| Operation |
Data |
Completion |
Time |
| Mutant created |
Name: \BaseNamedObjects\zXeRY3a_PtW|00FFFFFF |
success or wait |
2000465151 |
| Thread created |
PID: 1636 TID: 2432 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
2000469924 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2000471649 |
| Privilege adjusted |
Privilege: Debug On or off: on |
success or wait |
2000473622 |
| File created |
Path: C:\Recycle.Bin\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Attributes:
normal Content Overwritten: false
|
object name collision |
2000474054 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008200000000000000
Path: C:\Recycle.Bin
|
success or wait |
2000475779 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read data or list directory and read ea
and read attributes and synchronize Options: synchronous io non alert and non directory
file Attributes: normal Content Overwritten: false
|
success or wait |
2000476826 |
| File opened |
Path: C:\Recycle.Bin\ Access: read attributes and synchronize and generic write Options:
synchronous io non alert and non directory file Attributes: normal Content Overwritten:
false
|
file is a directory |
2000478006 |
| File opened |
Path: C:\Recycle.Bin\ Access: read attributes and synchronize and generic write Options:
synchronous io non alert and open for backup ident Attributes: none Content Overwritten:
false
|
success or wait |
2000478690 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008200000000000000
Path: C:\Recycle.Bin
|
success or wait |
2000479871 |
| File opened |
Path: C:\SpyEye_binary_62d0915f2d31d0a060671d31419a0b80.exe Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file Attributes: normal Content Overwritten: false
|
success or wait |
2000481080 |
| File read |
Path: C:\SpyEye_binary_62d0915f2d31d0a060671d31419a0b80.exe Offset: none Length: 254976
Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 01 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69
73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65
|
success or wait |
2000484886 |
| File created |
Path: C:\Recycle.Bin\B6232F3AC2C.exe Access: read attributes and synchronize and generic
write Options: synchronous io non alert and non directory file Attributes: normal
Content Overwritten: false
|
success or wait |
2000836335 |
| File write |
Path: C:\Recycle.Bin\B6232F3AC2C.exe Offset: none Length: 254976 Value: 4D 5A 90 00
03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 01 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72
61 6D 20 63 61 6E 6E 6F 74 20 62 65
|
success or wait |
2002639013 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read data or list directory and read ea
and read attributes and synchronize Options: synchronous io non alert and non directory
file Attributes: normal Content Overwritten: false
|
success or wait |
2002666352 |
| File opened |
Path: C:\Recycle.Bin\B6232F3AC2C.exe Access: read attributes and synchronize and generic
write Options: synchronous io non alert and non directory file Attributes: normal
Content Overwritten: false
|
success or wait |
2002667287 |
| File other operation |
Disposition: BasicInformation Data : 00A013805E3CC601ECCB1BD32FB0CC0180FC04DEB397CB0100000000000000000000000000000000
Path: C:\Recycle.Bin\B6232F3AC2C.exe
|
success or wait |
2002668510 |
| Section loaded |
Path: C:\Recycle.Bin\B6232F3AC2C.exe Access: query and write and read and execute
and extend size Type: image Baseaddress: BD0000 Size: 65536 Protection: readonly Mapped
to pid: own pid
|
success or wait |
2002670811 |
| Section loaded |
Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 2850000
Size: 1208320 Protection: readonly Mapped to pid: own pid
|
success or wait |
2002688443 |
| Section loaded |
Path: C:\Recycle.Bin\B6232F3AC2C.exe Access: query and read Type: commit Baseaddress:
2130000 Size: 258048 Protection: readonly Mapped to pid: own pid
|
success or wait |
2002699449 |
| Process created |
PID: 2444 Path: C:\Recycle.Bin\B6232F3AC2C.exe Cmdline: C:\Recycle.Bin\B6232F3AC2C.exe
Createflags: 0
|
success or wait |
2002705081 |
| File deleted |
Path: C:\SpyEye_binary_62d0915f2d31d0a060671d31419a0b80.exe |
cannot delete |
2003372659 |
| Thread delayed |
Time: 1 TID: 9266 |
success or wait |
2003373527 |
| File deleted |
Path: C:\SpyEye_binary_62d0915f2d31d0a060671d31419a0b80.exe |
cannot delete |
2006962607 |
| Thread delayed |
Time: 1 TID: 9266 |
success or wait |
2006965801 |
| File deleted |
Path: C:\SpyEye_binary_62d0915f2d31d0a060671d31419a0b80.exe |
cannot delete |
2010531630 |
| Mutant created |
Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 |
success or wait |
2010532053 |
| Thread created |
PID: 1636 TID: 1448 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
2010533068 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2010533664 |
| Thread delayed |
Time: 1 TID: 9266 |
success or wait |
2010533905 |
| Thread created |
PID: 1636 TID: 1076 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
2010535117 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2010535719 |
| Privilege adjusted |
Privilege: Debug On or off: on |
success or wait |
2010535804 |
| System info queried |
Type: HandleInformation |
info length mismatch |
2010536156 |
| System info queried |
Type: HandleInformation |
success or wait |
2010542539 |
| Mutant created |
Name: \BaseNamedObjects\Global\System64 |
success or wait |
2010547317 |
| Thread created |
PID: 1636 TID: 932 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
2010547893 |
| System info queried |
Type: ProcessInformation |
success or wait |
2010551115 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 1FC0000 Size:
16384 Protection: read write Mapped to pid: own pid
|
success or wait |
2010553563 |
| Privilege adjusted |
Privilege: Debug On or off: on |
success or wait |
2010554058 |
| Memory allocated |
PID: 636 Path: C:\WINDOWS\system32\winlogon.exe Base: BAD0000 Length: 216FBA8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2010554980 |
| Memory attributes changed |
PID: 636 Path: C:\WINDOWS\system32\winlogon.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2010555089 |
| Memory attributes changed |
PID: 636 Path: C:\WINDOWS\system32\winlogon.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2010555209 |
| Memory attributes changed |
PID: 636 Path: C:\WINDOWS\system32\winlogon.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2010555318 |
| Memory written |
PID: 636 Path: C:\WINDOWS\system32\winlogon.exe Base: BAD0000 Length: 286720 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00
00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00
00 10 00
|
success or wait |
2014622640 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2014624607 |
| File deleted |
Path: C:\SpyEye_binary_62d0915f2d31d0a060671d31419a0b80.exe |
cannot delete |
2014625269 |
| Thread delayed |
Time: 1 TID: 9266 |
success or wait |
2014625574 |
| Memory written |
PID: 636 Path: C:\WINDOWS\system32\winlogon.exe Base: BADAFFC Length: 13 Value: B8
00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2014651475 |
| Memory allocated |
PID: 636 Path: C:\WINDOWS\system32\winlogon.exe Base: A30000 Length: 216FBD8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2014651587 |
| System info queried |
Type: BasicInformation |
success or wait |
2014651715 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2014651815 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2014651963 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2014652270 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2014652357 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2014652585 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2014652671 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2014652776 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2014652980 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2014653065 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2014653247 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2014653360 |
| System info queried |
Type: BasicInformation |
success or wait |
2014653653 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2014653753 |
| Memory written |
PID: 636 Path: C:\WINDOWS\system32\winlogon.exe Base: A30000 Length: 4096 Value: 64
A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C
8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45
F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00
83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83
C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66
89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8
8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03
CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83
65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03
C3 8A
|
success or wait |
2014678545 |
| Memory attributes changed |
PID: 636 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2014678672 |
| Memory written |
PID: 636 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90CFEE Length: 5 Value: E9
BF 33 12 84
|
success or wait |
2014702293 |
| Memory allocated |
PID: 692 Path: C:\WINDOWS\system32\lsass.exe Base: BAD0000 Length: 216FBA8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2014702889 |
| Memory attributes changed |
PID: 692 Path: C:\WINDOWS\system32\lsass.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2014702998 |
| Memory attributes changed |
PID: 692 Path: C:\WINDOWS\system32\lsass.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2014703120 |
| Memory attributes changed |
PID: 692 Path: C:\WINDOWS\system32\lsass.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2014703230 |
| Memory written |
PID: 692 Path: C:\WINDOWS\system32\lsass.exe Base: BAD0000 Length: 286720 Value: 4D
5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00 00
00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00 00
10 00
|
success or wait |
2017165071 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2017167957 |
| Memory written |
PID: 692 Path: C:\WINDOWS\system32\lsass.exe Base: BADAFFC Length: 13 Value: B8 00
00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2017241398 |
| Memory allocated |
PID: 692 Path: C:\WINDOWS\system32\lsass.exe Base: 9B0000 Length: 216FBD8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2017272509 |
| System info queried |
Type: BasicInformation |
success or wait |
2017272842 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2017273129 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2017277161 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2017278028 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2017278279 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2017278972 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2017279217 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2017279517 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2017280102 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2017280348 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2017280859 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2017281183 |
| System info queried |
Type: BasicInformation |
success or wait |
2017281989 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2017282279 |
| Memory written |
PID: 692 Path: C:\WINDOWS\system32\lsass.exe Base: 9B0000 Length: 4096 Value: 64 A1
18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B
40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4
8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83
C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2
04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89
45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B
45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB
66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65
FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3
8A
|
success or wait |
2017297329 |
| Memory attributes changed |
PID: 692 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2017300505 |
| Memory written |
PID: 692 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90CFEE Length: 5 Value: E9 BF
33 0A 84
|
success or wait |
2017349200 |
| Memory allocated |
PID: 892 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 216FBA8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2017350674 |
| Memory attributes changed |
PID: 892 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2017350993 |
| Memory attributes changed |
PID: 892 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2017351418 |
| Memory attributes changed |
PID: 892 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2017351737 |
| Memory written |
PID: 892 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 286720 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00
00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00
00 10 00
|
success or wait |
2019260127 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2019261989 |
| File deleted |
Path: C:\SpyEye_binary_62d0915f2d31d0a060671d31419a0b80.exe |
cannot delete |
2019334255 |
| Thread delayed |
Time: 1 TID: 9266 |
success or wait |
2019353859 |
| Memory written |
PID: 892 Path: C:\WINDOWS\system32\svchost.exe Base: BADAFFC Length: 13 Value: B8
00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2019914781 |
| Memory allocated |
PID: 892 Path: C:\WINDOWS\system32\svchost.exe Base: EB0000 Length: 216FBD8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2019915508 |
| System info queried |
Type: BasicInformation |
success or wait |
2019916349 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2019918938 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2019925766 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2019945203 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2019956181 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2019957894 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2019958324 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2019958985 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2019962617 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2019962997 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2019964254 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2019965772 |
| System info queried |
Type: BasicInformation |
success or wait |
2019968456 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2019984256 |
| Memory written |
PID: 892 Path: C:\WINDOWS\system32\svchost.exe Base: EB0000 Length: 4096 Value: 64
A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C
8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45
F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00
83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83
C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66
89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8
8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03
CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83
65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03
C3 8A
|
success or wait |
2020033456 |
| Memory attributes changed |
PID: 892 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2020034794 |
| Memory written |
PID: 892 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 5 Value: E9
BF 33 5A 84
|
success or wait |
2020059338 |
| Memory allocated |
PID: 968 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 216FBA8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2020066407 |
| Memory attributes changed |
PID: 968 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2020067099 |
| Memory attributes changed |
PID: 968 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2020084125 |
| Memory attributes changed |
PID: 968 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2020085038 |
| Memory written |
PID: 968 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 286720 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00
00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00
00 10 00
|
success or wait |
2021388367 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2021389874 |
| Memory written |
PID: 968 Path: C:\WINDOWS\system32\svchost.exe Base: BADAFFC Length: 13 Value: B8
00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2021419814 |
| Memory allocated |
PID: 968 Path: C:\WINDOWS\system32\svchost.exe Base: AF0000 Length: 216FBD8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2021420333 |
| System info queried |
Type: BasicInformation |
success or wait |
2021420883 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2021420994 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2021421372 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2021427159 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2021427260 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2021431745 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2021431838 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2021432368 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2021433094 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2021433191 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2021434027 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2021434150 |
| System info queried |
Type: BasicInformation |
success or wait |
2021435268 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2021435376 |
| Memory written |
PID: 968 Path: C:\WINDOWS\system32\svchost.exe Base: AF0000 Length: 4096 Value: 64
A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C
8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45
F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00
83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83
C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66
89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8
8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03
CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83
65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03
C3 8A
|
success or wait |
2021463445 |
| Memory attributes changed |
PID: 968 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2021470039 |
| Memory written |
PID: 968 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 5 Value: E9
BF 33 1E 84
|
success or wait |
2021492108 |
| Memory allocated |
PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 216FBA8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2021492833 |
| Memory attributes changed |
PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2021492946 |
| Memory attributes changed |
PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2021493067 |
| Memory attributes changed |
PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2021493177 |
| Memory written |
PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 286720 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00
00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00
00 10 00
|
success or wait |
2029171502 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2029171972 |
| File deleted |
Path: C:\SpyEye_binary_62d0915f2d31d0a060671d31419a0b80.exe |
success or wait |
2029172778 |
| Thread delayed |
Time: 1 TID: 9266 |
success or wait |
2029173914 |
| Memory written |
PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BADAFFC Length: 13 Value: B8
00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2029201118 |
| Memory allocated |
PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 1A80000 Length: 216FBD8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2029201233 |
| System info queried |
Type: BasicInformation |
success or wait |
2029201352 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2029201451 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2029201601 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2029201909 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2029201996 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2029202215 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2029202305 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2029202413 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2029202621 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2029202709 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2029202892 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2029203009 |
| System info queried |
Type: BasicInformation |
success or wait |
2029203303 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2029203404 |
| Memory written |
PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 1A80000 Length: 4096 Value:
64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40
1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89
45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C
00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00
83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58
66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45
F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10
03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3
83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00
03 C3 8A
|
success or wait |
2029228936 |
| Memory attributes changed |
PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2029229065 |
| Memory written |
PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 5 Value: E9
BF 33 17 85
|
success or wait |
2029252853 |
| Memory allocated |
PID: 1100 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 216FBA8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2029253338 |
| Memory attributes changed |
PID: 1100 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2029253452 |
| Memory attributes changed |
PID: 1100 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2029253573 |
| Memory attributes changed |
PID: 1100 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2029253682 |
| Memory written |
PID: 1100 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 286720 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00
00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00
00 10 00
|
success or wait |
2030258558 |
| Memory written |
PID: 1100 Path: C:\WINDOWS\system32\svchost.exe Base: BADAFFC Length: 13 Value: B8
00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2030280542 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2030280901 |
| Memory allocated |
PID: 1100 Path: C:\WINDOWS\system32\svchost.exe Base: 890000 Length: 216FBD8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2031061074 |
| System info queried |
Type: BasicInformation |
success or wait |
2031063534 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2031065525 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2031067336 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2031104461 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2031121401 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2031126666 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2031145423 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2031151620 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2031191498 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2031392773 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2031549777 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2031552664 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2031552990 |
| System info queried |
Type: BasicInformation |
success or wait |
2031576528 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2031576820 |
| Memory written |
PID: 1100 Path: C:\WINDOWS\system32\svchost.exe Base: 890000 Length: 4096 Value: 64
A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C
8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45
F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00
83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83
C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66
89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8
8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03
CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83
65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03
C3 8A
|
success or wait |
2031645609 |
| Memory attributes changed |
PID: 1100 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2031646643 |
| Memory written |
PID: 1100 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 5 Value: E9
BF 33 F8 83
|
success or wait |
2031704567 |
| Memory allocated |
PID: 1144 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 216FBA8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2031729483 |
| Memory attributes changed |
PID: 1144 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2031731766 |
| Memory attributes changed |
PID: 1144 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2031733061 |
| Memory attributes changed |
PID: 1144 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2031749320 |
| Memory written |
PID: 1144 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 286720 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00
00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00
00 10 00
|
success or wait |
2033439134 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2033442802 |
| Memory written |
PID: 1144 Path: C:\WINDOWS\system32\svchost.exe Base: BADAFFC Length: 13 Value: B8
00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2033511940 |
| Memory allocated |
PID: 1144 Path: C:\WINDOWS\system32\svchost.exe Base: 990000 Length: 216FBD8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2033543172 |
| System info queried |
Type: BasicInformation |
success or wait |
2033545673 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2033546581 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2033547517 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2033550107 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2033558819 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2033560750 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2033562025 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2033562328 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2033562926 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2033563426 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2033567996 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1F70000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2033569111 |
| System info queried |
Type: BasicInformation |
success or wait |
2033572473 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2033573072 |
| Memory written |
PID: 1144 Path: C:\WINDOWS\system32\svchost.exe Base: 990000 Length: 4096 Value: 64
A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C
8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45
F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00
83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83
C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66
89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8
8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03
CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83
65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03
C3 8A
|
success or wait |
2033600432 |
| Memory attributes changed |
PID: 1144 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2033607814 |
| Memory written |
PID: 1144 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 5 Value: E9
BF 33 08 84
|
success or wait |
2033657848 |
| Memory allocated |
PID: 1496 Path: C:\WINDOWS\system32\spoolsv.exe Base: BAD0000 Length: 216FBA8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2033666079 |
| Memory attributes changed |
PID: 1496 Path: C:\WINDOWS\system32\spoolsv.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2033668792 |
| Memory attributes changed |
PID: 1496 Path: C:\WINDOWS\system32\spoolsv.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2033671498 |
| Memory attributes changed |
PID: 1496 Path: C:\WINDOWS\system32\spoolsv.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2033689470 |
| Memory written |
PID: 1496 Path: C:\WINDOWS\system32\spoolsv.exe Base: BAD0000 Length: 286720 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00
00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00
00 10 00
|
success or wait |
2035753773 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2035755100 |
| Memory written |
PID: 1496 Path: C:\WINDOWS\system32\spoolsv.exe Base: BADAFFC Length: 13 Value: B8
00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2035778576 |
| Memory allocated |
PID: 1496 Path: C:\WINDOWS\system32\spoolsv.exe Base: A40000 Length: 216FBD8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2035779727 |
| System info queried |
Type: BasicInformation |
success or wait |
2035780567 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2035781128 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2035797868 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2035798903 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2035815745 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2035816220 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2035817347 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2035818135 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2035818549 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2035818962 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2035820340 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1F70000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2035820837 |
| System info queried |
Type: BasicInformation |
success or wait |
2035821730 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2035822078 |
| Memory written |
PID: 1496 Path: C:\WINDOWS\system32\spoolsv.exe Base: A40000 Length: 4096 Value: 64
A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C
8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45
F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00
83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83
C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66
89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8
8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03
CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83
65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03
C3 8A
|
success or wait |
2035851012 |
| Memory attributes changed |
PID: 1496 Path: C:\WINDOWS\system32\spoolsv.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2035851317 |
| Memory written |
PID: 1496 Path: C:\WINDOWS\system32\spoolsv.exe Base: 7C90CFEE Length: 5 Value: E9
BF 33 13 84
|
success or wait |
2035873679 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BAD0000 Length: 216FBA8 Allocation Type:
null Protection: page execute and read and write
|
conflicting addresses |
2035875760 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB16000 Length: 216FBA8 Allocation Type:
null Protection: page execute and read and write
|
conflicting addresses |
2035875860 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB50000 Length: 216FBA8 Allocation Type:
null Protection: page execute and read and write
|
success or wait |
2035875955 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB50000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2035876137 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB50000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2035877121 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB50000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2035877223 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB50000 Length: 286720 Value: 4D 5A
90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00 00 00
00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00 00 10
00
|
success or wait |
2035879144 |
| Thread created |
PID: 1636 TID: 3448 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
2035881266 |
| Memory allocated |
PID: 1828 Path: C:\WINDOWS\system32\ctfmon.exe Base: BAD0000 Length: 216FBA8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2035881989 |
| Memory attributes changed |
PID: 1828 Path: C:\WINDOWS\system32\ctfmon.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2035882103 |
| Memory attributes changed |
PID: 1828 Path: C:\WINDOWS\system32\ctfmon.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2035883841 |
| Thread created |
PID: 1636 TID: 3452 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
2035884120 |
| Memory attributes changed |
PID: 1828 Path: C:\WINDOWS\system32\ctfmon.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2035884274 |
| Memory written |
PID: 1828 Path: C:\WINDOWS\system32\ctfmon.exe Base: BAD0000 Length: 286720 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00
00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00
00 10 00
|
success or wait |
2036753150 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2036753496 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90D76E Length: 2000 New Protection:
page execute and read and write New Protection: page execute and write copy
|
success or wait |
2036753830 |
| System info queried |
Type: BasicInformation |
success or wait |
2036754039 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2036754264 |
| Memory written |
PID: 1828 Path: C:\WINDOWS\system32\ctfmon.exe Base: BADAFFC Length: 13 Value: B8
00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2036784567 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2036785026 |
| Memory allocated |
PID: 1828 Path: C:\WINDOWS\system32\ctfmon.exe Base: A30000 Length: 216FBD8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2036815875 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2036815957 |
| System info queried |
Type: BasicInformation |
success or wait |
2036816088 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2036816145 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2036816341 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2036816546 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2036816751 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2036816893 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2036817326 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2036817381 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2036817768 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2036818019 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2036818182 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2036818253 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2036818486 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2036818775 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2036819178 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2036819261 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2036819551 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2036819806 |
| System info queried |
Type: BasicInformation |
success or wait |
2036819852 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2036820308 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2036820587 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2036820777 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90D76E Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2036821464 |
| System info queried |
Type: BasicInformation |
success or wait |
2036822061 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB76E20 Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2036822112 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2036822272 |
| Memory written |
PID: 1828 Path: C:\WINDOWS\system32\ctfmon.exe Base: A30000 Length: 4096 Value: 64
A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C
8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45
F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00
83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83
C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66
89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8
8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03
CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83
65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03
C3 8A
|
success or wait |
2036848522 |
| Thread created |
PID: 1636 TID: 3896 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
2036849043 |
| Memory attributes changed |
PID: 1828 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2036849363 |
| Memory written |
PID: 1828 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90CFEE Length: 5 Value: E9
BF 33 12 84
|
success or wait |
2036873800 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2036874397 |
| Thread created |
PID: 1636 TID: 3912 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
2036874832 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2036876446 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2036876589 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90DF1E Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2036876651 |
| System info queried |
Type: BasicInformation |
success or wait |
2036876790 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2036876921 |
| Memory allocated |
PID: 448 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 216FBA8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2036877456 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2036877822 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2036878261 |
| Memory attributes changed |
PID: 448 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2036878391 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2036878493 |
| Memory attributes changed |
PID: 448 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2036878706 |
| Memory attributes changed |
PID: 448 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2036878973 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2036879243 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2036879457 |
| Memory written |
PID: 448 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 286720 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00
00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00
00 10 00
|
success or wait |
2037985901 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2037987153 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2037987415 |
| Memory written |
PID: 448 Path: C:\WINDOWS\system32\svchost.exe Base: BADAFFC Length: 13 Value: B8
00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2038029443 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2038031624 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2038032514 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2038033730 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2038034608 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2038035008 |
| Memory allocated |
PID: 448 Path: C:\WINDOWS\system32\svchost.exe Base: A60000 Length: 216FBD8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2038035250 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2038036469 |
| System info queried |
Type: BasicInformation |
success or wait |
2038037029 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2038037795 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2038038501 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2038038680 |
| System info queried |
Type: BasicInformation |
success or wait |
2038040241 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2038041241 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2038041596 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2038041743 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2038042600 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90DF1E Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2038043862 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2038044359 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2038045004 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2038045880 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB90A90 Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2038046002 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90DC5E Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2038046562 |
| System info queried |
Type: BasicInformation |
success or wait |
2038047150 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2038047966 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2038048432 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2038048732 |
| System info queried |
Type: BasicInformation |
success or wait |
2038049461 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2038049927 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2038050479 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2038051365 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2038052469 |
| Memory written |
PID: 448 Path: C:\WINDOWS\system32\svchost.exe Base: A60000 Length: 4096 Value: 64
A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C
8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45
F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00
83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83
C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66
89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8
8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03
CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83
65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03
C3 8A
|
success or wait |
2038072122 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2038072708 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ntdll.dll |
success or wait |
2038073365 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2038073870 |
| Memory attributes changed |
PID: 448 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2038074233 |
| Memory written |
PID: 448 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 5 Value: E9
BF 33 15 84
|
success or wait |
2038117770 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2038118478 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2038120658 |
| Memory allocated |
PID: 508 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BAD0000 Length: 216FBA8
Allocation Type: null Protection: page execute and read and write
|
success or wait |
2038123722 |
| Memory attributes changed |
PID: 508 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BAD0000 Length: 46000
New Protection: page execute and read and write New Protection: page execute and read
and write
|
success or wait |
2038124754 |
| Memory attributes changed |
PID: 508 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BAD0000 Length: 46000
New Protection: page execute and read and write New Protection: page execute and read
and write
|
success or wait |
2038125567 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2038125757 |
| Memory attributes changed |
PID: 508 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BAD0000 Length: 46000
New Protection: page execute and read and write New Protection: page execute and read
and write
|
success or wait |
2038135134 |
| Memory written |
PID: 508 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BAD0000 Length: 286720
Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00
00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15
19 02 00 00 10 00
|
success or wait |
2041016773 |
| System info queried |
Type: BasicInformation |
success or wait |
2041019904 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2041020048 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2041020499 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2041022995 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2041024029 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2041024563 |
| Memory written |
PID: 508 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BADAFFC Length: 13 Value:
B8 00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2041067745 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90DC5E Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2041068346 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB7F2F8 Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2041069157 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90D2EE Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2041070228 |
| Memory allocated |
PID: 508 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 10A0000 Length: 216FBD8
Allocation Type: null Protection: page execute and read and write
|
success or wait |
2041070796 |
| System info queried |
Type: BasicInformation |
success or wait |
2041071206 |
| System info queried |
Type: BasicInformation |
success or wait |
2041071330 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2041071725 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2041072024 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2041072616 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2041073364 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2041076586 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2041077292 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2041079481 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2041079645 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2041080040 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2041080232 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2041082660 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2041083478 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2041085180 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2041085850 |
| System info queried |
Type: BasicInformation |
success or wait |
2041087060 |
| System info queried |
Type: BasicInformation |
success or wait |
2041087211 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2041087685 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2041088533 |
| Memory written |
PID: 508 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 10A0000 Length: 4096 Value:
64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40
1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89
45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C
00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00
83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58
66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45
F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10
03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3
83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00
03 C3 8A
|
success or wait |
2041107593 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90D2EE Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2041109226 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB7CF58 Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2041110047 |
| Memory attributes changed |
PID: 508 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7C90CFEE Length: 2000
New Protection: page execute and read and write New Protection: page execute read
|
success or wait |
2041110573 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90DB3E Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2041111172 |
| Memory written |
PID: 508 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7C90CFEE Length: 5 Value:
E9 BF 33 79 84
|
success or wait |
2041123675 |
| System info queried |
Type: BasicInformation |
success or wait |
2041124372 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2041125771 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2041127385 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2041129561 |
| Memory allocated |
PID: 1988 Path: C:\WINDOWS\system32\alg.exe Base: BAD0000 Length: 216FBA8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2041130005 |
| Memory attributes changed |
PID: 1988 Path: C:\WINDOWS\system32\alg.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2041130652 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2041131124 |
| Memory attributes changed |
PID: 1988 Path: C:\WINDOWS\system32\alg.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2041131285 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2041131754 |
| Memory attributes changed |
PID: 1988 Path: C:\WINDOWS\system32\alg.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2041132330 |
| Memory written |
PID: 1988 Path: C:\WINDOWS\system32\alg.exe Base: BAD0000 Length: 286720 Value: 4D
5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00 00
00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00 00
10 00
|
success or wait |
2042278152 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2042279538 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2042279641 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2042280976 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2042281151 |
| Memory written |
PID: 1988 Path: C:\WINDOWS\system32\alg.exe Base: BADAFFC Length: 13 Value: B8 00
00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2042298213 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2042303460 |
| Memory allocated |
PID: 1988 Path: C:\WINDOWS\system32\alg.exe Base: 990000 Length: 216FBD8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2042304362 |
| System info queried |
Type: BasicInformation |
success or wait |
2042304748 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2042305148 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2042305234 |
| System info queried |
Type: BasicInformation |
success or wait |
2042305936 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2042306217 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2042306602 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2042306895 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90DB3E Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2042307381 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2042307856 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2042308084 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB90168 Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2042308130 |
| Section loaded |
Path: \KnownDlls\nspr4.dll Access: write and read and execute Type: unknown Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
object name not found |
2042308728 |
| File opened |
Path: C:\Recycle.Bin\07A49F015E0D693 Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file Attributes: normal Content
Overwritten: false
|
success or wait |
2042310078 |
| File read |
Path: C:\Recycle.Bin\07A49F015E0D693 Offset: none Length: 5934 Value: 50 D7 96 D6
A6 EA BF F3 B7 FB 7B 65 8A 85 C9 85 C9 85 C9 85 C9 85 D8 95 D9 95 D3 9F FC B0 5F 82
BC 6E 9B 4E 30 D8 75 A5 B6 46 1F 53 16 3C E9 D5 6F 23 7C CC 40 C7 5F 13 5B 25 68 B6
F4 00 4A FB D0 8B 29 AA 5C 07 EB F8 69 F9 3F A6 F2 9C 1F 0D EA 9E F6 D2 0B 00 8E C4
6C EF 48 BA B7 4B DA AD F9 82 10 28
|
success or wait |
2042310803 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2042310990 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2042314924 |
| System info queried |
Type: BasicInformation |
success or wait |
2042316430 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2042316577 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E418BF6 Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2042317292 |
| System info queried |
Type: BasicInformation |
success or wait |
2042317524 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2042318140 |
| Memory written |
PID: 1988 Path: C:\WINDOWS\system32\alg.exe Base: 990000 Length: 4096 Value: 64 A1
18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B
40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4
8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83
C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2
04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89
45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B
45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB
66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65
FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3
8A
|
success or wait |
2042342459 |
| File opened |
Path: C:\WINDOWS\system32\USER32.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2042342697 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\user32.dll |
success or wait |
2042343286 |
| File read |
Path: C:\WINDOWS\system32\user32.dll Offset: none Length: 4 Value: D8 00 00 00 |
success or wait |
2042343635 |
| Memory attributes changed |
PID: 1988 Path: C:\WINDOWS\system32\alg.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2042343806 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\user32.dll |
success or wait |
2042343979 |
| Memory written |
PID: 1988 Path: C:\WINDOWS\system32\alg.exe Base: 7C90CFEE Length: 5 Value: E9 BF
33 08 84
|
success or wait |
2042365660 |
| File read |
Path: C:\WINDOWS\system32\user32.dll Offset: none Length: 20 Value: 4C 01 04 00 1B
A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2042366031 |
| Memory allocated |
PID: 236 Path: C:\WINDOWS\system32\wscntfy.exe Base: BAD0000 Length: 216FBA8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2042367183 |
| Memory attributes changed |
PID: 236 Path: C:\WINDOWS\system32\wscntfy.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2042367568 |
| File read |
Path: C:\WINDOWS\system32\user32.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
F4 05 00 00 E2 02 00 00 00 00 00 17 B2 00 00 00 10 00 00 00 B0 05 00 00 00 41 7E 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 10 09 00 00
04 00 00 76 FC 08 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 39 00 00
|
success or wait |
2042367653 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\user32.dll |
success or wait |
2042368077 |
| File read |
Path: C:\WINDOWS\system32\user32.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 83 F2 05 00 00 10 00 00 00 F4 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 80 11 00 00 00 10 06 00 00 0C 00 00 00
F8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 88
A0 02 00 00 30 06 00 00 A2 02 00
|
success or wait |
2042368408 |
| Memory attributes changed |
PID: 236 Path: C:\WINDOWS\system32\wscntfy.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2042368699 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\user32.dll |
success or wait |
2042369001 |
| Memory attributes changed |
PID: 236 Path: C:\WINDOWS\system32\wscntfy.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2042369067 |
| Section loaded |
Path: C:\WINDOWS\system32\user32.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 57344 Protection: readonly Mapped to pid: own pid
|
success or wait |
2042369296 |
| Memory written |
PID: 236 Path: C:\WINDOWS\system32\wscntfy.exe Base: BAD0000 Length: 286720 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00
00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00
00 10 00
|
success or wait |
2042954627 |
| Memory written |
PID: 236 Path: C:\WINDOWS\system32\wscntfy.exe Base: BADAFFC Length: 13 Value: B8
00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2042976636 |
| System info queried |
Type: BasicInformation |
success or wait |
2042976929 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2042977157 |
| Memory allocated |
PID: 236 Path: C:\WINDOWS\system32\wscntfy.exe Base: AE0000 Length: 216FBD8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2042977219 |
| System info queried |
Type: BasicInformation |
success or wait |
2042977637 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2042977989 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2042978645 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E418BF6 Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2042978703 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB7C210 Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2042978923 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D949088 Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2042979281 |
| System info queried |
Type: BasicInformation |
success or wait |
2042979756 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2042979813 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2042979996 |
| File opened |
Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file and random access
Attributes: none Content Overwritten: false
|
success or wait |
2042980298 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2042980503 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2042980832 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2042981393 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 4 Value: F8 00 00 00 |
success or wait |
2042981685 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2042981947 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2042982211 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 20 Value: 4C 01 04 00 D8
ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21
|
success or wait |
2042982420 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 224 Value: 0B 01 08 00
00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D
00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00
00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00
00 00 00 00 10 00 00 00 F8 18 00 00
|
success or wait |
2042982638 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2042982725 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2042983062 |
| System info queried |
Type: BasicInformation |
success or wait |
2042983563 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2042983749 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 160 Value: 2E 74 65 78
74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00
00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00
00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00
C0 61 02 00 00 80 0B 00 00 62 02 00
|
success or wait |
2042983803 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2042984507 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2042984749 |
| Memory written |
PID: 236 Path: C:\WINDOWS\system32\wscntfy.exe Base: AE0000 Length: 4096 Value: 64
A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C
8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45
F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00
83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83
C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66
89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8
8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03
CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83
65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03
C3 8A
|
success or wait |
2043009817 |
| System info queried |
Type: BasicInformation |
success or wait |
2043010029 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2043010304 |
| Memory attributes changed |
PID: 236 Path: C:\WINDOWS\system32\wscntfy.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2043010667 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D949088 Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2043011233 |
| Memory written |
PID: 236 Path: C:\WINDOWS\system32\wscntfy.exe Base: 7C90CFEE Length: 5 Value: E9
BF 33 1D 84
|
success or wait |
2043032539 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB90D98 Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2043032885 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D95EE89 Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2043033493 |
| System info queried |
Type: BasicInformation |
success or wait |
2043033925 |
| Memory allocated |
PID: 724 Path: C:\WINDOWS\system32\msiexec.exe Base: BAD0000 Length: 216FBA8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2043034033 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2043034224 |
| Memory attributes changed |
PID: 724 Path: C:\WINDOWS\system32\msiexec.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2043034274 |
| Memory attributes changed |
PID: 724 Path: C:\WINDOWS\system32\msiexec.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2043034542 |
| File opened |
Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file and random access
Attributes: none Content Overwritten: false
|
success or wait |
2043034813 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2043035391 |
| Memory attributes changed |
PID: 724 Path: C:\WINDOWS\system32\msiexec.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2043035516 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 4 Value: F8 00 00 00 |
success or wait |
2043035627 |
| Memory written |
PID: 724 Path: C:\WINDOWS\system32\msiexec.exe Base: BAD0000 Length: 286720 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00
00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00
00 10 00
|
success or wait |
2046818384 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2046819602 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2046819705 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2046820085 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2046821044 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 20 Value: 4C 01 04 00 D8
ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21
|
success or wait |
2046821446 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2046821643 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 224 Value: 0B 01 08 00
00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D
00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00
00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00
00 00 00 00 10 00 00 00 F8 18 00 00
|
success or wait |
2046822339 |
| Memory written |
PID: 724 Path: C:\WINDOWS\system32\msiexec.exe Base: BADAFFC Length: 13 Value: B8
00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2046844659 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2046845025 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 160 Value: 2E 74 65 78
74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00
00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00
00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00
C0 61 02 00 00 80 0B 00 00 62 02 00
|
success or wait |
2046845260 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2046845639 |
| Memory allocated |
PID: 724 Path: C:\WINDOWS\system32\msiexec.exe Base: 990000 Length: 216FBD8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2046845687 |
| System info queried |
Type: BasicInformation |
success or wait |
2046845970 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2046846611 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2046847101 |
| System info queried |
Type: BasicInformation |
success or wait |
2046847184 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2046847416 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2046848702 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2046848982 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D95EE89 Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2046849682 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2046852994 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB904E8 Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2046853264 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D94FABE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2046853546 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2046853699 |
| System info queried |
Type: BasicInformation |
success or wait |
2046853826 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2046854519 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2046854791 |
| File opened |
Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file and random access
Attributes: none Content Overwritten: false
|
success or wait |
2046855133 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2046855616 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2046855686 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 4 Value: F8 00 00 00 |
success or wait |
2046856363 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2046856659 |
| System info queried |
Type: BasicInformation |
success or wait |
2046856815 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 20 Value: 4C 01 04 00 D8
ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21
|
success or wait |
2046856904 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2046857064 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 224 Value: 0B 01 08 00
00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D
00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00
00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00
00 00 00 00 10 00 00 00 F8 18 00 00
|
success or wait |
2046857800 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2046858325 |
| Memory written |
PID: 724 Path: C:\WINDOWS\system32\msiexec.exe Base: 990000 Length: 4096 Value: 64
A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C
8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45
F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00
83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83
C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66
89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8
8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03
CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83
65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03
C3 8A
|
success or wait |
2046883525 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 160 Value: 2E 74 65 78
74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00
00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00
00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00
C0 61 02 00 00 80 0B 00 00 62 02 00
|
success or wait |
2046883818 |
| Memory attributes changed |
PID: 724 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2046884018 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2046884495 |
| Memory written |
PID: 724 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90CFEE Length: 5 Value: E9
BF 33 08 84
|
success or wait |
2046908266 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2046908468 |
| Memory allocated |
PID: 1120 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BAD0000 Length: 216FBA8
Allocation Type: null Protection: page execute and read and write
|
success or wait |
2046909842 |
| System info queried |
Type: BasicInformation |
success or wait |
2046909894 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2046910120 |
| Memory attributes changed |
PID: 1120 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BAD0000 Length: 46000
New Protection: page execute and read and write New Protection: page execute and read
and write
|
success or wait |
2046910733 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D94FABE Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2046911300 |
| Memory attributes changed |
PID: 1120 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BAD0000 Length: 46000
New Protection: page execute and read and write New Protection: page execute and read
and write
|
success or wait |
2046911368 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB765C8 Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2046911539 |
| Memory attributes changed |
PID: 1120 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BAD0000 Length: 46000
New Protection: page execute and read and write New Protection: page execute and read
and write
|
success or wait |
2046911674 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D9A608E Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2046912367 |
| Memory written |
PID: 1120 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BAD0000 Length: 286720
Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00
00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15
19 02 00 00 10 00
|
success or wait |
2048438697 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2048439548 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2048439650 |
| System info queried |
Type: BasicInformation |
success or wait |
2048440021 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2048441004 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2048441844 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2048442109 |
| File opened |
Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file and random access
Attributes: none Content Overwritten: false
|
success or wait |
2048442377 |
| Memory written |
PID: 1120 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BADAFFC Length: 13 Value:
B8 00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2048465599 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2048465976 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 4 Value: F8 00 00 00 |
success or wait |
2048466195 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2048466459 |
| Memory allocated |
PID: 1120 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: C00000 Length: 216FBD8
Allocation Type: null Protection: page execute and read and write
|
success or wait |
2048466566 |
| System info queried |
Type: BasicInformation |
success or wait |
2048466974 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2048467278 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 20 Value: 4C 01 04 00 D8
ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21
|
success or wait |
2048467337 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 224 Value: 0B 01 08 00
00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D
00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00
00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00
00 00 00 00 10 00 00 00 F8 18 00 00
|
success or wait |
2048467568 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2048467940 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2048468074 |
| File read |
Path: C:\WINDOWS\system32\wininet.dll Offset: none Length: 160 Value: 2E 74 65 78
74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00
00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00
00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00
C0 61 02 00 00 80 0B 00 00 62 02 00
|
success or wait |
2048468615 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2048468678 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\wininet.dll |
success or wait |
2048468939 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2048469189 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2048469638 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2048469870 |
| System info queried |
Type: BasicInformation |
success or wait |
2048470307 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2048470615 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2048470989 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D9A608E Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2048471823 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: BB7F660 Length: 2000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2048472114 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2048472246 |
| System info queried |
Type: BasicInformation |
success or wait |
2048472956 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 71AB4C27 Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2048473015 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2048473909 |
| File opened |
Path: C:\WINDOWS\system32\WS2_32.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2048474558 |
| Memory written |
PID: 1120 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: C00000 Length: 4096 Value:
64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40
1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89
45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C
00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00
83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58
66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45
F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10
03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3
83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00
03 C3 8A
|
success or wait |
2048498360 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ws2_32.dll |
success or wait |
2048498684 |
| File read |
Path: C:\WINDOWS\system32\ws2_32.dll Offset: none Length: 4 Value: F0 00 00 00 |
success or wait |
2048498939 |
| Memory attributes changed |
PID: 1120 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90CFEE Length: 2000
New Protection: page execute and read and write New Protection: page execute read
|
success or wait |
2048499139 |
| Memory written |
PID: 1120 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90CFEE Length: 5 Value:
E9 BF 33 2F 84
|
success or wait |
2048594433 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ws2_32.dll |
success or wait |
2048594507 |
| File read |
Path: C:\WINDOWS\system32\ws2_32.dll Offset: none Length: 20 Value: 4C 01 04 00 63
A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2048595003 |
| File read |
Path: C:\WINDOWS\system32\ws2_32.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
22 01 00 00 1C 00 00 00 00 00 00 73 12 00 00 00 10 00 00 00 20 01 00 00 00 AB 71 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 70 01 00 00
04 00 00 20 F0 01 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 04 14 00 00
|
success or wait |
2048595307 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ws2_32.dll |
success or wait |
2048595874 |
| Memory allocated |
PID: 2000 Path: C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
Base: BAD0000 Length: 216FBA8 Allocation Type: null Protection: page execute and read
and write
|
success or wait |
2048596330 |
| File read |
Path: C:\WINDOWS\system32\ws2_32.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 53 21 01 00 00 10 00 00 00 22 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 14 09 00 00 00 40 01 00 00 0A 00 00 00
26 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 F8
03 00 00 00 50 01 00 00 04 00 00
|
success or wait |
2048596430 |
| Memory attributes changed |
PID: 2000 Path: C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
Base: BAD0000 Length: 46000 New Protection: page execute and read and write New Protection:
page execute and read and write
|
success or wait |
2048596651 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\ws2_32.dll |
success or wait |
2048596821 |
| Section loaded |
Path: C:\WINDOWS\system32\ws2_32.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 20480 Protection: readonly Mapped to pid: own pid
|
success or wait |
2048597090 |
| Memory attributes changed |
PID: 2000 Path: C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
Base: BAD0000 Length: 46000 New Protection: page execute and read and write New Protection:
page execute and read and write
|
success or wait |
2048597789 |
| Memory attributes changed |
PID: 2000 Path: C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
Base: BAD0000 Length: 46000 New Protection: page execute and read and write New Protection:
page execute and read and write
|
success or wait |
2048598038 |
| Memory written |
PID: 2000 Path: C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
Base: BAD0000 Length: 286720 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00
B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00
4C 01 02 00 9D 80 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00
00 1E 00 00 00 00 00 00 15 19 02 00 00 10 00
|
success or wait |
2049051522 |
| Memory written |
PID: 2000 Path: C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
Base: BADAFFC Length: 13 Value: B8 00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2049074297 |
| Memory allocated |
PID: 2000 Path: C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
Base: 650000 Length: 216FBD8 Allocation Type: null Protection: page execute and read
and write
|
success or wait |
2049075091 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2049076666 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2049077286 |
| File opened |
Path: C:\WINDOWS\system32\ADVAPI32.dll Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file and random access
Attributes: none Content Overwritten: false
|
success or wait |
2049077376 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\advapi32.dll |
success or wait |
2049077942 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2049078376 |
| File read |
Path: C:\WINDOWS\system32\advapi32.dll Offset: none Length: 4 Value: F0 00 00 00 |
success or wait |
2049078513 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2049078689 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\advapi32.dll |
success or wait |
2049078851 |
| File read |
Path: C:\WINDOWS\system32\advapi32.dll Offset: none Length: 20 Value: 4C 01 04 00
48 1D 90 49 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2049079197 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2049079822 |
| File read |
Path: C:\WINDOWS\system32\advapi32.dll Offset: none Length: 224 Value: 0B 01 07 0A
00 46 07 00 00 3E 02 00 00 00 00 00 0B 71 00 00 00 10 00 00 00 20 07 00 00 00 DD 77
00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 B0 09 00
00 04 00 00 B8 5B 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00
00 00 00 00 10 00 00 00 A4 16 00 00
|
success or wait |
2049079925 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\advapi32.dll |
success or wait |
2049080322 |
| File read |
Path: C:\WINDOWS\system32\advapi32.dll Offset: none Length: 160 Value: 2E 74 65 78
74 00 00 00 C9 45 07 00 00 10 00 00 00 46 07 00 00 04 00 00 00 00 00 00 00 00 00 00
00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 28 46 00 00 00 60 07 00 00 2C 00 00
00 4A 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00
80 A9 01 00 00 B0 07 00 00 AA 01 00
|
success or wait |
2049080588 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2049080828 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\advapi32.dll |
success or wait |
2049081301 |
| Section loaded |
Path: C:\WINDOWS\system32\advapi32.dll Access: query and read Type: commit Baseaddress:
1FC0000 Size: 28672 Protection: readonly Mapped to pid: own pid
|
success or wait |
2049081548 |
| Memory written |
PID: 2000 Path: C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
Base: 650000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00
64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59
89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72
00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00
64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18
89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4
50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43
3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C
8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83
79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A
|
success or wait |
2049107123 |
| Memory attributes changed |
PID: 2000 Path: C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection:
page execute read
|
success or wait |
2049107742 |
| Memory written |
PID: 2000 Path: C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
Base: 7C90CFEE Length: 5 Value: E9 BF 33 D4 83
|
success or wait |
2049128706 |
| Memory allocated |
PID: 2224 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base:
BAD0000 Length: 216FBA8 Allocation Type: null Protection: page execute and read and
write
|
success or wait |
2049130378 |
| Memory attributes changed |
PID: 2224 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base:
BAD0000 Length: 46000 New Protection: page execute and read and write New Protection:
page execute and read and write
|
success or wait |
2049131005 |
| File opened |
Path: C:\WINDOWS\system32\CRYPT32.dll Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file and random access
Attributes: none Content Overwritten: false
|
success or wait |
2049131131 |
| Memory attributes changed |
PID: 2224 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base:
BAD0000 Length: 46000 New Protection: page execute and read and write New Protection:
page execute and read and write
|
success or wait |
2049131339 |
| Memory attributes changed |
PID: 2224 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base:
BAD0000 Length: 46000 New Protection: page execute and read and write New Protection:
page execute and read and write
|
success or wait |
2049131568 |
| Memory written |
PID: 2224 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base:
BAD0000 Length: 286720 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00
00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01
02 00 9D 80 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E
00 00 00 00 00 00 15 19 02 00 00 10 00
|
success or wait |
2049928956 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\crypt32.dll |
success or wait |
2049929881 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2049929927 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2049930030 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2049930993 |
| File read |
Path: C:\WINDOWS\system32\crypt32.dll Offset: none Length: 4 Value: F0 00 00 00 |
success or wait |
2049931384 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2049931594 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\crypt32.dll |
success or wait |
2049932305 |
| Memory written |
PID: 2224 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base:
BADAFFC Length: 13 Value: B8 00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2049955286 |
| File read |
Path: C:\WINDOWS\system32\crypt32.dll Offset: none Length: 20 Value: 4C 01 04 00 D7
A0 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2049955351 |
| File read |
Path: C:\WINDOWS\system32\crypt32.dll Offset: none Length: 224 Value: 0B 01 07 0A
00 44 08 00 00 DC 00 00 00 00 00 00 32 16 00 00 00 10 00 00 00 20 08 00 00 00 A8 77
00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 50 09 00
00 04 00 00 30 C5 09 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00
00 00 00 00 10 00 00 00 9C 1A 00 00
|
success or wait |
2049955577 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\crypt32.dll |
success or wait |
2049955955 |
| Memory allocated |
PID: 2224 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base:
8F0000 Length: 216FBD8 Allocation Type: null Protection: page execute and read and
write
|
success or wait |
2049956149 |
| File read |
Path: C:\WINDOWS\system32\crypt32.dll Offset: none Length: 160 Value: 2E 74 65 78
74 00 00 00 C4 43 08 00 00 10 00 00 00 44 08 00 00 04 00 00 00 00 00 00 00 00 00 00
00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 E8 23 00 00 00 60 08 00 00 24 00 00
00 48 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00
50 67 00 00 00 90 08 00 00 68 00 00
|
success or wait |
2049956310 |
| File other operation |
Disposition: PositionInformation Data : Offset: 60 Path: C:\WINDOWS\system32\crypt32.dll |
success or wait |
2049956601 |
| Section loaded |
Path: C:\WINDOWS\system32\crypt32.dll Access: query and read Type: commit Baseaddress:
2950000 Size: 77824 Protection: readonly Mapped to pid: own pid
|
success or wait |
2049956857 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2049957124 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2049957888 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2049959053 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2049959577 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2049960369 |
| Mutant created |
Name: \BaseNamedObjects\Global\25LSmN0q5Cx8k1GCFvMKe5z0i3US0DM |
object name exists |
2049960831 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1F70000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2049962008 |
| Thread created |
PID: 1636 TID: 924 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
2049962655 |
| Memory written |
PID: 2224 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base:
8F0000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1
30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45
F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E
00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00
83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45
E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83
E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B
4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04
81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18
00 76 3F 8B 06 83 65 F8 00 03 C3 8A
|
success or wait |
2049994890 |
| Memory attributes changed |
PID: 2224 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base:
7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection:
page execute read
|
success or wait |
2050001319 |
| Memory written |
PID: 2224 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base:
7C90CFEE Length: 5 Value: E9 BF 33 FE 83
|
success or wait |
2050023580 |
| Memory allocated |
PID: 2264 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 216FBA8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2050025238 |
| Memory attributes changed |
PID: 2264 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2050025374 |
| Memory attributes changed |
PID: 2264 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2050025519 |
| Memory attributes changed |
PID: 2264 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 46000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
2050026536 |
| Memory written |
PID: 2264 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 286720 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 9D 80 86 4E 00 00 00 00
00 00 00 00 E0 00 02 01 0B 01 0A 00 00 26 04 00 00 1E 00 00 00 00 00 00 15 19 02 00
00 10 00
|
success or wait |
2051526728 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2051535280 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2051535763 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2051538744 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2051540013 |
| Memory written |
PID: 2264 Path: C:\WINDOWS\system32\svchost.exe Base: BADAFFC Length: 13 Value: B8
00 00 00 00 50 BA B0 15 AF 0B FF D2
|
success or wait |
2051583768 |
| Memory allocated |
PID: 2264 Path: C:\WINDOWS\system32\svchost.exe Base: 9A0000 Length: 216FBD8 Allocation
Type: null Protection: page execute and read and write
|
success or wait |
2051586301 |
| File opened |
Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
none Content Overwritten: false
|
success or wait |
2051587213 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 4 Value: D0 00 00 00 |
success or wait |
2051591753 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 20 Value: 4C 01 04 00 7D
F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
2051592339 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 224 Value: 0B 01 07 0A 00
D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00
10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00
04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00
00 00 00 10 00 00 00 00 34 00 00
|
success or wait |
2051592615 |
| File read |
Path: C:\WINDOWS\system32\ntdll.dll Offset: none Length: 160 Value: 2E 74 65 78 74
00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00
00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00
D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78
BE 02 00 00 30 08 00 00 C0 02 00
|
success or wait |
2051595349 |
| Section loaded |
Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress:
1F70000 Size: 65536 Protection: readonly Mapped to pid: own pid
|
success or wait |
2051596126 |
| Memory written |
PID: 2264 Path: C:\WINDOWS\system32\svchost.exe Base: 9A0000 Length: 4096 Value: 64
A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C
8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45
F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00
83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83
C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66
89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8
8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03
CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83
65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03
C3 8A
|
success or wait |
2051644504 |
| Memory attributes changed |
PID: 2264 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
2051647226 |
| Memory written |
PID: 2264 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 5 Value: E9
BF 33 09 84
|
success or wait |
2051705888 |
| File opened |
Path: C:\Recycle.Bin\07A49F015E0D693 Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file Attributes: normal Content
Overwritten: false
|
success or wait |
2051713318 |
| File read |
Path: C:\Recycle.Bin\07A49F015E0D693 Offset: none Length: 5934 Value: 50 D7 96 D6
A6 EA BF F3 B7 FB 7B 65 8A 85 C9 85 C9 85 C9 85 C9 85 D8 95 D9 95 D3 9F FC B0 5F 82
BC 6E 9B 4E 30 D8 75 A5 B6 46 1F 53 16 3C E9 D5 6F 23 7C CC 40 C7 5F 13 5B 25 68 B6
F4 00 4A FB D0 8B 29 AA 5C 07 EB F8 69 F9 3F A6 F2 9C 1F 0D EA 9E F6 D2 0B 00 8E C4
6C EF 48 BA B7 4B DA AD F9 82 10 28
|
success or wait |
2051714256 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1F70000 Length: 216FA60 Allocation Type:
null Protection: page execute and read and write
|
success or wait |
2051725641 |
| Thread created |
PID: 1636 TID: 2196 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
2051730554 |
| Thread created |
PID: 1636 TID: 2188 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
2051735329 |
| Thread created |
PID: 1636 TID: 2192 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
2051738031 |
| File opened |
Path: C:\Recycle.Bin\07A49F015E0D693 Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file and random access Attributes:
normal Content Overwritten: false
|
success or wait |
2051756116 |
| File other operation |
Disposition: PositionInformation Data : Offset: 5930 Path: C:\Recycle.Bin\07A49F015E0D693 |
success or wait |
2051760722 |
| File read |
Path: C:\Recycle.Bin\07A49F015E0D693 Offset: none Length: 4 Value: 03 12 C0 79 |
success or wait |
2051760945 |
| File opened |
Path: C:\Recycle.Bin\B6232F3AC2C.exe Access: read attributes and synchronize and generic
write Options: synchronous io non alert and non directory file Attributes: normal
Content Overwritten: false
|
success or wait |
2051761615 |
| File read |
Path: C:\Recycle.Bin\B6232F3AC2C.exe Offset: none Length: 254976 Value: 4D 5A 90 00
03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 01 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72
61 6D 20 63 61 6E 6E 6F 74 20 62 65
|
success or wait |
2051764189 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2052191213 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2052192331 |
| Section loaded |
Path: C:\WINDOWS\system32\mswsock.dll Access: write and read and execute Type: commit
Baseaddress: 2950000 Size: 245760 Protection: execute Mapped to pid: own pid
|
success or wait |
2052224097 |
| Section loaded |
Path: C:\WINDOWS\system32\mswsock.dll Access: query and write and read and execute
Type: image Baseaddress: 71A50000 Size: 258048 Protection: read write Mapped to pid:
own pid
|
success or wait |
2052228982 |
| Section loaded |
Path: \KnownDlls\DNSAPI.dll Access: write and read and execute Type: unknown Baseaddress:
71A50000 Size: 258048 Protection: read write Mapped to pid: own pid
|
object name not found |
2052253823 |
| Section loaded |
Path: C:\WINDOWS\system32\dnsapi.dll Access: query and write and read and execute
Type: image Baseaddress: 76F20000 Size: 159744 Protection: read write Mapped to pid:
own pid
|
success or wait |
2052255717 |
| Section loaded |
Path: C:\WINDOWS\system32\winrnr.dll Access: write and read and execute Type: commit
Baseaddress: 1F80000 Size: 20480 Protection: execute Mapped to pid: own pid
|
success or wait |
2052368242 |
| Section loaded |
Path: C:\WINDOWS\system32\winrnr.dll Access: query and write and read and execute
Type: image Baseaddress: 76FB0000 Size: 32768 Protection: read write Mapped to pid:
own pid
|
success or wait |
2052371398 |
| Section loaded |
Path: \KnownDlls\rasadhlp.dll Access: write and read and execute Type: unknown Baseaddress:
76FB0000 Size: 32768 Protection: read write Mapped to pid: own pid
|
object name not found |
2052388703 |
| Section loaded |
Path: C:\WINDOWS\system32\rasadhlp.dll Access: query and write and read and execute
Type: image Baseaddress: 76FC0000 Size: 24576 Protection: read write Mapped to pid:
own pid
|
success or wait |
2052390200 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2052448067 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2052448854 |
| Section loaded |
Path: \KnownDlls\RASAPI32.dll Access: write and read and execute Type: unknown Baseaddress:
2A10000 Size: 942080 Protection: readonly Mapped to pid: own pid
|
object name not found |
2052469085 |
| Section loaded |
Path: C:\WINDOWS\system32\rasapi32.dll Access: query and write and read and execute
Type: image Baseaddress: 76EE0000 Size: 245760 Protection: read write Mapped to pid:
own pid
|
success or wait |
2052471065 |
| Section loaded |
Path: \KnownDlls\rasman.dll Access: write and read and execute Type: unknown Baseaddress:
76EE0000 Size: 245760 Protection: read write Mapped to pid: own pid
|
object name not found |
2052485637 |
| Section loaded |
Path: C:\WINDOWS\system32\rasman.dll Access: query and write and read and execute
Type: image Baseaddress: 76E90000 Size: 73728 Protection: read write Mapped to pid:
own pid
|
success or wait |
2052490021 |
| Section loaded |
Path: \KnownDlls\TAPI32.dll Access: write and read and execute Type: unknown Baseaddress:
76E90000 Size: 73728 Protection: read write Mapped to pid: own pid
|
object name not found |
2052508116 |
| Section loaded |
Path: C:\WINDOWS\system32\tapi32.dll Access: query and write and read and execute
Type: image Baseaddress: 76EB0000 Size: 192512 Protection: read write Mapped to pid:
own pid
|
success or wait |
2052510129 |
| Section loaded |
Path: C:\WINDOWS\system32\tapi32.dll Access: read Type: commit Baseaddress: 2950000
Size: 184320 Protection: readonly Mapped to pid: own pid
|
success or wait |
2052555137 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2052645825 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2052646348 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2052648767 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2052650601 |
| Section loaded |
Path: \KnownDlls\sensapi.dll Access: write and read and execute Type: unknown Baseaddress:
2950000 Size: 184320 Protection: readonly Mapped to pid: own pid
|
object name not found |
2052870621 |
| Section loaded |
Path: C:\WINDOWS\system32\sensapi.dll Access: query and write and read and execute
Type: image Baseaddress: 722B0000 Size: 20480 Protection: read write Mapped to pid:
own pid
|
success or wait |
2052874690 |
| Section loaded |
Path: \KnownDlls\msapsspc.dll Access: write and read and execute Type: unknown Baseaddress:
722B0000 Size: 20480 Protection: read write Mapped to pid: own pid
|
object name not found |
2052896609 |
| Section loaded |
Path: C:\WINDOWS\system32\msapsspc.dll Access: query and write and read and execute
Type: image Baseaddress: 71E50000 Size: 86016 Protection: read write Mapped to pid:
own pid
|
success or wait |
2052901557 |
| Section loaded |
Path: \KnownDlls\MSVCRT40.dll Access: write and read and execute Type: unknown Baseaddress:
71E50000 Size: 86016 Protection: read write Mapped to pid: own pid
|
object name not found |
2052908035 |
| Section loaded |
Path: C:\WINDOWS\system32\msvcrt40.dll Access: query and write and read and execute
Type: image Baseaddress: 78080000 Size: 69632 Protection: read write Mapped to pid:
own pid
|
success or wait |
2052911266 |
| Section loaded |
Path: \BaseNamedObjects\SENS Information Cache Access: read Type: unknown Baseaddress:
1FA0000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
2052959015 |
| Section loaded |
Path: \KnownDlls\schannel.dll Access: write and read and execute Type: unknown Baseaddress:
1FA0000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
object name not found |
2052971127 |
| Section loaded |
Path: C:\WINDOWS\system32\schannel.dll Access: query and write and read and execute
Type: image Baseaddress: 767F0000 Size: 163840 Protection: read write Mapped to pid:
own pid
|
success or wait |
2052972888 |
| Section loaded |
Path: \KnownDlls\digest.dll Access: write and read and execute Type: unknown Baseaddress:
767F0000 Size: 163840 Protection: read write Mapped to pid: own pid
|
object name not found |
2053036336 |
| Section loaded |
Path: C:\WINDOWS\system32\digest.dll Access: query and write and read and execute
Type: image Baseaddress: 75B00000 Size: 86016 Protection: read write Mapped to pid:
own pid
|
success or wait |
2053046139 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2053080117 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2053081545 |
| Section loaded |
Path: \KnownDlls\msnsspc.dll Access: write and read and execute Type: unknown Baseaddress:
75B00000 Size: 86016 Protection: read write Mapped to pid: own pid
|
object name not found |
2053081856 |
| Section loaded |
Path: C:\WINDOWS\system32\msnsspc.dll Access: query and write and read and execute
Type: image Baseaddress: 747B0000 Size: 290816 Protection: read write Mapped to pid:
own pid
|
success or wait |
2053090410 |
| Section loaded |
Path: \KnownDlls\MSVCRT40.dll Access: write and read and execute Type: unknown Baseaddress:
747B0000 Size: 290816 Protection: read write Mapped to pid: own pid
|
object name not found |
2053097858 |
| Section loaded |
Path: C:\WINDOWS\system32\msvcrt40.dll Access: query and write and read and execute
Type: image Baseaddress: 78080000 Size: 69632 Protection: read write Mapped to pid:
own pid
|
success or wait |
2053099935 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2053125457 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2053126248 |
| Section loaded |
Path: C:\WINDOWS\system32\msv1_0.dll Access: write and read and execute Type: commit
Baseaddress: 2950000 Size: 139264 Protection: execute Mapped to pid: own pid
|
success or wait |
2053185329 |
| Section loaded |
Path: C:\WINDOWS\system32\msv1_0.dll Access: query and write and read and execute
Type: image Baseaddress: 77C70000 Size: 151552 Protection: read write Mapped to pid:
own pid
|
success or wait |
2053194147 |
| Section loaded |
Path: \KnownDlls\cryptdll.dll Access: write and read and execute Type: unknown Baseaddress:
77C70000 Size: 151552 Protection: read write Mapped to pid: own pid
|
object name not found |
2053210628 |
| Section loaded |
Path: C:\WINDOWS\system32\cryptdll.dll Access: query and write and read and execute
Type: image Baseaddress: 76790000 Size: 49152 Protection: read write Mapped to pid:
own pid
|
success or wait |
2053217450 |
| Section loaded |
Path: \KnownDlls\MPRAPI.dll Access: write and read and execute Type: unknown Baseaddress:
76790000 Size: 49152 Protection: read write Mapped to pid: own pid
|
object name not found |
2053496783 |
| Section loaded |
Path: C:\WINDOWS\system32\mprapi.dll Access: query and write and read and execute
Type: image Baseaddress: 76D40000 Size: 98304 Protection: read write Mapped to pid:
own pid
|
success or wait |
2053500947 |
| Section loaded |
Path: \KnownDlls\ACTIVEDS.dll Access: write and read and execute Type: unknown Baseaddress:
76D40000 Size: 98304 Protection: read write Mapped to pid: own pid
|
object name not found |
2053514563 |
| Section loaded |
Path: C:\WINDOWS\system32\activeds.dll Access: query and write and read and execute
Type: image Baseaddress: 77CC0000 Size: 204800 Protection: read write Mapped to pid:
own pid
|
success or wait |
2053520460 |
| Section loaded |
Path: \KnownDlls\adsldpc.dll Access: write and read and execute Type: unknown Baseaddress:
77CC0000 Size: 204800 Protection: read write Mapped to pid: own pid
|
object name not found |
2053528764 |
| Section loaded |
Path: C:\WINDOWS\system32\adsldpc.dll Access: query and write and read and execute
Type: image Baseaddress: 76E10000 Size: 151552 Protection: read write Mapped to pid:
own pid
|
success or wait |
2053533991 |
| Section loaded |
Path: \KnownDlls\hnetcfg.dll Access: write and read and execute Type: unknown Baseaddress:
76E10000 Size: 151552 Protection: read write Mapped to pid: own pid
|
object name not found |
2053641999 |
| Section loaded |
Path: C:\WINDOWS\system32\hnetcfg.dll Access: query and write and read and execute
Type: image Baseaddress: 662B0000 Size: 360448 Protection: read write Mapped to pid:
own pid
|
success or wait |
2053644244 |
| Section loaded |
Path: C:\WINDOWS\system32\wshtcpip.dll Access: write and read and execute Type: commit
Baseaddress: 2960000 Size: 20480 Protection: execute Mapped to pid: own pid
|
success or wait |
2053682090 |
| Section loaded |
Path: C:\WINDOWS\system32\wshtcpip.dll Access: query and write and read and execute
Type: image Baseaddress: 71A90000 Size: 32768 Protection: read write Mapped to pid:
own pid
|
success or wait |
2053689718 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2053765945 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2053766216 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2053768445 |
| Thread delayed |
Time: 0 TID: 4214 |
success or wait |
2053769820 |
| File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\profiles.ini
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: normal Content Overwritten: false
|
object name not found |
2053832341 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2077616092 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2077617059 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2077618890 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2077628323 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2077688542 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2077694458 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2077716296 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2077724477 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2077726408 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2077727299 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2105181057 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2105181961 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2105186793 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2105188019 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2106050990 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2106062448 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2106064892 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2106065760 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2106141651 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2106142943 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2106146130 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2106147197 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2106173327 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2106174496 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2106269444 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2106270267 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2106530383 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2106531538 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2106534722 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2106535513 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2106834743 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2106836002 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2106839763 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2106840663 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2106843147 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2106843932 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2106929386 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2106931102 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2107703898 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2107704731 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2107708174 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2107708975 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2107711363 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2107712149 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2107714611 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2107715317 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2107717398 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2107718185 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2107720565 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2107721354 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2107723432 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2107724219 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2107726547 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2107727332 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2107729482 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2107730270 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2108251639 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2108254055 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2108260981 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2108262331 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2108266115 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2108267075 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2108269502 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2108270286 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2108330747 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2108332558 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2108337032 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2108338179 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2108429455 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2108430171 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2108541181 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2108541970 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2108798383 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2108799196 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2108812811 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2108813610 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2108883421 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2108884227 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2108889101 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2108889893 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2109007279 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2109008125 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2110281978 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2110286620 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2110288190 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2110288519 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2110289801 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2110290170 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2110291213 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2110291539 |
| File opened |
Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options:
synchronous io non alert and non directory file and random access
|
success or wait |
2110292393 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2110292718 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2110294005 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2110576007 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2110642959 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2110644098 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2110709174 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2110710935 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2110785210 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2110801523 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2111548591 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2111550471 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2111551484 |
| Thread delayed |
Time: 80 TID: 8584 |
success or wait |
2111552008 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2397920540 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2397934441 |
| Section loaded |
Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute
and extend size Type: image Baseaddress: 2A10000 Size: 942080 Protection: readonly
Mapped to pid: own pid
|
image not at base |
2397937349 |