Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [#############################################################################]
- Analysis Report for Tarz__n-y-los-hombres-hormiga_Installer.exe
- MD5: 34db8548e1c6bb2a25c7233b3effd535
- [#############################################################################]
- Summary:
- - Packed Binary:
- This executable is protected with a packer in order to prevent it
- from being reverse engineered.
- - Performs File Modification and Destruction:
- The executable modifies and destructs files which are not temporary.
- - Performs Registry Activities:
- The executable creates and/or modifies registry entries.
- [=============================================================================]
- Table of Contents
- [=============================================================================]
- - General information
- - Tarz__n-y-.exe
- a) Registry Activities
- b) File Activities
- c) Network Activities
- [#############################################################################]
- 1. General Information
- [#############################################################################]
- [=============================================================================]
- Information about Anubis' invocation
- [=============================================================================]
- Time needed: 257 s
- Report created: 09/30/12, 15:15:06 UTC
- Termination reason: Timeout
- Program version: 1.76.3886
- [#############################################################################]
- 2. Tarz__n-y-.exe
- [#############################################################################]
- [=============================================================================]
- General information about this executable
- [=============================================================================]
- Analysis Reason: Primary Analysis Subject
- Filename: Tarz__n-y-.exe
- MD5: 34db8548e1c6bb2a25c7233b3effd535
- SHA-1: b0ec00f081a20931a653d0ed5fc2e250173457f6
- File Size: 329480 Bytes
- Command Line: "C:\Tarz__n-y-.exe"
- Process-status
- at analysis end: alive
- Exit Code: 0
- [=============================================================================]
- Load-time Dlls
- [=============================================================================]
- Module Name: [ C:\WINDOWS\system32\ntdll.dll ],
- Base Address: [0x7C900000 ], Size: [0x000AF000 ]
- Module Name: [ C:\WINDOWS\system32\kernel32.dll ],
- Base Address: [0x7C800000 ], Size: [0x000F6000 ]
- Module Name: [ C:\WINDOWS\system32\USER32.dll ],
- Base Address: [0x7E410000 ], Size: [0x00091000 ]
- Module Name: [ C:\WINDOWS\system32\GDI32.dll ],
- Base Address: [0x77F10000 ], Size: [0x00049000 ]
- Module Name: [ C:\WINDOWS\system32\SHELL32.dll ],
- Base Address: [0x7C9C0000 ], Size: [0x00817000 ]
- Module Name: [ C:\WINDOWS\system32\ADVAPI32.dll ],
- Base Address: [0x77DD0000 ], Size: [0x0009B000 ]
- Module Name: [ C:\WINDOWS\system32\RPCRT4.dll ],
- Base Address: [0x77E70000 ], Size: [0x00092000 ]
- Module Name: [ C:\WINDOWS\system32\Secur32.dll ],
- Base Address: [0x77FE0000 ], Size: [0x00011000 ]
- Module Name: [ C:\WINDOWS\system32\msvcrt.dll ],
- Base Address: [0x77C10000 ], Size: [0x00058000 ]
- Module Name: [ C:\WINDOWS\system32\SHLWAPI.dll ],
- Base Address: [0x77F60000 ], Size: [0x00076000 ]
- Module Name: [ C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.dll ],
- Base Address: [0x773D0000 ], Size: [0x00103000 ]
- Module Name: [ C:\WINDOWS\system32\ole32.dll ],
- Base Address: [0x774E0000 ], Size: [0x0013D000 ]
- Module Name: [ C:\WINDOWS\system32\VERSION.dll ],
- Base Address: [0x77C00000 ], Size: [0x00008000 ]
- [=============================================================================]
- Run-time Dlls
- [=============================================================================]
- Module Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\nsRichEdit.dll ],
- Base Address: [0x003F0000 ], Size: [0x00009000 ]
- Module Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\NSISdl.dll ],
- Base Address: [0x10000000 ], Size: [0x0000D000 ]
- Module Name: [ C:\WINDOWS\system32\UxTheme.dll ],
- Base Address: [0x5AD70000 ], Size: [0x00038000 ]
- Module Name: [ C:\WINDOWS\system32\hnetcfg.dll ],
- Base Address: [0x662B0000 ], Size: [0x00058000 ]
- Module Name: [ C:\WINDOWS\system32\mswsock.dll ],
- Base Address: [0x71A50000 ], Size: [0x0003F000 ]
- Module Name: [ C:\WINDOWS\System32\wshtcpip.dll ],
- Base Address: [0x71A90000 ], Size: [0x00008000 ]
- Module Name: [ C:\WINDOWS\system32\WS2HELP.dll ],
- Base Address: [0x71AA0000 ], Size: [0x00008000 ]
- Module Name: [ C:\WINDOWS\system32\WS2_32.dll ],
- Base Address: [0x71AB0000 ], Size: [0x00017000 ]
- Module Name: [ C:\WINDOWS\system32\MSCTF.dll ],
- Base Address: [0x74720000 ], Size: [0x0004C000 ]
- Module Name: [ C:\WINDOWS\system32\RichEd20.dll ],
- Base Address: [0x74E30000 ], Size: [0x0006D000 ]
- Module Name: [ C:\WINDOWS\system32\comdlg32.dll ],
- Base Address: [0x763B0000 ], Size: [0x00049000 ]
- Module Name: [ C:\WINDOWS\system32\SHFOLDER.dll ],
- Base Address: [0x76780000 ], Size: [0x00009000 ]
- Module Name: [ C:\WINDOWS\system32\DNSAPI.dll ],
- Base Address: [0x76F20000 ], Size: [0x00027000 ]
- Module Name: [ C:\WINDOWS\system32\WLDAP32.dll ],
- Base Address: [0x76F60000 ], Size: [0x0002C000 ]
- Module Name: [ C:\WINDOWS\System32\winrnr.dll ],
- Base Address: [0x76FB0000 ], Size: [0x00008000 ]
- Module Name: [ C:\WINDOWS\system32\rasadhlp.dll ],
- Base Address: [0x76FC0000 ], Size: [0x00006000 ]
- Module Name: [ C:\WINDOWS\system32\SETUPAPI.dll ],
- Base Address: [0x77920000 ], Size: [0x000F3000 ]
- [=============================================================================]
- SigBuster Output
- [=============================================================================]
- NullSoft_PiMP_SFX vna SN: 1724
- [=============================================================================]
- Popups
- [=============================================================================]
- Window Name: Instalaci.n de Tarz.n-y-los-hombres-hormiga
- Displayed Times: 1
- Window Text:
- &Siguiente >
- Cancelar
- Contrato de licencia de usuario final de Metainstaller Downloader.
- Esta descarga es gratuita.
- Lea y acepte este contrato de licencia antes de instalar y utilizar el software. Si es una persona f.sica, debe ser mayor de edad o tener el consentimiento de los padres. Si adquiere el software para una empresa, debe contar con poderes para formalizar este contrato en nombre de la empresa. Al hacer clic en el bot.n .Aceptar. (o equivalente) que se encuentra en la parte inferior de la p.gina, expresar. la aceptaci.n de este contrato.
- Metainstaller LLC, sociedad estadounidense propiedad de Onekit Internet SL y con domicilio social en 01 Silverside Road, Suite 105, Wilmington - Delaware 19809 (USA). (en adelante, Metainstaller), otorga a sus usuarios una licencia gratuita, no exclusiva y no transferible (en adelante, la Licencia) de uso del presente software denominado Este WebInstaller.
- Finalidad y requisitos t.cnicos
- Este WebInstaller es un programa ejecutable que le permite descargar determinados programas inform.ticos.
- Al ejecutar Este WebInstaller acepta los t.rminos y condiciones del presente documento que conoce Este WebInstaller y lo ejecuta bajo su propia responsabilidad.
- Metainstaller se reserva el derecho de actualizar y modificar la Licencia de software y cualesquiera documentos de referencia adjuntos llegado el caso.
- Adem.s, se ofrecer. una barra de herramientas que cambiar. la p.gina de inicio del usuario, los ajustes de b.squeda por defecto y el error 404, en caso de que el usuario seleccione dichas opciones.
- La unidad de software inicia la instalaci.n de los productos de software descargados.
- La unidad de software no se instala en el ordenador del usuario, y el usuario debe borrar manualmente el ejecutable de la unidad de software.
- Garant.as y responsabilidades
- Debe utilizar Este WebInstaller de acuerdo con los t.rminos y condiciones del presente documento. Metainstaller no ser. responsable de cualesquiera da.os surgidos de su uso de Este WebInstaller de forma contraria a esta Licencia de software.
- Excepto en cuanto a las responsabilidades reglamentarias establecidas en las leyes de protecci.n del consumidor, usted exonera a Metainstaller de cualquier responsabilidad surgida de la ejecuci.n inadecuada de Este WebInstaller o el funcionamiento incorrecto de Este WebInstaller causado por el modo en que usted ejecut. el software. Dicha exoneraci.n de responsabilidad se ampliar. a los empleados y la direcci.n de Metainstaller.
- Metainstaller expresa que esta Licencia para utilizar el WebInstaller no infringe ning.n contrato previo o legislaci.n actual.
- Metainstaller garantiza que Este WebInstaller no es un programa esp.a o de publicidad. Metainstaller tambi.n garantiza que Este WebInstaller no muestra anuncios emergentes ni recopila datos personales de los usuarios.
- Metainstaller no garantiza la disponibilidad, la continuidad ni el funcionamiento a prueba de fallos de Este WebInstaller. Por lo tanto, en la medida en que la legislaci.n lo permite, esta garant.a no incluye los da.os surgidos de la falta de disponibilidad o funcionamiento interrumpido de Este WebInstaller y cualesquiera servicios que .ste posibilite.
- Metainstaller no asume responsabilidad en caso de circunstancia imprevisible o fuerza mayor. Asimismo, Metainstaller no ser. responsable de cualesquiera causas fuera del control razonable, como virus e interferencias de terceros.
- Usted eximir. a Metainstaller de cualquier responsabilidad por los derechos de propiedad intelectual, los derechos de distribuci.n, la integridad, la calidad y la ejecuci.n del software inform.tico descargado con Este WebInstaller.
- Usted afirma tener conocimiento de que Metainstaller puede no tener relaci.n de ning.n tipo con los propietarios de los programas inform.ticos que usted descarga. Usted exime a Metainstaller de toda responsabilidad por cualesquiera demandas interpuestas contra usted por su uso o posesi.n de los productos descargados con el WebInstaller, incluyendo, pero sin limitarse a ello, demandas por calumnias, violaciones de derechos de protecci.n de datos o publicidad, derechos de propiedad intelectual, derechos de nombre comercial, y cualquier otra demanda o queja referente al contenido, la calidad y el funcionamiento de dicho software.
- Vigencia
- La vigencia de este Contrato empieza en el momento de su aceptaci.n. Metainstaller tendr. derecho a restringir, suspender o rescindir este Contrato a su propia discreci.n, tanto completa como parcialmente, en cualquier momento y por cualquier motivo, sin previo aviso o responsabilidad.
- Este Contrato y, por tanto, la Licencia se rescindir.n en el momento en que usted incurra en incumplimiento de los t.rminos y condiciones del presente. Debe borrar todas las copias de el WebInstaller que posea en el momento en que este Contrato finalice.
- Uso de dispositivos de seguimiento
- Metainstaller utiliza cookies y seguimiento de IP. El software de Metainstaller y el analizador de tr.fico del sitio de Metainstaller utilizan cookies y seguidores de IP para recopilar datos para fines estad.sticos, incluyendo: la fecha de la primera visita, el n.mero de visitas, la fecha de la .ltima visita, el URL y el dominio, el buscador y la resoluci.n de pantalla.
- La publicidad en los sitios de Metainstaller incluye Google AdSense, un sistema que utiliza cookies para mostrar contenido publicitario relacionado con las p.ginas que ha visitado el usuario.
- Cuando un usuario accede a un sitio que utiliza Google AdSense, se introduce una cookie en su buscador, hecho que permite a Google recopilar informaci.n sobre la actividad del usuario, con el fin de gestionar y publicar anuncios mediante el programa publicitario Google AdSense.
- El usuario puede desactivar y/o eliminar las cookies libremente siguiendo las instrucciones de su buscador de Internet.
- Adem.s, Metainstaller utiliza el sistema de medici.n de Nielsen, que tambi.n utiliza cookies. Nielsen proporciona indicadores de medici.n de audiencia e Internet mediante la aplicaci.n de determinadas tecnolog.as web.
- Pol.ticas de privacidad:
- Nielsen NetTratings: http://www.netratings.com/corp.jsp?section=leg_scs_es&nav=3
- Google Analytics: http://www.google.com/intl/es_ALL/privacypolicy.html
- Metainstaller no utiliza correo basura y solamente gestiona datos proporcionados por los usuarios a trav.s de formularios electr.nicos que se encuentran en la web o mediante mensajes de correo electr.nico.
- Metainstaller hace un seguimiento de la informaci.n de seud.nimo: el identificador de usuario, que es un c.digo de identificaci.n .nico que se genera la primera vez que ejecuta el WebInstaller; el identificador de sesi.n, que es su identificador de usuario y la marca horaria; el identificador de archivo, que es el programa que el usuario quiere descargar; el sitio web; la versi.n de Este WebInstaller, versi.n de API; la direcci.n IP; con el fin de verificar la correcta ejecuci.n del software y analizar cualesquiera errores que se produzcan. Esta informaci.n se encuentra almacenada en el registro del ordenador.
- Derecho y jurisdicci.n aplicables
- Esta Licencia de software y la ejecuci.n del Este WebInstaller se regir.n en virtud de las leyes de Espa.a.
- En caso de controversia surgida a ra.z de esta Licencia de software o la ejecuci.n de Este WebInstaller, las partes, si la legislaci.n lo permite, se someten a la jurisdicci.n de los juzgados y los tribunales de Espa.a.
- 23 de agosto de 2011
- Instalador de Tarz.n y los hombres hormiga
- Window Name: Instalaci.n de Tarz.n-y-los-hombres-hormiga
- Displayed Times: 9
- Window Text:
- &Yes
- &No
- .Est. seguro de que desea salir de la instalaci.n de Tarz.n-y-los-hombres-hormiga ?
- [=============================================================================]
- 2.a) Tarz__n-y-.exe - Registry Activities
- [=============================================================================]
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Registry Values Modified:
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a1094da8-30a0-11dd-817b-806d6172696f}\ ],
- Value Name: [ BaseClass ], New Value: [ Drive ]
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a1094daa-30a0-11dd-817b-806d6172696f}\ ],
- Value Name: [ BaseClass ], New Value: [ Drive ]
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Registry Values Read:
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Key: [ HKLM\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\INPROCSERVER32 ],
- Value Name: [ ], Value: [ %SystemRoot%\system32\SHELL32.dll ], 1 time
- Key: [ HKLM\SOFTWARE\CLASSES\DIRECTORY ],
- Value Name: [ AlwaysShowExt ], Value: [ ], 1 time
- Key: [ HKLM\SOFTWARE\CLASSES\DRIVE\SHELLEX\FOLDEREXTENSIONS\{FBEB8A05-BEEE-4442-804E-409D6C4515E9} ],
- Value Name: [ DriveMask ], Value: [ 32 ], 1 time
- Key: [ HKLM\SOFTWARE\Microsoft\CTF\SystemShared\ ],
- Value Name: [ CUAS ], Value: [ 0 ], 1 time
- Key: [ HKLM\SYSTEM\CurrentControlSet\Control\Session Manager ],
- Value Name: [ CriticalSectionTimeout ], Value: [ 2592000 ], 1 time
- Key: [ HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters ],
- Value Name: [ Transports ], Value: [ 0x5400630070006900700000004e0065007400420049004f00530000000000 ], 2 times
- Key: [ HKLM\SYSTEM\Setup ],
- Value Name: [ OsLoaderPath ], Value: [ \ ], 2 times
- Key: [ HKLM\SYSTEM\Setup ],
- Value Name: [ SystemPartition ], Value: [ \Device\HarddiskVolume1 ], 2 times
- Key: [ HKLM\SYSTEM\Setup ],
- Value Name: [ SystemSetupInProgress ], Value: [ 0 ], 1 time
- Key: [ HKLM\Software\Microsoft\Windows\CurrentVersion ],
- Value Name: [ DevicePath ], Value: [ %SystemRoot%\inf ], 1 time
- Key: [ HKLM\Software\Microsoft\Windows\CurrentVersion\Setup ],
- Value Name: [ DriverCachePath ], Value: [ %SystemRoot%\Driver Cache ], 2 times
- Key: [ HKLM\Software\Microsoft\Windows\CurrentVersion\Setup ],
- Value Name: [ LogLevel ], Value: [ 0 ], 2 times
- Key: [ HKLM\Software\Microsoft\Windows\CurrentVersion\Setup ],
- Value Name: [ ServicePackCachePath ], Value: [ c:\windows\ServicePackFiles\ServicePackCache ], 2 times
- Key: [ HKLM\Software\Microsoft\Windows\CurrentVersion\Setup ],
- Value Name: [ ServicePackSourcePath ], Value: [ D:\ ], 2 times
- Key: [ HKLM\Software\Microsoft\Windows\CurrentVersion\Setup ],
- Value Name: [ SourcePath ], Value: [ D:\ ], 2 times
- Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers ],
- Value Name: [ TransparentEnabled ], Value: [ 1 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName ],
- Value Name: [ ComputerName ], Value: [ PC ], 2 times
- Key: [ HKLM\System\CurrentControlSet\Services\LDAP ],
- Value Name: [ LdapClientIntegrity ], Value: [ 1 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\Tcpip\Parameters ],
- Value Name: [ Domain ], Value: [ ], 3 times
- Key: [ HKLM\System\CurrentControlSet\Services\Tcpip\Parameters ],
- Value Name: [ Hostname ], Value: [ pc ], 3 times
- Key: [ HKLM\System\CurrentControlSet\Services\Tcpip\Parameters ],
- Value Name: [ UseDomainNameDevolution ], Value: [ 0 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock ],
- Value Name: [ HelperDllName ], Value: [ %SystemRoot%\System32\wshtcpip.dll ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock ],
- Value Name: [ Mapping ], Value: [ 0x0b0000000300000002000000010000000600000002000000010000000000 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock ],
- Value Name: [ MaxSockaddrLength ], Value: [ 16 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock ],
- Value Name: [ MinSockaddrLength ], Value: [ 16 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock ],
- Value Name: [ UseDelayedAcceptance ], Value: [ 0 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters ],
- Value Name: [ WinSock_Registry_Version ], Value: [ 2.0 ], 4 times
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5 ],
- Value Name: [ Num_Catalog_Entries ], Value: [ 3 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5 ],
- Value Name: [ Serial_Access_Num ], Value: [ 4 ], 2 times
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 ],
- Value Name: [ DisplayString ], Value: [ Tcpip ], 4 times
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 ],
- Value Name: [ Enabled ], Value: [ 1 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 ],
- Value Name: [ LibraryPath ], Value: [ %SystemRoot%\System32\mswsock.dll ], 2 times
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 ],
- Value Name: [ ProviderId ], Value: [ 0x409d05229e7ecf11ae5a00aa00a7112b ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 ],
- Value Name: [ StoresServiceClassInfo ], Value: [ 0 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 ],
- Value Name: [ SupportedNameSpace ], Value: [ 12 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 ],
- Value Name: [ Version ], Value: [ 0 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 ],
- Value Name: [ DisplayString ], Value: [ NTDS ], 4 times
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 ],
- Value Name: [ Enabled ], Value: [ 1 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 ],
- Value Name: [ LibraryPath ], Value: [ %SystemRoot%\System32\winrnr.dll ], 2 times
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 ],
- Value Name: [ ProviderId ], Value: [ 0xee37263b80e5cf11a55500c04fd8d4ac ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 ],
- Value Name: [ StoresServiceClassInfo ], Value: [ 0 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 ],
- Value Name: [ SupportedNameSpace ], Value: [ 32 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 ],
- Value Name: [ Version ], Value: [ 0 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 ],
- Value Name: [ DisplayString ], Value: [ Network Location Awareness (NLA) Namespace ], 4 times
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 ],
- Value Name: [ Enabled ], Value: [ 1 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 ],
- Value Name: [ LibraryPath ], Value: [ %SystemRoot%\System32\mswsock.dll ], 2 times
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 ],
- Value Name: [ ProviderId ], Value: [ 0x3a244266a83ba64abaa52e0bd71fdd83 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 ],
- Value Name: [ StoresServiceClassInfo ], Value: [ 0 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 ],
- Value Name: [ SupportedNameSpace ], Value: [ 15 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 ],
- Value Name: [ Version ], Value: [ 0 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9 ],
- Value Name: [ Next_Catalog_Entry_ID ], Value: [ 1020 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9 ],
- Value Name: [ Num_Catalog_Entries ], Value: [ 13 ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9 ],
- Value Name: [ Serial_Access_Num ], Value: [ 6 ], 2 times
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001 ],
- Value Name: [ PackedCatalogItem ], Value: [ %SystemRoot%\system32\mswsock. ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002 ],
- Value Name: [ PackedCatalogItem ], Value: [ %SystemRoot%\system32\mswsock. ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003 ],
- Value Name: [ PackedCatalogItem ], Value: [ %SystemRoot%\system32\mswsock. ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004 ],
- Value Name: [ PackedCatalogItem ], Value: [ %SystemRoot%\system32\rsvpsp.d ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005 ],
- Value Name: [ PackedCatalogItem ], Value: [ %SystemRoot%\system32\rsvpsp.d ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006 ],
- Value Name: [ PackedCatalogItem ], Value: [ %SystemRoot%\system32\mswsock. ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007 ],
- Value Name: [ PackedCatalogItem ], Value: [ %SystemRoot%\system32\mswsock. ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008 ],
- Value Name: [ PackedCatalogItem ], Value: [ %SystemRoot%\system32\mswsock. ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009 ],
- Value Name: [ PackedCatalogItem ], Value: [ %SystemRoot%\system32\mswsock. ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010 ],
- Value Name: [ PackedCatalogItem ], Value: [ %SystemRoot%\system32\mswsock. ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011 ],
- Value Name: [ PackedCatalogItem ], Value: [ %SystemRoot%\system32\mswsock. ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012 ],
- Value Name: [ PackedCatalogItem ], Value: [ %SystemRoot%\system32\mswsock. ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013 ],
- Value Name: [ PackedCatalogItem ], Value: [ %SystemRoot%\system32\mswsock. ], 1 time
- Key: [ HKLM\System\Setup ],
- Value Name: [ SystemSetupInProgress ], Value: [ 0 ], 2 times
- Key: [ HKLM\System\WPA\PnP ],
- Value Name: [ seed ], Value: [ 1274198464 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Keyboard Layout\Toggle ],
- Value Name: [ Language Hotkey ], Value: [ 1 ], 4 times
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Keyboard Layout\Toggle ],
- Value Name: [ Layout Hotkey ], Value: [ 2 ], 4 times
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ ],
- Value Name: [ ShellState ], Value: [ 0x2400000038080000000000000000000000000000010000000d0000000000 ], 2 times
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ],
- Value Name: [ DontPrettyPath ], Value: [ 0 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ],
- Value Name: [ Filter ], Value: [ 0 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ],
- Value Name: [ Hidden ], Value: [ 1 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ],
- Value Name: [ HideFileExt ], Value: [ 0 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ],
- Value Name: [ HideIcons ], Value: [ 0 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ],
- Value Name: [ MapNetDrvBtn ], Value: [ 0 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ],
- Value Name: [ NoNetCrawling ], Value: [ 1 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ],
- Value Name: [ SeparateProcess ], Value: [ 0 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ],
- Value Name: [ ShowCompColor ], Value: [ 1 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ],
- Value Name: [ ShowInfoTip ], Value: [ 1 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ],
- Value Name: [ ShowSuperHidden ], Value: [ 1 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ],
- Value Name: [ WebView ], Value: [ 0 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{a1094da8-30a0-11dd-817b-806d6172696f}\ ],
- Value Name: [ Data ], Value: [ 0x000000005c005c003f005c0049004400450023004300640052006f006d00 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{a1094da8-30a0-11dd-817b-806d6172696f}\ ],
- Value Name: [ Generation ], Value: [ 1 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{a1094daa-30a0-11dd-817b-806d6172696f}\ ],
- Value Name: [ Data ], Value: [ 0x000000005c005c003f005c00530054004f00520041004700450023005600 ], 1 time
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{a1094daa-30a0-11dd-817b-806d6172696f}\ ],
- Value Name: [ Generation ], Value: [ 1 ], 2 times
- Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings ],
- Value Name: [ ProxyEnable ], Value: [ 0 ], 1 time
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Monitored Registry Keys:
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5 ],
- Watch subtree: [ 0 ], Notify Filter: [ Key Change ], 1 time
- Key: [ HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9 ],
- Watch subtree: [ 0 ], Notify Filter: [ Key Change ], 1 time
- [=============================================================================]
- 2.b) Tarz__n-y-.exe - File Activities
- [=============================================================================]
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Files Deleted:
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsi3.tmp ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj1.tmp ]
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Files Created:
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\NSISdl.dll ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\System.dll ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\headerleft.bmp ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\metainstallerlicense_DE.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\metainstallerlicense_EN.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\metainstallerlicense_ES.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\metainstallerlicense_FR.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\metainstallerlicense_IT.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\metainstallerlicense_NL.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\metainstallerlicense_PT.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\modern-header.bmp ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\modern-wizard.bmp ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\nsDialogs.dll ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\nsRichEdit.dll ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsi3.tmp ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj1.tmp ]
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Files Read:
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\MetainstallerLicense_ES.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsi3.tmp ]
- File Name: [ C:\Tarz__n-y-.exe ]
- File Name: [ C:\WINDOWS\win.ini ]
- File Name: [ PIPE\lsarpc ]
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Files Modified:
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\NSISdl.dll ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\System.dll ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\headerleft.bmp ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\metainstallerlicense_DE.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\metainstallerlicense_EN.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\metainstallerlicense_ES.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\metainstallerlicense_FR.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\metainstallerlicense_IT.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\metainstallerlicense_NL.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\metainstallerlicense_PT.txt ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\modern-header.bmp ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\modern-wizard.bmp ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\nsDialogs.dll ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\nsRichEdit.dll ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsi3.tmp ]
- File Name: [ MountPointManager ]
- File Name: [ PIPE\lsarpc ]
- File Name: [ \Device\Afd\AsyncConnectHlp ]
- File Name: [ \Device\Afd\Endpoint ]
- File Name: [ \Device\RasAcd ]
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Directories Created:
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Directory: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp ]
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- File System Control Communication:
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- File: [ C:\Program Files\Common Files\ ], Control Code: [ 0x00090028 ], 1 time
- File: [ PIPE\lsarpc ], Control Code: [ 0x0011C017 ], 6 times
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Device Control Communication:
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- File: [ \Device\KsecDD ], Control Code: [ 0x00390008 ], 8 times
- File: [ IDE#CdRomQEMU_QEMU_CD-ROM________________________0.9.____#4d51303030302033202020202020202020202020#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} ], Control Code: [ 0x004D0008 ], 1 time
- File: [ MountPointManager ], Control Code: [ 0x006D0008 ], 2 times
- File: [ STORAGE#Volume#1&30a96598&0&SignatureB15FB15FOffset7E00Length13F291800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} ], Control Code: [ 0x004D0008 ], 1 time
- File: [ MountPointManager ], Control Code: [ 0x006D0034 ], 4 times
- File: [ \Device\Afd\Endpoint ], Control Code: [ AFD_GET_INFO (0x0001207B) ], 2 times
- File: [ \Device\Afd\Endpoint ], Control Code: [ AFD_SET_CONTEXT (0x00012047) ], 3 times
- File: [ \Device\Afd\Endpoint ], Control Code: [ AFD_SET_INFO (0x0001203B) ], 1 time
- File: [ \Device\RasAcd ], Control Code: [ 0x00F14014 ], 1 time
- File: [ \Device\Afd\Endpoint ], Control Code: [ AFD_BIND (0x00012003) ], 1 time
- File: [ \Device\Afd\Endpoint ], Control Code: [ AFD_GET_TDI_HANDLES (0x00012037) ], 2 times
- File: [ \Device\Afd\AsyncConnectHlp ], Control Code: [ AFD_CONNECT (0x00012007) ], 1 time
- File: [ \Device\Afd\Endpoint ], Control Code: [ AFD_SELECT (0x00012024) ], 2 times
- File: [ \Device\Afd\Endpoint ], Control Code: [ AFD_SEND (0x0001201F) ], 1 time
- File: [ \Device\Afd\Endpoint ], Control Code: [ AFD_RECV (0x00012017) ], 2 times
- File: [ \Device\Afd\Endpoint ], Control Code: [ AFD_DISCONNECT (0x0001202B) ], 1 time
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Memory Mapped Files:
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\NSISdl.dll ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\System.dll ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\headerleft.bmp ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\modern-header.bmp ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\nsDialogs.dll ]
- File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsg2.tmp\nsRichEdit.dll ]
- File Name: [ C:\WINDOWS\System32\winrnr.dll ]
- File Name: [ C:\WINDOWS\System32\wshtcpip.dll ]
- File Name: [ C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.dll ]
- File Name: [ C:\WINDOWS\WindowsShell.Manifest ]
- File Name: [ C:\WINDOWS\system32\DNSAPI.dll ]
- File Name: [ C:\WINDOWS\system32\MSCTF.dll ]
- File Name: [ C:\WINDOWS\system32\RichEd20.dll ]
- File Name: [ C:\WINDOWS\system32\SETUPAPI.dll ]
- File Name: [ C:\WINDOWS\system32\SHELL32.dll ]
- File Name: [ C:\WINDOWS\system32\SHFOLDER.dll ]
- File Name: [ C:\WINDOWS\system32\UxTheme.dll ]
- File Name: [ C:\WINDOWS\system32\WS2HELP.dll ]
- File Name: [ C:\WINDOWS\system32\WS2_32.dll ]
- File Name: [ C:\WINDOWS\system32\hnetcfg.dll ]
- File Name: [ C:\WINDOWS\system32\imm32.dll ]
- File Name: [ C:\WINDOWS\system32\mswsock.dll ]
- File Name: [ C:\WINDOWS\system32\rasadhlp.dll ]
- File Name: [ C:\WINDOWS\system32\rpcss.dll ]
- [=============================================================================]
- 2.c) Tarz__n-y-.exe - Network Activities
- [=============================================================================]
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- DNS Queries:
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- Name: [ stats.xmlinst.com ], Query Type: [ DNS_TYPE_A ],
- Query Result: [ 94.23.81.131 ], Successful: [ YES ], Protocol: [ udp ]
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- HTTP Conversations:
- [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
- From ANUBIS:1028 to 94.23.81.131:80 - [ stats.xmlinst.com ]
- Request: [ GET /report/index4.php?iid=118&nsoft=&soft=Tarz\xe1n-y-los-hombres-hormiga&offer=371&logtext=&action=startedInstall ], Response: [ 200 "OK" ]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement