 000003e4",
- "ConnHashTable<2028>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 000007ec",
- "ConnHashTable<1528>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 000005f8",
- "ConnHashTable<2308>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000904",
- "Local\\Feed Arbitration Shared Memory Mutex [ User : S-1-5-21-0000000000-0000000000-0000000000-1000 ]",
- "Local\\Feeds Store Mutex S-1-5-21-0000000000-0000000000-0000000000-1000",
- "ConnHashTable<2332>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 0000091c",
- "ConnHashTable<2852>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000b24"
- ]
- [*] Modified Files: [
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{022A481F-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF7039C55C1F26A4FD.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{022A4820-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF719335267FB80751.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon[1].ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon[2].ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon[3].ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon[4].ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{022A4822-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF3D71F6405D0A3257.TMP",
- "\\??\\pipe\\MsFteWds",
- "\\??\\PIPE\\samr",
- "\\??\\PIPE\\srvsvc",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\H58NRIQEF0J49CL9XINB.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11dc4ab.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\favicon[1].ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\favicon[2].ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{022A4823-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF6635C3FD1AC9875D.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\6FJULFP3RG8Z0DK85E8T.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF12068ce.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\372JPYXKI2ICJNJSCC8U.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF121e344.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Feeds Cache\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\ErrorPageTemplate[2]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\PrivacIE\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\noConnect[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\noConnect[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\background_gradient[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\down[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favcenter[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\tools[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\errorPageStrings[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\background_gradient[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\down[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\favcenter[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\tools[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{0A27E9C3-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFFC876E9A36B75E41.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{0A27E9C4-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFCA5D2930069361D2.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon[1].ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon[2].ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon[3].ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon[4].ico",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\QF1ADM85ATTEYISHIHL6.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF129b13a.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\httpErrorPagesScripts[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\noConnect[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\down[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\tools[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{115FA839-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFC761795D2E4F2253.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{115FA83A-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF957A61B9B9AA975B.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favicon[1].ico",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\VNMBJ3DH3724KVX1VXUN.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF129e47f.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\background_gradient[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\down[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favcenter[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{1664BBB7-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF168D9ACE638B9EBA.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{1664BBB8-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF67E065919670E2EF.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\WDV7W8ZTOVPBKS69GOIG.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11c6f3f.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\background_gradient[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favcenter[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\tools[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{1E6BE6C3-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF509842DBEFC330EC.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{1E6BE6C4-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF381661B4BE7FFDF6.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\SONNIFFI5HUQDLSOUCAK.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11ca3fb.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\down[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\MSIMGSIZ.DAT",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\tools[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{2337C1D1-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF89E0A9BA6FE47FAF.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{2337C1D2-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF95BB085FAF89F781.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\LAS6956X6PRQ1TEVQGW9.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11cc483.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\background_gradient[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favcenter[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{2BE5D179-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB74A90ACB8B6686D.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{2BE5D17A-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF9AD394CDBF7D5C13.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\H0ISDU3RV36WM6UC81UG.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11cf799.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\noConnect[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{3054B0D1-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF8207C491A85CDE87.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{3054B0D2-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB1FB8DD00DE1D324.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\6I1VU22KEXPW89981D47.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d15df.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\noConnect[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\down[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{354DD88D-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFAB6654B053047C03.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{354DD88E-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF6C056DEDAA6BB3EF.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\DKJI5ID60HF237TV20ZU.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d450d.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favcenter[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{3CA2333B-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF76D44CDACD6673E7.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{3CA2333C-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB242AB0679B2FA9D.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\CRURTB66JR88ZW3BKW4Q.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d66ed.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\tools[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{418F6F35-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF1CA8D08A73EB6C10.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{418F6F36-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFDF9910B6BEFF5DBA.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\J9UEQ8VSLSZXJH73TNWK.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d98da.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{4ABE3DD9-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFC10FD87C451648C0.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{4ABE3DDA-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFA68A08A4A84C76BC.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\2F0597NZ74Z8U4XQZ9NF.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11dc2e8.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\dnserror[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\background_gradient[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{502E9B29-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF908EE3B49B81668B.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{502E9B2A-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFDC345CFDF1107CFA.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\VVGBUBO8TAHLF2PMFE8J.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11ded34.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\noConnect[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{5A876FBF-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF0155D8FB2E46B312.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{5A876FC0-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF6D9E848A6C256AE4.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\3B9XAEKTDY9QS3E4NNAW.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e2c02.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\down[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{60382C8D-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF2CE555F16FCCAA3E.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{60382C8E-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF502B8FD847D48AD5.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\WZ1BRPAFDEHVLBPW4WZN.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e6496.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favcenter[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{6A497A97-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFEAB84CCEFB2A7E05.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{6A497A98-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF83E53BFA2A2ECF2A.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\R5UMAP16LXDRJ691QC8W.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e92bb.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\tools[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{702EAB21-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB2D3E68F7CBFCF12.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{702EAB22-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFDF5BAFF2EF7937D1.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Feeds\\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\\WebSlices~\\Suggested Sites~.feed-ms",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF1AF626254D711423.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF0C7DDE37D3E9C042.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF3728F500A19CFA33.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF5C74D2E82B35D492.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Feeds\\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\\WebSlices~\\Web Slice Gallery~.feed-ms",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFBDD952A43DABD60C.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF6E1D94A714D93D38.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\VY3PX1YTQ44901TOQNR9.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF12d2bda.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{7ADFB6B9-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFE155A8FC5F1FF348.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{7ADFB6BA-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFDA713C653828C049.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\VGW54HG7YG91XA1IWJTV.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11eff50.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\dnserror[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{80EFD197-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF4F87479313F2CECF.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{80EFD198-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF2CFE32E797C42E43.TMP"
- ]
- [*] Deleted Files: [
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\Internet Explorer\\Services\\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11dc4ab.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF12068ce.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF121e344.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{022A4823-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{022A4822-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{022A4820-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{022A481F-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\errorPageStrings[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\noConnect[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\background_gradient[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\down[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favcenter[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\tools[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\ErrorPageTemplate[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\noConnect[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\background_gradient[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\down[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favcenter[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\tools[1]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF129b13a.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{0A27E9C4-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{0A27E9C3-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\errorPageStrings[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\background_gradient[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\favcenter[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\tools[1]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF129e47f.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{115FA83A-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{115FA839-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\httpErrorPagesScripts[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\noConnect[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\down[2]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11c6f3f.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{1664BBB8-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{1664BBB7-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\background_gradient[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\down[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favcenter[2]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11ca3fb.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{1E6BE6C4-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{1E6BE6C3-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\background_gradient[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favcenter[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\tools[2]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11cc483.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{2337C1D2-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{2337C1D1-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\down[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\tools[1]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11cf799.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{2BE5D17A-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{2BE5D179-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d15df.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{3054B0D2-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{3054B0D1-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\noConnect[1]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d450d.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{354DD88E-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{354DD88D-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\noConnect[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\down[2]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d66ed.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{3CA2333C-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{3CA2333B-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favcenter[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon[3].png",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11d98da.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{418F6F36-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{418F6F35-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\tools[2]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11dc2e8.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{4ABE3DDA-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{4ABE3DD9-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11ded34.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{502E9B2A-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{502E9B29-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\dnserror[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\background_gradient[2]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e2c02.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{5A876FC0-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{5A876FBF-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\noConnect[2]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e6496.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{60382C8E-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{60382C8D-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\down[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon[4].png",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11e92bb.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{6A497A98-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{6A497A97-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favcenter[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon[5].png",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF12d2bda.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{702EAB22-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{702EAB21-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\tools[2]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF11eff50.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{7ADFB6BA-991D-11E9-8070-18C086CD4729}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{7ADFB6B9-991D-11E9-8070-18C086CD4729}.dat"
- ]
- [*] Modified Registry Keys: [
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE10RunOnceLastShown",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE10RunOnceLastShown_TIMESTAMP",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE8RunOnceLastShown",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE8RunOnceLastShown_TIMESTAMP",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\Check_Associations",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\VerCache",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\VerCache",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\VerCache",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\CompatibilityFlags",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\SecuritySafe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{022A481F-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{2670000A-7350-4F3C-8081-5663EE0C6C49}\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{2670000A-7350-4F3C-8081-5663EE0C6C49}\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{2670000A-7350-4F3C-8081-5663EE0C6C49}\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FullScreen",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MenuOrder\\Favorites\\Links\\Order",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Window_Placement",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\User Preferences\\88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\DefaultScope",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\User Preferences\\2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\iexplore\\LoadTime",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\iexplore\\LoadTime",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\iexplore\\LoadTime",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{0A27E9C3-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{115FA839-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{1664BBB7-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{1E6BE6C3-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{2337C1D1-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{2BE5D179-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{3054B0D1-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{354DD88D-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{3CA2333B-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{418F6F35-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{4ABE3DD9-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{502E9B29-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{5A876FBF-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{60382C8D-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{6A497A97-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{702EAB21-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\Path",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\Handler",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\FeedUrl",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\DisplayName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\ErrorState",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\DisplayMask",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\Path",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\Handler",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\FeedUrl",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\DisplayName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\ErrorState",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\DisplayMask",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\Expiration",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\Expiration",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{7ADFB6B9-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{80EFD197-991D-11E9-8070-18C086CD4729}"
- ]
- [*] Deleted Registry Keys: [
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{022A481F-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFavoritesInitialSelection",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFeedsInitialSelection",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{0A27E9C3-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{115FA839-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{1664BBB7-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{1E6BE6C3-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{2337C1D1-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{2BE5D179-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{3054B0D1-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{354DD88D-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{3CA2333B-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{418F6F35-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{4ABE3DD9-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{502E9B29-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{5A876FBF-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{60382C8D-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{6A497A97-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\Expiration",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\Expiration",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{702EAB21-991D-11E9-8070-18C086CD4729}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{7ADFB6B9-991D-11E9-8070-18C086CD4729}"
- ]
- [*] DNS Communications: [
- {
- "type": "A",
- "request": "www.bing.com",
- "answers": [
- {
- "data": "dual-a-0001.a-msedge.net",
- "type": "CNAME"
- },
- {
- "data": "a-0001.a-afdentry.net.trafficmanager.net",
- "type": "CNAME"
- },
- {
- "data": "204.79.197.200",
- "type": "A"
- },
- {
- "data": "13.107.21.200",
- "type": "A"
- }
- ]
- },
- {
- "type": "A",
- "request": "ch12ozoo.com",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- }
- ]
- [*] Domains: [
- {
- "ip": "13.107.21.200",
- "domain": "www.bing.com"
- },
- {
- "ip": "",
- "domain": "ch12ozoo.com"
- }
- ]
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: [
- {
- "count": 20,
- "body": "",
- "uri": "http://www.bing.com/favicon.ico",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "www.bing.com",
- "version": "1.1",
- "path": "/favicon.ico",
- "data": "GET /favicon.ico HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: www.bing.com\r\nConnection: Keep-Alive\r\nCookie: MUID=055643067C21678412144E247D39664A; SRCHD=AF=NOFORM; SRCHUID=V=2&GUID=5262DC06BBB54635AC9D8A0AD382875E&dmnchg=1; SRCHUSR=DOB=20190317\r\n\r\n",
- "port": 80
- }
- ]
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": [
- [
- "Ste@lth PE 1.01 -> BGCorp"
- ]
- ],
- "imports": [
- {
- "imports": [
- {
- "name": "GetClusterFromResource",
- "address": "0x40b038"
- }
- ],
- "dll": "CLUSAPI.dll"
- },
- {
- "imports": [
- {
- "name": "GetCursorPos",
- "address": "0x40b154"
- },
- {
- "name": "GetPriorityClipboardFormat",
- "address": "0x40b158"
- },
- {
- "name": "GetClientRect",
- "address": "0x40b15c"
- },
- {
- "name": "GetTopWindow",
- "address": "0x40b160"
- },
- {
- "name": "GetUserObjectInformationW",
- "address": "0x40b164"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x40b168"
- },
- {
- "name": "DefDlgProcA",
- "address": "0x40b16c"
- },
- {
- "name": "GetUserObjectSecurity",
- "address": "0x40b170"
- },
- {
- "name": "LoadStringA",
- "address": "0x40b174"
- },
- {
- "name": "GetMenuStringA",
- "address": "0x40b178"
- },
- {
- "name": "LockWindowUpdate",
- "address": "0x40b17c"
- },
- {
- "name": "DestroyWindow",
- "address": "0x40b180"
- },
- {
- "name": "GetWindowTextLengthA",
- "address": "0x40b184"
- },
- {
- "name": "GetDlgItemTextW",
- "address": "0x40b188"
- },
- {
- "name": "GetClipboardSequenceNumber",
- "address": "0x40b18c"
- },
- {
- "name": "EnumThreadWindows",
- "address": "0x40b190"
- },
- {
- "name": "DefDlgProcW",
- "address": "0x40b194"
- },
- {
- "name": "LoadAcceleratorsA",
- "address": "0x40b198"
- },
- {
- "name": "GetClassWord",
- "address": "0x40b19c"
- },
- {
- "name": "GetWindowWord",
- "address": "0x40b1a0"
- },
- {
- "name": "GetMenuDefaultItem",
- "address": "0x40b1a4"
- },
- {
- "name": "IsWindow",
- "address": "0x40b1a8"
- },
- {
- "name": "DrawStateA",
- "address": "0x40b1ac"
- },
- {
- "name": "GetWindowModuleFileNameW",
- "address": "0x40b1b0"
- },
- {
- "name": "IsWindowEnabled",
- "address": "0x40b1b4"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "vfwprintf",
- "address": "0x40b1e0"
- },
- {
- "name": "fgetws",
- "address": "0x40b1e4"
- },
- {
- "name": "strncmp",
- "address": "0x40b1e8"
- },
- {
- "name": "strftime",
- "address": "0x40b1ec"
- },
- {
- "name": "strtol",
- "address": "0x40b1f0"
- }
- ],
- "dll": "msvcrt.dll"
- },
- {
- "imports": [
- {
- "name": "GetCurrentObject",
- "address": "0x40b048"
- },
- {
- "name": "GetWorldTransform",
- "address": "0x40b04c"
- },
- {
- "name": "GetOutlineTextMetricsW",
- "address": "0x40b050"
- },
- {
- "name": "ExtTextOutW",
- "address": "0x40b054"
- },
- {
- "name": "GdiSetBatchLimit",
- "address": "0x40b058"
- },
- {
- "name": "GetTextExtentExPointW",
- "address": "0x40b05c"
- },
- {
- "name": "GetPixel",
- "address": "0x40b060"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0x40b064"
- },
- {
- "name": "FlattenPath",
- "address": "0x40b068"
- },
- {
- "name": "GetViewportExtEx",
- "address": "0x40b06c"
- }
- ],
- "dll": "GDI32.dll"
- },
- {
- "imports": [
- {
- "name": "GetColorDirectoryW",
- "address": "0x40b1d8"
- }
- ],
- "dll": "mscms.dll"
- },
- {
- "imports": [
- {
- "name": "GetMenuPosFromID",
- "address": "0x40b140"
- }
- ],
- "dll": "SHLWAPI.dll"
- },
- {
- "imports": [
- {
- "name": "FindCloseUrlCache",
- "address": "0x40b1c8"
- }
- ],
- "dll": "WININET.dll"
- },
- {
- "imports": [
- {
- "name": "GetFileTitleA",
- "address": "0x40b040"
- }
- ],
- "dll": "COMDLG32.dll"
- },
- {
- "imports": [
- {
- "name": "GetPrintProcessorDirectoryW",
- "address": "0x40b1d0"
- }
- ],
- "dll": "WINSPOOL.DRV"
- },
- {
- "imports": [
- {
- "name": "EnumerateSecurityPackagesW",
- "address": "0x40b148"
- },
- {
- "name": "GetComputerObjectNameW",
- "address": "0x40b14c"
- }
- ],
- "dll": "Secur32.dll"
- },
- {
- "imports": [
- {
- "name": "GetServiceKeyNameA",
- "address": "0x40b000"
- },
- {
- "name": "GetPrivateObjectSecurity",
- "address": "0x40b004"
- },
- {
- "name": "IsTokenRestricted",
- "address": "0x40b008"
- },
- {
- "name": "DeleteService",
- "address": "0x40b00c"
- },
- {
- "name": "LogonUserA",
- "address": "0x40b010"
- },
- {
- "name": "GetServiceDisplayNameW",
- "address": "0x40b014"
- },
- {
- "name": "LookupAccountSidW",
- "address": "0x40b018"
- },
- {
- "name": "GetSidSubAuthorityCount",
- "address": "0x40b01c"
- },
- {
- "name": "DecryptFileW",
- "address": "0x40b020"
- },
- {
- "name": "GetServiceKeyNameW",
- "address": "0x40b024"
- },
- {
- "name": "EqualSid",
- "address": "0x40b028"
- },
- {
- "name": "GetUserNameA",
- "address": "0x40b02c"
- },
- {
- "name": "IsValidSecurityDescriptor",
- "address": "0x40b030"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "MkParseDisplayName",
- "address": "0x40b1f8"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "GetPwrCapabilities",
- "address": "0x40b138"
- }
- ],
- "dll": "POWRPROF.dll"
- },
- {
- "imports": [
- {
- "name": "GetCPInfo",
- "address": "0x40b074"
- },
- {
- "name": "GetFileAttributesA",
- "address": "0x40b078"
- },
- {
- "name": "GetVolumeNameForVolumeMountPointW",
- "address": "0x40b07c"
- },
- {
- "name": "GetUserDefaultUILanguage",
- "address": "0x40b080"
- },
- {
- "name": "LoadLibraryW",
- "address": "0x40b084"
- },
- {
- "name": "GetTapeParameters",
- "address": "0x40b088"
- },
- {
- "name": "FindActCtxSectionStringW",
- "address": "0x40b08c"
- },
- {
- "name": "GetPrivateProfileSectionNamesW",
- "address": "0x40b090"
- },
- {
- "name": "DeactivateActCtx",
- "address": "0x40b094"
- },
- {
- "name": "GetUserDefaultLangID",
- "address": "0x40b098"
- },
- {
- "name": "GetThreadTimes",
- "address": "0x40b09c"
- },
- {
- "name": "DeleteTimerQueue",
- "address": "0x40b0a0"
- },
- {
- "name": "FindResourceExA",
- "address": "0x40b0a4"
- },
- {
- "name": "GetDefaultCommConfigA",
- "address": "0x40b0a8"
- },
- {
- "name": "GetLocalTime",
- "address": "0x40b0ac"
- },
- {
- "name": "GetFileType",
- "address": "0x40b0b0"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0x40b0b4"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x40b0b8"
- },
- {
- "name": "GetLogicalDriveStringsA",
- "address": "0x40b0bc"
- },
- {
- "name": "EnumSystemGeoID",
- "address": "0x40b0c0"
- },
- {
- "name": "GenerateConsoleCtrlEvent",
- "address": "0x40b0c4"
- },
- {
- "name": "EscapeCommFunction",
- "address": "0x40b0c8"
- },
- {
- "name": "lstrcpyW",
- "address": "0x40b0cc"
- },
- {
- "name": "GetLastError",
- "address": "0x40b0d0"
- },
- {
- "name": "GetPrivateProfileStringA",
- "address": "0x40b0d4"
- },
- {
- "name": "FindResourceA",
- "address": "0x40b0d8"
- },
- {
- "name": "GetLongPathNameA",
- "address": "0x40b0dc"
- },
- {
- "name": "EnumResourceTypesA",
- "address": "0x40b0e0"
- },
- {
- "name": "FindAtomA",
- "address": "0x40b0e4"
- },
- {
- "name": "FreeLibrary",
- "address": "0x40b0e8"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x40b0ec"
- },
- {
- "name": "LocalLock",
- "address": "0x40b0f0"
- },
- {
- "name": "FindClose",
- "address": "0x40b0f4"
- },
- {
- "name": "GetCommModemStatus",
- "address": "0x40b0f8"
- },
- {
- "name": "EnumUILanguagesW",
- "address": "0x40b0fc"
- },
- {
- "name": "FreeEnvironmentStringsW",
- "address": "0x40b100"
- },
- {
- "name": "FindFirstVolumeW",
- "address": "0x40b104"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x40b108"
- },
- {
- "name": "LocalHandle",
- "address": "0x40b10c"
- },
- {
- "name": "GetSystemDefaultLangID",
- "address": "0x40b110"
- },
- {
- "name": "GetExitCodeThread",
- "address": "0x40b114"
- },
- {
- "name": "GetACP",
- "address": "0x40b118"
- },
- {
- "name": "FindFirstVolumeMountPointW",
- "address": "0x40b11c"
- },
- {
- "name": "LocalUnlock",
- "address": "0x40b120"
- },
- {
- "name": "GetTickCount",
- "address": "0x40b124"
- },
- {
- "name": "GetShortPathNameA",
- "address": "0x40b128"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "LoadRegTypeLib",
- "address": "0x40b130"
- }
- ],
- "dll": "OLEAUT32.dll"
- },
- {
- "imports": [
- {
- "name": "GetFileVersionInfoA",
- "address": "0x40b1bc"
- },
- {
- "name": "GetFileVersionInfoSizeA",
- "address": "0x40b1c0"
- }
- ],
- "dll": "VERSION.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00034b17",
- "overlay": {
- "size": "0x00001b28",
- "offset": "0x00027000"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x00034b17",
- "icon_hash": null,
- "entrypoint": "0x00405e40",
- "timestamp": "2019-06-13 06:15:17",
- "osversion": "5.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x0000a000",
- "entropy": "6.24",
- "raw_address": "0x00001000",
- "virtual_size": "0x00009e52",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0000b000",
- "size_of_data": "0x00002000",
- "entropy": "4.10",
- "raw_address": "0x0000b000",
- "virtual_size": "0x00001500",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0000d000",
- "size_of_data": "0x00003000",
- "entropy": "4.27",
- "raw_address": "0x0000d000",
- "virtual_size": "0x00003128",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00011000",
- "size_of_data": "0x00015000",
- "entropy": "7.88",
- "raw_address": "0x00010000",
- "virtual_size": "0x000141af",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00026000",
- "size_of_data": "0x00002000",
- "entropy": "2.95",
- "raw_address": "0x00025000",
- "virtual_size": "0x00001b70",
- "characteristics_raw": "0x40000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0000b84c",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000154"
- },
- {
- "virtual_address": "0x00026000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00001b70"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00027000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00001b28"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0000b000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000200"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "82b133201a2a706828cfe4416a0ef7e7",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 16,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.VirtualAlloc",
- "kernel32.dll.LoadLibraryA",
- "kernel32.dll.GetProcAddress",
- "kernel32.dll.VirtualProtect",
- "kernel32.dll.UnmapViewOfFile",
- "kernel32.dll.AddVectoredExceptionHandler",
- "kernel32.dll.RemoveVectoredExceptionHandler",
- "kernel32.dll.FreeConsole",
- "kernel32.dll.ExitProcess",
- "kernel32.dll.GetLastError",
- "kernel32.dll.HeapDestroy",
- "kernel32.dll.HeapCreate",
- "kernel32.dll.GetModuleHandleA",
- "kernel32.dll.GetTickCount",
- "kernel32.dll.VirtualFree",
- "kernel32.dll.lstrlenW",
- "kernel32.dll.lstrlenA",
- "kernel32.dll.HeapAlloc",
- "kernel32.dll.HeapFree",
- "kernel32.dll.WaitForSingleObject",
- "kernel32.dll.CloseHandle",
- "kernel32.dll.CreateEventA",
- "ntdll.dll.memcpy",
- "ntdll.dll.memset",
- "ntdll.dll.RtlUnwind",
- "ntdll.dll.NtQueryVirtualMemory",
- "ntdll.dll.sprintf",
- "ntdll.dll._snprintf",
- "ntdll.dll.strchr",
- "ntdll.dll.strcpy",
- "ntdll.dll.NtCreateKey",
- "ntdll.dll.NtDeleteValueKey",
- "ntdll.dll.RtlInitUnicodeString",
- "ntdll.dll.NtSetValueKey",
- "ntdll.dll.memmove",
- "ntdll.dll.RtlAddVectoredExceptionHandler",
- "ntdll.dll.RtlRemoveVectoredExceptionHandler",
- "ntdll.dll.wcstombs",
- "ntdll.dll.NtQueryInformationToken",
- "ntdll.dll._allmul",
- "ntdll.dll._aulldiv",
- "ntdll.dll.NtOpenProcessToken",
- "ntdll.dll.NtClose",
- "ntdll.dll._wcsupr",
- "ntdll.dll._snwprintf",
- "ntdll.dll.RtlNtStatusToDosError",
- "ntdll.dll.wcsrchr",
- "ntdll.dll.NtQueryInformationProcess",
- "ntdll.dll.mbstowcs",
- "ntdll.dll.RtlImageNtHeader",
- "ntdll.dll.wcschr",
- "shlwapi.dll.StrChrW",
- "shlwapi.dll.StrStrA",
- "shlwapi.dll.StrStrIW",
- "shlwapi.dll.StrChrA",
- "shlwapi.dll.StrStrIA",
- "shlwapi.dll.StrTrimA",
- "shlwapi.dll.#176",
- "shlwapi.dll.PathCombineW",
- "shlwapi.dll.StrToIntExA",
- "kernel32.dll.CreateWaitableTimerW",
- "kernel32.dll.Sleep",
- "kernel32.dll.CreateWaitableTimerA",
- "kernel32.dll.SwitchToThread",
- "kernel32.dll.TlsSetValue",
- "kernel32.dll.TlsFree",
- "kernel32.dll.WaitForMultipleObjects",
- "kernel32.dll.SetWaitableTimer",
- "kernel32.dll.GetSystemTimeAsFileTime",
- "kernel32.dll.CreateEventW",
- "kernel32.dll.CreateMutexW",
- "kernel32.dll.TlsAlloc",
- "kernel32.dll.LeaveCriticalSection",
- "kernel32.dll.EnterCriticalSection",
- "kernel32.dll.OpenProcess",
- "kernel32.dll.TlsGetValue",
- "kernel32.dll.DeleteCriticalSection",
- "kernel32.dll.InitializeCriticalSection",
- "kernel32.dll.lstrcatW",
- "kernel32.dll.lstrcpyA",
- "kernel32.dll.ExpandEnvironmentStringsW",
- "kernel32.dll.InterlockedIncrement",
- "kernel32.dll.QueryPerformanceFrequency",
- "kernel32.dll.QueryPerformanceCounter",
- "kernel32.dll.GetComputerNameW",
- "kernel32.dll.InterlockedDecrement",
- "kernel32.dll.lstrcmpW",
- "kernel32.dll.ProcessIdToSessionId",
- "kernel32.dll.GetCurrentProcessId",
- "kernel32.dll.SetEvent",
- "kernel32.dll.ResetEvent",
- "kernel32.dll.GetModuleFileNameW",
- "kernel32.dll.MultiByteToWideChar",
- "kernel32.dll.lstrcpyW",
- "kernel32.dll.lstrcatA",
- "user32.dll.wsprintfW",
- "user32.dll.wsprintfA",
- "advapi32.dll.OpenProcessToken",
- "advapi32.dll.RegEnumKeyExW",
- "advapi32.dll.GetUserNameW",
- "advapi32.dll.GetSidSubAuthorityCount",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.GetTokenInformation",
- "advapi32.dll.GetSidSubAuthority",
- "advapi32.dll.RegSetValueExW",
- "advapi32.dll.RegCreateKeyW",
- "shell32.dll.ShellExecuteW",
- "ws2_32.dll.#12",
- "ws2_32.dll.#11",
- "winhttp.dll.WinHttpOpenRequest",
- "winhttp.dll.WinHttpSetOption",
- "winhttp.dll.WinHttpSendRequest",
- "winhttp.dll.WinHttpWriteData",
- "winhttp.dll.WinHttpReadData",
- "winhttp.dll.WinHttpConnect",
- "winhttp.dll.WinHttpQueryOption",
- "winhttp.dll.WinHttpReceiveResponse",
- "winhttp.dll.WinHttpOpen",
- "winhttp.dll.WinHttpQueryDataAvailable",
- "winhttp.dll.WinHttpSetTimeouts",
- "winhttp.dll.WinHttpQueryHeaders",
- "winhttp.dll.WinHttpCloseHandle",
- "dnsapi.dll.DnsQuery_A",
- "dnsapi.dll.DnsFree",
- "ole32.dll.CoInitializeEx",
- "ole32.dll.CoUninitialize",
- "ole32.dll.CoSetProxyBlanket",
- "ole32.dll.CoCreateInstance",
- "ole32.dll.CreateStreamOnHGlobal",
- "oleaut32.dll.#6",
- "oleaut32.dll.#2",
- "oleaut32.dll.#15",
- "oleaut32.dll.#16",
- "cryptbase.dll.SystemFunction036",
- "uxtheme.dll.ThemeInitApiHook",
- "user32.dll.IsProcessDPIAware",
- "kernel32.dll.GetThreadPreferredUILanguages",
- "kernel32.dll.SetThreadPreferredUILanguages",
- "kernel32.dll.LocaleNameToLCID",
- "kernel32.dll.GetLocaleInfoEx",
- "kernel32.dll.LCIDToLocaleName",
- "kernel32.dll.GetSystemDefaultLocaleName",
- "oleaut32.dll.#283",
- "oleaut32.dll.#284",
- "kernel32.dll.RegOpenKeyExW",
- "oleaut32.dll.BSTR_UserSize",
- "oleaut32.dll.BSTR_UserMarshal",
- "oleaut32.dll.BSTR_UserUnmarshal",
- "oleaut32.dll.BSTR_UserFree",
- "oleaut32.dll.VARIANT_UserSize",
- "oleaut32.dll.VARIANT_UserMarshal",
- "oleaut32.dll.VARIANT_UserUnmarshal",
- "oleaut32.dll.VARIANT_UserFree",
- "oleaut32.dll.LPSAFEARRAY_UserSize",
- "oleaut32.dll.LPSAFEARRAY_UserMarshal",
- "oleaut32.dll.LPSAFEARRAY_UserUnmarshal",
- "oleaut32.dll.LPSAFEARRAY_UserFree",
- "ws2_32.dll.GetAddrInfoW",
- "rpcrt4.dll.RpcBindingFree",
- "ws2_32.dll.#116",
- "kernel32.dll.SortGetHandle",
- "kernel32.dll.SortCloseHandle",
- "ntmarta.dll.GetMartaExtensionInterface",
- "sechost.dll.LookupAccountNameLocalW",
- "advapi32.dll.LookupAccountSidW",
- "sechost.dll.LookupAccountSidLocalW",
- "kernel32.dll.RegQueryValueExW",
- "kernel32.dll.RegCloseKey",
- "oleaut32.dll.#285",
- "advapi32.dll.RegOpenKeyW",
- "sechost.dll.ConvertSidToStringSidW",
- "kernel32.dll.RegSetValueExW",
- "oleaut32.dll.#286",
- "ntdll.dll.EtwUnregisterTraceGuids",
- "oleaut32.dll.#500",
- "cryptsp.dll.CryptReleaseContext",
- "advapi32.dll.EventWrite",
- "advapi32.dll.EventRegister",
- "advapi32.dll.EventUnregister",
- "kernel32.dll.InitializeSRWLock",
- "kernel32.dll.AcquireSRWLockExclusive",
- "kernel32.dll.AcquireSRWLockShared",
- "kernel32.dll.ReleaseSRWLockExclusive",
- "kernel32.dll.ReleaseSRWLockShared",
- "kernel32.dll.SetProcessDEPPolicy",
- "user32.dll.SetProcessDPIAware",
- "shell32.dll.SetCurrentProcessExplicitAppUserModelID",
- "user32.dll.GetShellWindow",
- "user32.dll.GetWindowThreadProcessId",
- "ieframe.dll.#250",
- "wininet.dll.InternetQueryOptionW",
- "advapi32.dll.EventActivityIdControl",
- "advapi32.dll.EventWriteTransfer",
- "kernel32.dll.SetFileInformationByHandle",
- "shell32.dll.SHGetFolderPathW",
- "kernel32.dll.GetModuleHandleW",
- "advapi32.dll.AddMandatoryAce",
- "ws2_32.dll.accept",
- "ws2_32.dll.bind",
- "ws2_32.dll.closesocket",
- "ws2_32.dll.connect",
- "ws2_32.dll.getpeername",
- "ws2_32.dll.getsockname",
- "ws2_32.dll.getsockopt",
- "ws2_32.dll.ntohl",
- "ws2_32.dll.htonl",
- "ws2_32.dll.htons",
- "ws2_32.dll.inet_addr",
- "ws2_32.dll.inet_ntoa",
- "ws2_32.dll.ioctlsocket",
- "ws2_32.dll.listen",
- "ws2_32.dll.ntohs",
- "ws2_32.dll.recv",
- "ws2_32.dll.recvfrom",
- "ws2_32.dll.select",
- "ws2_32.dll.send",
- "ws2_32.dll.sendto",
- "ws2_32.dll.setsockopt",
- "ws2_32.dll.shutdown",
- "ws2_32.dll.socket",
- "ws2_32.dll.gethostbyname",
- "ws2_32.dll.gethostname",
- "ws2_32.dll.WSAIoctl",
- "ws2_32.dll.WSAGetLastError",
- "ws2_32.dll.WSASetLastError",
- "ws2_32.dll.WSAStartup",
- "ws2_32.dll.WSACleanup",
- "ws2_32.dll.__WSAFDIsSet",
- "ws2_32.dll.getaddrinfo",
- "ws2_32.dll.freeaddrinfo",
- "ws2_32.dll.getnameinfo",
- "ws2_32.dll.WSALookupServiceBeginW",
- "ws2_32.dll.WSALookupServiceNextW",
- "ws2_32.dll.WSALookupServiceEnd",
- "ws2_32.dll.WSANSPIoctl",
- "ws2_32.dll.WSAStringToAddressA",
- "ws2_32.dll.WSAStringToAddressW",
- "ws2_32.dll.WSAAddressToStringA",
- "dnsapi.dll.DnsGetProxyInformation",
- "dnsapi.dll.DnsFreeProxyName",
- "iphlpapi.dll.GetIpForwardTable2",
- "iphlpapi.dll.FreeMibTable",
- "iphlpapi.dll.GetIfEntry2",
- "iphlpapi.dll.ConvertInterfaceGuidToLuid",
- "iphlpapi.dll.ResolveIpNetEntry2",
- "iphlpapi.dll.GetIpNetEntry2",
- "shlwapi.dll.#260",
- "ws2_32.dll.#115",
- "urlmon.dll.CreateUri",
- "version.dll.GetFileVersionInfoSizeW",
- "version.dll.GetFileVersionInfoW",
- "version.dll.VerQueryValueW",
- "comctl32.dll.PropertySheetW",
- "comctl32.dll.PropertySheetA",
- "comdlg32.dll.PageSetupDlgW",
- "comdlg32.dll.PrintDlgW",
- "urlmon.dll.#101",
- "urlmon.dll.#400",
- "advapi32.dll.TraceMessage",
- "advapi32.dll.TraceMessageVa",
- "kernel32.dll.IsWow64Process",
- "sqmapi.dll.SqmGetSession",
- "sqmapi.dll.SqmEndSession",
- "sqmapi.dll.SqmStartSession",
- "sqmapi.dll.SqmStartUpload",
- "sqmapi.dll.SqmWaitForUploadComplete",
- "sqmapi.dll.SqmSet",
- "sqmapi.dll.SqmSetBool",
- "sqmapi.dll.SqmSetBits",
- "sqmapi.dll.SqmSetString",
- "sqmapi.dll.SqmIncrement",
- "sqmapi.dll.SqmSetIfMax",
- "sqmapi.dll.SqmSetIfMin",
- "sqmapi.dll.SqmAddToAverage",
- "sqmapi.dll.SqmAddToStreamDWord",
- "sqmapi.dll.SqmAddToStreamString",
- "sqmapi.dll.SqmSetAppId",
- "sqmapi.dll.SqmSetAppVersion",
- "sqmapi.dll.SqmSetMachineId",
- "sqmapi.dll.SqmSetUserId",
- "sqmapi.dll.SqmCreateNewId",
- "sqmapi.dll.SqmReadSharedMachineId",
- "sqmapi.dll.SqmReadSharedUserId",
- "sqmapi.dll.SqmWriteSharedMachineId",
- "sqmapi.dll.SqmWriteSharedUserId",
- "sqmapi.dll.SqmIsWindowsOptedIn",
- "urlmon.dll.#442",
- "kernel32.dll.WerRegisterMemoryBlock",
- "kernel32.dll.WerUnregisterMemoryBlock",
- "user32.dll.RegisterWindowMessageW",
- "rpcrt4.dll.UuidCreateSequential",
- "rpcrt4.dll.RpcServerUseProtseqW",
- "rpcrt4.dll.RpcServerRegisterIfEx",
- "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
- "rpcrt4.dll.RpcServerInqBindings",
- "rpcrt4.dll.RpcEpRegisterW",
- "rpcrt4.dll.RpcServerListen",
- "ntdll.dll.NtQuerySystemInformation",
- "user32.dll.RegisterClassExW",
- "user32.dll.CreateWindowExW",
- "user32.dll.DefWindowProcW",
- "user32.dll.SetWindowLongW",
- "dwmapi.dll.DwmIsCompositionEnabled",
- "urlmon.dll.#416",
- "kernel32.dll.RegisterApplicationRestart",
- "shell32.dll.#165",
- "urlmon.dll.CoInternetCreateZoneManager",
- "ws2_32.dll.FreeAddrInfoW",
- "user32.dll.AllowSetForegroundWindow",
- "wininet.dll.InternetInitializeAutoProxyDll",
- "rasapi32.dll.RasConnectionNotificationW",
- "rasapi32.dll.RasEnumEntriesW",
- "rtutils.dll.TracePrintfExA",
- "profapi.dll.#104",
- "shlwapi.dll.PathCanonicalizeW",
- "shlwapi.dll.PathRemoveFileSpecW",
- "shlwapi.dll.PathFindFileNameW",
- "sensapi.dll.IsNetworkAlive",
- "rpcrt4.dll.RpcBindingFromStringBindingW",
- "rpcrt4.dll.RpcBindingSetAuthInfoExW",
- "rpcrt4.dll.NdrClientCall2",
- "sechost.dll.NotifyServiceStatusChangeA",
- "nlaapi.dll.NSPStartup",
- "iphlpapi.dll.GetAdapterIndex",
- "user32.dll.PostThreadMessageW",
- "comctl32.dll.LoadIconWithScaleDown",
- "ieui.dll.InitGadgets",
- "cryptsp.dll.CryptAcquireContextW",
- "cryptsp.dll.CryptGenRandom",
- "ieproxy.dll.DllGetClassObject",
- "ieproxy.dll.DllCanUnloadNow",
- "ole32.dll.CoGetClassObject",
- "ole32.dll.CoGetMarshalSizeMax",
- "ole32.dll.CoMarshalInterface",
- "ole32.dll.CoUnmarshalInterface",
- "ole32.dll.StringFromIID",
- "ole32.dll.CoGetPSClsid",
- "ole32.dll.CoTaskMemAlloc",
- "ole32.dll.CoTaskMemFree",
- "ole32.dll.CoReleaseMarshalData",
- "ole32.dll.DcomChannelSetHResult",
- "gdi32.dll.GetLayout",
- "gdi32.dll.GdiRealizationInfo",
- "gdi32.dll.FontIsLinked",
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "gdi32.dll.GetTextFaceAliasW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegQueryValueExW",
- "gdi32.dll.GetFontAssocStatus",
- "advapi32.dll.RegQueryValueExA",
- "gdi32.dll.GdiIsMetaPrintDC",
- "user32.dll.MsgWaitForMultipleObjectsEx",
- "uxtheme.dll.OpenThemeData",
- "uxtheme.dll.GetThemeMargins",
- "uxtheme.dll.GetThemePartSize",
- "uxtheme.dll.GetThemeTextMetrics",
- "uxtheme.dll.GetThemeBool",
- "comctl32.dll.#410",
- "comctl32.dll.#413",
- "uxtheme.dll.IsAppThemed",
- "uxtheme.dll.GetThemeBackgroundExtent",
- "comctl32.dll.ImageList_LoadImageW",
- "comctl32.dll.ImageList_GetIconSize",
- "uxtheme.dll.GetThemeFont",
- "uxtheme.dll.IsCompositionActive",
- "uxtheme.dll.SetWindowTheme",
- "comctl32.dll.ImageList_Create",
- "comctl32.dll.ImageList_ReplaceIcon",
- "oleaut32.dll.#10",
- "comctl32.dll.ImageList_AddMasked",
- "uxtheme.dll.IsThemePartDefined",
- "uxtheme.dll.GetThemeColor",
- "imm32.dll.ImmIsIME",
- "urlmon.dll.CoInternetCreateSecurityManager",
- "msctf.dll.SetInputScopes2",
- "uxtheme.dll.CloseThemeData",
- "uxtheme.dll.GetThemeBackgroundContentRect",
- "uxtheme.dll.GetThemeTextExtent",
- "uxtheme.dll.EnableThemeDialogTexture",
- "urlmon.dll.#408",
- "uxtheme.dll.IsThemeActive",
- "ieui.dll.CreateGadget",
- "ieui.dll.SetGadgetMessageFilter",
- "ieui.dll.SetGadgetStyle",
- "ole32.dll.CreateBindCtx",
- "ieui.dll.SetGadgetRootInfo",
- "ole32.dll.CoGetApartmentType",
- "ole32.dll.CoRegisterInitializeSpy",
- "uxtheme.dll.GetThemeAppProperties",
- "xmllite.dll.CreateXmlReader",
- "xmllite.dll.CreateXmlReaderInputWithEncodingName",
- "comctl32.dll.#236",
- "ole32.dll.CoGetMalloc",
- "comctl32.dll.#320",
- "comctl32.dll.#324",
- "comctl32.dll.#323",
- "comctl32.dll.#328",
- "comctl32.dll.#334",
- "advapi32.dll.RegEnumKeyW",
- "ieui.dll.FindStdColor",
- "ieui.dll.InvalidateGadget",
- "ieui.dll.SetGadgetParent",
- "ieui.dll.GetGadgetTicket",
- "ieui.dll.SetGadgetRect",
- "urlmon.dll.#103",
- "urlmon.dll.#105",
- "kernel32.dll.GetThreadUILanguage",
- "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
- "setupapi.dll.CM_Get_Device_Interface_List_ExW",
- "advapi32.dll.InitializeSecurityDescriptor",
- "advapi32.dll.SetEntriesInAclW",
- "advapi32.dll.SetSecurityDescriptorDacl",
- "advapi32.dll.IsTextUnicode",
- "comctl32.dll.#332",
- "comctl32.dll.#338",
- "comctl32.dll.#339",
- "shell32.dll.#102",
- "propsys.dll.PSCreateMemoryPropertyStore",
- "propsys.dll.PSPropertyBag_WriteStr",
- "ole32.dll.PropVariantClear",
- "oleaut32.dll.#9",
- "propsys.dll.PSPropertyBag_WriteGUID",
- "propsys.dll.PSPropertyBag_ReadGUID",
- "comctl32.dll.#386",
- "shell32.dll.SHGetInstanceExplorer",
- "wininet.dll.InternetSetOptionW",
- "comctl32.dll.ImageList_Read",
- "comctl32.dll.ImageList_GetImageCount",
- "ole32.dll.CoRevokeInitializeSpy",
- "comctl32.dll.#388",
- "rpcrt4.dll.RpcBindingToStringBindingW",
- "rpcrt4.dll.RpcStringBindingParseW",
- "rpcrt4.dll.RpcStringFreeW",
- "rpcrt4.dll.I_RpcBindingInqLocalClientPID",
- "rpcrt4.dll.RpcServerInqCallAttributesW",
- "rpcrt4.dll.RpcImpersonateClient",
- "rpcrt4.dll.RpcRevertToSelf",
- "rpcrt4.dll.NdrServerCall2",
- "rpcrt4.dll.RpcBindingInqObject",
- "rpcrt4.dll.RpcStringBindingComposeW",
- "user32.dll.PostMessageW",
- "oleaut32.dll.DllGetClassObject",
- "oleaut32.dll.DllCanUnloadNow",
- "sxs.dll.SxsOleAut32MapIIDToProxyStubCLSID",
- "advapi32.dll.RegQueryValueW",
- "sxs.dll.SxsOleAut32MapIIDToTLBPath",
- "sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid",
- "sxs.dll.SxsOleAut32RedirectTypeLibrary",
- "ieui.dll.PeekMessageExW",
- "ole32.dll.CoInitialize",
- "ole32.dll.RegisterDragDrop",
- "msfeeds.dll.MsfeedsCreateInstance",
- "shell32.dll.SHGetSpecialFolderPathW",
- "shell32.dll.#66",
- "shell32.dll.SHCreateDirectoryExW",
- "wininet.dll.FindFirstUrlCacheContainerW",
- "wininet.dll.FindNextUrlCacheContainerW",
- "wininet.dll.FindCloseUrlCache",
- "user32.dll.GetWindowLongW",
- "user32.dll.IsWindow",
- "user32.dll.SendMessageW",
- "user32.dll.PeekMessageW",
- "propsys.dll.PSStringFromPropertyKey",
- "propsys.dll.PSGetPropertyDescription",
- "propsys.dll.PropVariantToString",
- "propsys.dll.InitPropVariantFromStringAsVector",
- "propsys.dll.PSCoerceToCanonicalValue",
- "shell32.dll.SHGetKnownFolderPath",
- "urlmon.dll.#458",
- "urlmon.dll.URLDownloadToFileW",
- "ieui.dll.WaitMessageEx",
- "urlmon.dll.CoInternetIsFeatureEnabledForUrl",
- "oleaut32.dll.#23",
- "oleaut32.dll.#22",
- "urlmon.dll.#441",
- "urlmon.dll.#395",
- "urlmon.dll.#351",
- "mlang.dll.#112",
- "wininet.dll.GetUrlCacheEntryInfoA",
- "wininet.dll.GetUrlCacheEntryInfoExW",
- "wininet.dll.GetUrlCacheEntryInfoExA",
- "uxtheme.dll.BufferedPaintInit",
- "uxtheme.dll.BeginBufferedPaint",
- "uxtheme.dll.DrawThemeParentBackgroundEx",
- "uxtheme.dll.DrawThemeParentBackground",
- "uxtheme.dll.IsThemeBackgroundPartiallyTransparent",
- "uxtheme.dll.DrawThemeBackground",
- "uxtheme.dll.EndBufferedPaint",
- "usp10.dll.ScriptIsComplex",
- "urlmon.dll.#420",
- "user32.dll.TranslateMessage",
- "user32.dll.DispatchMessageW",
- "ieui.dll.DUserPostEvent",
- "ieui.dll.DeleteHandle",
- "comctl32.dll.#412",
- "uxtheme.dll.BufferedPaintUnInit",
- "ieui.dll.DUserFlushMessages",
- "ieui.dll.DUserFlushDeferredMessages",
- "comctl32.dll.ImageList_Destroy",
- "ole32.dll.RevokeDragDrop",
- "ieui.dll.DisableContainerHwnd",
- "ole32.dll.CoWaitForMultipleHandles",
- "comctl32.dll.#326",
- "urlmon.dll.#412",
- "urlmon.dll.#414",
- "ntdll.dll.RtlDllShutdownInProgress",
- "comctl32.dll.#329",
- "linkinfo.dll.IsValidLinkInfo",
- "propsys.dll.#417",
- "propsys.dll.PSGetNameFromPropertyKey",
- "propsys.dll.InitVariantFromBuffer",
- "propsys.dll.PropVariantToGUID",
- "apphelp.dll.ApphelpCheckShellObject",
- "advapi32.dll.OpenThreadToken",
- "propsys.dll.PSGetPropertyDescriptionByName",
- "urlmon.dll.#325",
- "sechost.dll.ConvertStringSidToSidW",
- "samcli.dll.NetUserGetLocalGroups",
- "samlib.dll.SamConnect",
- "samlib.dll.SamEnumerateDomainsInSamServer",
- "samlib.dll.SamLookupDomainInSamServer",
- "samlib.dll.SamFreeMemory",
- "samlib.dll.SamOpenDomain",
- "advapi32.dll.LsaOpenPolicy",
- "advapi32.dll.LsaLookupNames2",
- "advapi32.dll.LsaClose",
- "advapi32.dll.LsaFreeMemory",
- "samlib.dll.SamGetAliasMembership",
- "samlib.dll.SamLookupIdsInDomain",
- "samlib.dll.SamCloseHandle",
- "netutils.dll.NetApiBufferFree",
- "linkinfo.dll.CreateLinkInfoW",
- "user32.dll.IsCharAlphaW",
- "user32.dll.CharPrevW",
- "ntshrui.dll.GetNetResourceFromLocalPathW",
- "srvcli.dll.NetShareEnum",
- "cscapi.dll.CscNetApiGetInterface",
- "slc.dll.SLGetWindowsInformationDWORD",
- "linkinfo.dll.DestroyLinkInfo",
- "propsys.dll.PropVariantToBoolean",
- "urlmon.dll.#364",
- "shell32.dll.SHCreateShellItemArrayFromIDLists",
- "ole32.dll.CoTaskMemRealloc",
- "shell32.dll.SHAssocEnumHandlersForProtocolByApplication",
- "urlmon.dll.#397",
- "urlmon.dll.#398",
- "propsys.dll.PSPropertyBag_ReadBOOL",
- "advapi32.dll.GetSecurityInfo",
- "advapi32.dll.SetSecurityInfo",
- "advapi32.dll.GetSecurityDescriptorControl",
- "user32.dll.CharLowerW",
- "cryptsp.dll.CryptCreateHash",
- "cryptsp.dll.CryptHashData",
- "cryptsp.dll.CryptGetHashParam",
- "cryptsp.dll.CryptDestroyHash",
- "crypt32.dll.CryptUnprotectData",
- "crypt32.dll.CryptProtectData",
- "cryptbase.dll.SystemFunction040",
- "cryptbase.dll.SystemFunction041",
- "comctl32.dll.#321",
- "user32.dll.DestroyWindow",
- "user32.dll.PostQuitMessage",
- "urlmon.dll.#456",
- "urlmon.dll.#451",
- "user32.dll.UnregisterClassW",
- "rpcrt4.dll.RpcEpUnregister",
- "rpcrt4.dll.RpcBindingVectorFree",
- "rpcrt4.dll.RpcServerUnregisterIf",
- "urlmon.dll.#401",
- "advapi32.dll.UnregisterTraceGuids",
- "ieframe.dll.#251",
- "kernel32.dll.WerSetFlags",
- "ieshims.dll.IEShims_Initialize",
- "user32.dll.SetWindowsHookExW",
- "user32.dll.FindWindowExA",
- "kernel32.dll.CreateProcessW",
- "kernel32.dll.CreateProcessA",
- "advapi32.dll.RegQueryValueA",
- "ntdll.dll.LdrRegisterDllNotification",
- "ole32.dll.NdrOleInitializeExtension",
- "shell32.dll.SHChangeNotifyRegisterThread",
- "comctl32.dll.#4",
- "comctl32.dll.ImageList_Add",
- "wininet.dll.InternetQueryOptionA",
- "gdi32.dll.GetTextExtentExPointWPri",
- "urlmon.dll.#104",
- "user32.dll.LoadCursorW",
- "user32.dll.GetClassInfoExW",
- "kernel32.dll.QueryActCtxW",
- "kernel32.dll.ActivateActCtx",
- "kernel32.dll.FindActCtxSectionStringW",
- "kernel32.dll.DeactivateActCtx",
- "user32.dll.CallWindowProcW",
- "user32.dll.ChangeWindowMessageFilter",
- "dwmapi.dll.DwmSetWindowAttribute",
- "urlmon.dll.#111",
- "wininet.dll.GetUrlCacheEntryInfoW",
- "urlmon.dll.UrlMkGetSessionOption",
- "mlang.dll.#121",
- "urlmon.dll.ReleaseBindInfo",
- "oleaut32.dll.#11",
- "ieshims.dll.IEShims_SetRedirectRegistryForThread",
- "comctl32.dll.#8",
- "uxtheme.dll.GetThemeInt",
- "urlmon.dll.CreateURLMonikerEx",
- "urlmon.dll.CreateAsyncBindCtxEx",
- "urlmon.dll.RegisterBindStatusCallback",
- "urlmon.dll.CreateFormatEnumerator",
- "rasadhlp.dll.WSAttemptAutodialAddr",
- "rasadhlp.dll.WSAttemptAutodialName",
- "rasadhlp.dll.WSNoteSuccessfulHostentLookup",
- "urlmon.dll.#444",
- "urlmon.dll.#445",
- "dwmapi.dll.DwmInvalidateIconicBitmaps",
- "urlmon.dll.RevokeBindStatusCallback",
- "urlmon.dll.CreateIUriBuilder",
- "urlmon.dll.#330",
- "urlmon.dll.RegisterFormatEnumerator",
- "oleaut32.dll.#201",
- "oleaut32.dll.#3",
- "wininet.dll.CreateUrlCacheEntryA",
- "wininet.dll.CommitUrlCacheEntryA",
- "oleaut32.dll.#7",
- "urlmon.dll.CoInternetIsFeatureEnabled",
- "oleaut32.dll.#8",
- "ieframe.dll.#302",
- "wininet.dll.CreateUrlCacheContainerW",
- "oleaut32.dll.#4",
- "oleaut32.dll.VariantClear",
- "urlmon.dll.IntlPercentEncodeNormalize",
- "shlwapi.dll.PathGetDriveNumberW",
- "urlmon.dll.#335",
- "oleaut32.dll.#19",
- "oleaut32.dll.#17",
- "oleaut32.dll.#20",
- "ole32.dll.CoGetObjectContext",
- "imgutil.dll.DecodeImage",
- "uxtheme.dll.#61",
- "oleaut32.dll.#147",
- "ieshims.dll.IEShims_GetOriginatingThreadId",
- "user32.dll.UnregisterClassA",
- "ieshims.dll.IEShims_Uninitialize",
- "ntdll.dll.LdrUnregisterDllNotification",
- "rtutils.dll.TraceRegisterExA",
- "sechost.dll.OpenServiceA",
- "urlmon.dll.#326",
- "urlmon.dll.#327",
- "ole32.dll.StgOpenStorageEx"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": [
- [
- "Ste@lth PE 1.01 -> BGCorp"
- ]
- ],
- "imports": [
- {
- "imports": [
- {
- "name": "GetClusterFromResource",
- "address": "0x40b038"
- }
- ],
- "dll": "CLUSAPI.dll"
- },
- {
- "imports": [
- {
- "name": "GetCursorPos",
- "address": "0x40b154"
- },
- {
- "name": "GetPriorityClipboardFormat",
- "address": "0x40b158"
- },
- {
- "name": "GetClientRect",
- "address": "0x40b15c"
- },
- {
- "name": "GetTopWindow",
- "address": "0x40b160"
- },
- {
- "name": "GetUserObjectInformationW",
- "address": "0x40b164"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x40b168"
- },
- {
- "name": "DefDlgProcA",
- "address": "0x40b16c"
- },
- {
- "name": "GetUserObjectSecurity",
- "address": "0x40b170"
- },
- {
- "name": "LoadStringA",
- "address": "0x40b174"
- },
- {
- "name": "GetMenuStringA",
- "address": "0x40b178"
- },
- {
- "name": "LockWindowUpdate",
- "address": "0x40b17c"
- },
- {
- "name": "DestroyWindow",
- "address": "0x40b180"
- },
- {
- "name": "GetWindowTextLengthA",
- "address": "0x40b184"
- },
- {
- "name": "GetDlgItemTextW",
- "address": "0x40b188"
- },
- {
- "name": "GetClipboardSequenceNumber",
- "address": "0x40b18c"
- },
- {
- "name": "EnumThreadWindows",
- "address": "0x40b190"
- },
- {
- "name": "DefDlgProcW",
- "address": "0x40b194"
- },
- {
- "name": "LoadAcceleratorsA",
- "address": "0x40b198"
- },
- {
- "name": "GetClassWord",
- "address": "0x40b19c"
- },
- {
- "name": "GetWindowWord",
- "address": "0x40b1a0"
- },
- {
- "name": "GetMenuDefaultItem",
- "address": "0x40b1a4"
- },
- {
- "name": "IsWindow",
- "address": "0x40b1a8"
- },
- {
- "name": "DrawStateA",
- "address": "0x40b1ac"
- },
- {
- "name": "GetWindowModuleFileNameW",
- "address": "0x40b1b0"
- },
- {
- "name": "IsWindowEnabled",
- "address": "0x40b1b4"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "vfwprintf",
- "address": "0x40b1e0"
- },
- {
- "name": "fgetws",
- "address": "0x40b1e4"
- },
- {
- "name": "strncmp",
- "address": "0x40b1e8"
- },
- {
- "name": "strftime",
- "address": "0x40b1ec"
- },
- {
- "name": "strtol",
- "address": "0x40b1f0"
- }
- ],
- "dll": "msvcrt.dll"
- },
- {
- "imports": [
- {
- "name": "GetCurrentObject",
- "address": "0x40b048"
- },
- {
- "name": "GetWorldTransform",
- "address": "0x40b04c"
- },
- {
- "name": "GetOutlineTextMetricsW",
- "address": "0x40b050"
- },
- {
- "name": "ExtTextOutW",
- "address": "0x40b054"
- },
- {
- "name": "GdiSetBatchLimit",
- "address": "0x40b058"
- },
- {
- "name": "GetTextExtentExPointW",
- "address": "0x40b05c"
- },
- {
- "name": "GetPixel",
- "address": "0x40b060"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0x40b064"
- },
- {
- "name": "FlattenPath",
- "address": "0x40b068"
- },
- {
- "name": "GetViewportExtEx",
- "address": "0x40b06c"
- }
- ],
- "dll": "GDI32.dll"
- },
- {
- "imports": [
- {
- "name": "GetColorDirectoryW",
- "address": "0x40b1d8"
- }
- ],
- "dll": "mscms.dll"
- },
- {
- "imports": [
- {
- "name": "GetMenuPosFromID",
- "address": "0x40b140"
- }
- ],
- "dll": "SHLWAPI.dll"
- },
- {
- "imports": [
- {
- "name": "FindCloseUrlCache",
- "address": "0x40b1c8"
- }
- ],
- "dll": "WININET.dll"
- },
- {
- "imports": [
- {
- "name": "GetFileTitleA",
- "address": "0x40b040"
- }
- ],
- "dll": "COMDLG32.dll"
- },
- {
- "imports": [
- {
- "name": "GetPrintProcessorDirectoryW",
- "address": "0x40b1d0"
- }
- ],
- "dll": "WINSPOOL.DRV"
- },
- {
- "imports": [
- {
- "name": "EnumerateSecurityPackagesW",
- "address": "0x40b148"
- },
- {
- "name": "GetComputerObjectNameW",
- "address": "0x40b14c"
- }
- ],
- "dll": "Secur32.dll"
- },
- {
- "imports": [
- {
- "name": "GetServiceKeyNameA",
- "address": "0x40b000"
- },
- {
- "name": "GetPrivateObjectSecurity",
- "address": "0x40b004"
- },
- {
- "name": "IsTokenRestricted",
- "address": "0x40b008"
- },
- {
- "name": "DeleteService",
- "address": "0x40b00c"
- },
- {
- "name": "LogonUserA",
- "address": "0x40b010"
- },
- {
- "name": "GetServiceDisplayNameW",
- "address": "0x40b014"
- },
- {
- "name": "LookupAccountSidW",
- "address": "0x40b018"
- },
- {
- "name": "GetSidSubAuthorityCount",
- "address": "0x40b01c"
- },
- {
- "name": "DecryptFileW",
- "address": "0x40b020"
- },
- {
- "name": "GetServiceKeyNameW",
- "address": "0x40b024"
- },
- {
- "name": "EqualSid",
- "address": "0x40b028"
- },
- {
- "name": "GetUserNameA",
- "address": "0x40b02c"
- },
- {
- "name": "IsValidSecurityDescriptor",
- "address": "0x40b030"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "MkParseDisplayName",
- "address": "0x40b1f8"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "GetPwrCapabilities",
- "address": "0x40b138"
- }
- ],
- "dll": "POWRPROF.dll"
- },
- {
- "imports": [
- {
- "name": "GetCPInfo",
- "address": "0x40b074"
- },
- {
- "name": "GetFileAttributesA",
- "address": "0x40b078"
- },
- {
- "name": "GetVolumeNameForVolumeMountPointW",
- "address": "0x40b07c"
- },
- {
- "name": "GetUserDefaultUILanguage",
- "address": "0x40b080"
- },
- {
- "name": "LoadLibraryW",
- "address": "0x40b084"
- },
- {
- "name": "GetTapeParameters",
- "address": "0x40b088"
- },
- {
- "name": "FindActCtxSectionStringW",
- "address": "0x40b08c"
- },
- {
- "name": "GetPrivateProfileSectionNamesW",
- "address": "0x40b090"
- },
- {
- "name": "DeactivateActCtx",
- "address": "0x40b094"
- },
- {
- "name": "GetUserDefaultLangID",
- "address": "0x40b098"
- },
- {
- "name": "GetThreadTimes",
- "address": "0x40b09c"
- },
- {
- "name": "DeleteTimerQueue",
- "address": "0x40b0a0"
- },
- {
- "name": "FindResourceExA",
- "address": "0x40b0a4"
- },
- {
- "name": "GetDefaultCommConfigA",
- "address": "0x40b0a8"
- },
- {
- "name": "GetLocalTime",
- "address": "0x40b0ac"
- },
- {
- "name": "GetFileType",
- "address": "0x40b0b0"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0x40b0b4"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x40b0b8"
- },
- {
- "name": "GetLogicalDriveStringsA",
- "address": "0x40b0bc"
- },
- {
- "name": "EnumSystemGeoID",
- "address": "0x40b0c0"
- },
- {
- "name": "GenerateConsoleCtrlEvent",
- "address": "0x40b0c4"
- },
- {
- "name": "EscapeCommFunction",
- "address": "0x40b0c8"
- },
- {
- "name": "lstrcpyW",
- "address": "0x40b0cc"
- },
- {
- "name": "GetLastError",
- "address": "0x40b0d0"
- },
- {
- "name": "GetPrivateProfileStringA",
- "address": "0x40b0d4"
- },
- {
- "name": "FindResourceA",
- "address": "0x40b0d8"
- },
- {
- "name": "GetLongPathNameA",
- "address": "0x40b0dc"
- },
- {
- "name": "EnumResourceTypesA",
- "address": "0x40b0e0"
- },
- {
- "name": "FindAtomA",
- "address": "0x40b0e4"
- },
- {
- "name": "FreeLibrary",
- "address": "0x40b0e8"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x40b0ec"
- },
- {
- "name": "LocalLock",
- "address": "0x40b0f0"
- },
- {
- "name": "FindClose",
- "address": "0x40b0f4"
- },
- {
- "name": "GetCommModemStatus",
- "address": "0x40b0f8"
- },
- {
- "name": "EnumUILanguagesW",
- "address": "0x40b0fc"
- },
- {
- "name": "FreeEnvironmentStringsW",
- "address": "0x40b100"
- },
- {
- "name": "FindFirstVolumeW",
- "address": "0x40b104"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x40b108"
- },
- {
- "name": "LocalHandle",
- "address": "0x40b10c"
- },
- {
- "name": "GetSystemDefaultLangID",
- "address": "0x40b110"
- },
- {
- "name": "GetExitCodeThread",
- "address": "0x40b114"
- },
- {
- "name": "GetACP",
- "address": "0x40b118"
- },
- {
- "name": "FindFirstVolumeMountPointW",
- "address": "0x40b11c"
- },
- {
- "name": "LocalUnlock",
- "address": "0x40b120"
- },
- {
- "name": "GetTickCount",
- "address": "0x40b124"
- },
- {
- "name": "GetShortPathNameA",
- "address": "0x40b128"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "LoadRegTypeLib",
- "address": "0x40b130"
- }
- ],
- "dll": "OLEAUT32.dll"
- },
- {
- "imports": [
- {
- "name": "GetFileVersionInfoA",
- "address": "0x40b1bc"
- },
- {
- "name": "GetFileVersionInfoSizeA",
- "address": "0x40b1c0"
- }
- ],
- "dll": "VERSION.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00034b17",
- "overlay": {
- "size": "0x00001b28",
- "offset": "0x00027000"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x00034b17",
- "icon_hash": null,
- "entrypoint": "0x00405e40",
- "timestamp": "2019-06-13 06:15:17",
- "osversion": "5.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x0000a000",
- "entropy": "6.24",
- "raw_address": "0x00001000",
- "virtual_size": "0x00009e52",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0000b000",
- "size_of_data": "0x00002000",
- "entropy": "4.10",
- "raw_address": "0x0000b000",
- "virtual_size": "0x00001500",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0000d000",
- "size_of_data": "0x00003000",
- "entropy": "4.27",
- "raw_address": "0x0000d000",
- "virtual_size": "0x00003128",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00011000",
- "size_of_data": "0x00015000",
- "entropy": "7.88",
- "raw_address": "0x00010000",
- "virtual_size": "0x000141af",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00026000",
- "size_of_data": "0x00002000",
- "entropy": "2.95",
- "raw_address": "0x00025000",
- "virtual_size": "0x00001b70",
- "characteristics_raw": "0x40000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0000b84c",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000154"
- },
- {
- "virtual_address": "0x00026000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00001b70"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00027000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00001b28"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0000b000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000200"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "82b133201a2a706828cfe4416a0ef7e7",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 16,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment