| Operation |
Data |
Completion |
Time |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2950000 Length: 294F6A8 Allocation Type:
null Protection: page read and write
|
success or wait |
1986859950 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2950000 Length: 294F6AC Allocation Type:
null Protection: page read and write
|
success or wait |
1986860194 |
| File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Qiokze\pauz.dat Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
object name not found |
1986869838 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Internet
Explorer\PhishingFilter Name: Enabled
|
object name not found |
1986870593 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Internet
Explorer\PhishingFilter Name: EnabledV8
|
success or wait |
1986871107 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Internet
Explorer\PhishingFilter Name: EnabledV8 Type: Dword Data: 0
|
success or wait |
1986872392 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Internet
Explorer\Privacy Name: CleanCookies Type: Dword Data: 0
|
success or wait |
1986876122 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Internet
Explorer\Privacy Name: 1406
|
success or wait |
1986877541 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Internet
Explorer\Privacy Name: 1609
|
success or wait |
1986878065 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\0 Name: 1609 Type: Dword Data: 0
|
success or wait |
1986879161 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\0 Name: 1406
|
success or wait |
1986880441 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\1 Name: 1406 Type: Dword Data: 0
|
success or wait |
1986881525 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\1 Name: 1609
|
success or wait |
1986881980 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\1 Name: 1609 Type: Dword Data: 0
|
success or wait |
1986883162 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\1 Name: 1406
|
success or wait |
1986883636 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\2 Name: 1406 Type: Dword Data: 0
|
success or wait |
1986884880 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\2 Name: 1609
|
success or wait |
1986886282 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\2 Name: 1609 Type: Dword Data: 0
|
success or wait |
1986887531 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\2 Name: 1406
|
success or wait |
1986888002 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\3 Name: 1406 Type: Dword Data: 0
|
success or wait |
1986889065 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\3 Name: 1609
|
success or wait |
1986890278 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\3 Name: 1609 Type: Dword Data: 0
|
success or wait |
1986891357 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\3 Name: 1406
|
success or wait |
1986891824 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\4 Name: 1406 Type: Dword Data: 0
|
success or wait |
1986892897 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\4 Name: 1609
|
success or wait |
1986893348 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\4 Name: 1609 Type: Dword Data: 0
|
success or wait |
1986894427 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 294F47C Allocation Type:
null Protection: page execute and read and write
|
success or wait |
1986895226 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90D1AE Length: 1000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
1986896048 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90D1AE Length: 30 Value: B8 35 00
00 00 BA 00 03 FE 7F FF 12 C2 20 00 90 B8 36 00 00 00 BA 00 03 FE 7F FF 12 C2 10
|
success or wait |
1986896318 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986896596 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986896849 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 10 Value: B8 35 00 00
00 E9 A9 D1 0F 7B
|
success or wait |
1986897140 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90D1AE Length: 1000 New Protection:
page execute and read and write New Protection: page execute and write copy
|
success or wait |
1986897409 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90D000 Length: 1000 New Protection:
page execute and write copy New Protection: page execute and write copy
|
success or wait |
1986897673 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90D1AE Length: 5 Value: E9 33 B7 66
85
|
success or wait |
1986897963 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C90D1AE Length: 1000 New Protection:
page execute read New Protection: page execute and read and write
|
success or wait |
1986898244 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C91632D Length: 1000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
1986899042 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C91632D Length: 30 Value: 68 6C 02
00 00 68 80 64 91 7C E8 8F 85 FF FF A1 C8 E0 97 7C 89 45 E4 8B 45 08 89 85 B4 FD
|
success or wait |
1986899303 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 181000A Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986899643 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986899912 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 181000A Length: 10 Value: 68 6C 02 00
00 E9 1E 63 10 7B
|
success or wait |
1986900210 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C91632D Length: 1000 New Protection:
page execute and read and write New Protection: page execute and write copy
|
success or wait |
1986900447 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C916000 Length: 1000 New Protection:
page execute and write copy New Protection: page execute and write copy
|
success or wait |
1986900709 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C91632D Length: 5 Value: E9 94 27 66
85
|
success or wait |
1986900999 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C91632D Length: 1000 New Protection:
page execute read New Protection: page execute and read and write
|
success or wait |
1986901277 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C811195 Length: 1000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
1986901932 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C811195 Length: 30 Value: 8B FF 55
8B EC 83 EC 64 83 7D 0C 01 56 57 0F 8D 13 AE 01 00 33 F6 39 75 0C 0F 8C 08 AE 01
|
success or wait |
1986902192 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810014 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986902467 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986902730 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810014 Length: 10 Value: 8B FF 55 8B
EC E9 7C 11 00 7B
|
success or wait |
1986903025 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C811195 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and write copy
|
success or wait |
1986903262 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C811000 Length: 1000 New Protection:
page execute and write copy New Protection: page execute and write copy
|
success or wait |
1986903524 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C811195 Length: 5 Value: E9 CE 79 76
85
|
success or wait |
1986903814 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7C811195 Length: 1000 New Protection:
page execute read New Protection: page execute and read and write
|
success or wait |
1986904092 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D94FABE Length: 1000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
1986905257 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D94FABE Length: 30 Value: 8B FF 55
8B EC 51 51 53 56 33 DB 57 33 F6 33 FF 39 5D 08 89 5D FC 89 5D F8 0F 84 2A EB 03
|
success or wait |
1986905518 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 181001E Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986905793 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986906055 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 181001E Length: 10 Value: 8B FF 55 8B
EC E9 9B FA 13 3C
|
success or wait |
1986906350 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D94FABE Length: 1000 New Protection:
page execute and read and write New Protection: page execute and write copy
|
success or wait |
1986906585 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D94F000 Length: 1000 New Protection:
page execute and write copy New Protection: page execute and write copy
|
success or wait |
1986906847 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D94FABE Length: 5 Value: E9 97 45 63
C4
|
success or wait |
1986907136 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D94FABE Length: 1000 New Protection:
page execute read New Protection: page execute and read and write
|
success or wait |
1986907415 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D95EE89 Length: 1000 New Protection:
page execute and read and write New Protection: page execute read
|
success or wait |
1986908509 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D95EE89 Length: 30 Value: 8B FF 55
8B EC 6A 10 6A 00 FF 75 18 FF 75 14 FF 75 10 FF 75 0C FF 75 08 E8 19 FD FE FF 5D
|
success or wait |
1986908769 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810028 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986909042 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986909303 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810028 Length: 10 Value: 8B FF 55 8B
EC E9 5C EE 14 3C
|
success or wait |
1986909597 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D95EE89 Length: 5 Value: E9 20 52 62
C4
|
success or wait |
1986910384 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D9BA6BF Length: 30 Value: 8B FF 55
8B EC 51 51 53 33 C0 21 45 FC 21 45 F8 56 57 33 FF 33 DB 33 C9 33 D2 39 45 08 75
|
success or wait |
1986911442 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986911974 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810032 Length: 10 Value: 8B FF 55 8B
EC E9 88 A6 1A 3C
|
success or wait |
1986912270 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D9BA6BF Length: 5 Value: E9 3E 9A 5C
C4
|
success or wait |
1986913057 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D9BA666 Length: 30 Value: 8B FF 55
8B EC 53 56 57 33 DB 33 C9 33 D2 33 F6 33 FF 39 5D 10 75 2C 8B 45 0C 85 C0 74 14
|
success or wait |
1986914112 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986914646 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 181003C Length: 10 Value: 8B FF 55 8B
EC E9 25 A6 1A 3C
|
success or wait |
1986914941 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D9BA666 Length: 5 Value: E9 33 9B 5C
C4
|
success or wait |
1986915727 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D949088 Length: 30 Value: 8B FF 55
8B EC 51 51 53 56 57 33 DB 33 FF F6 05 78 11 9E 3D 01 89 5D FC 0F 84 D9 6A 01 00
|
success or wait |
1986917387 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986917921 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810046 Length: 10 Value: 8B FF 55 8B
EC E9 3D 90 13 3C
|
success or wait |
1986918215 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D949088 Length: 5 Value: E9 AD B1 63
C4
|
success or wait |
1986919087 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D94654B Length: 30 Value: 8B FF 55
8B EC 83 EC 24 53 56 57 33 FF 39 3D B8 11 9E 3D 89 7D F4 89 7D F8 89 7D F0 C7 45
|
success or wait |
1986921021 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986921557 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810050 Length: 10 Value: 8B FF 55 8B
EC E9 F6 64 13 3C
|
success or wait |
1986921854 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D94654B Length: 5 Value: E9 2D DD 63
C4
|
success or wait |
1986922783 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D963381 Length: 30 Value: 8B FF 55
8B EC 83 EC 20 53 33 DB 39 1D B8 11 9E 3D 56 57 89 5D FC 89 5D F4 89 5D F8 C7 45
|
success or wait |
1986924406 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986924942 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 181005A Length: 10 Value: 8B FF 55 8B
EC E9 22 33 15 3C
|
success or wait |
1986925238 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D963381 Length: 5 Value: E9 36 0F 62
C4
|
success or wait |
1986926026 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D94BF83 Length: 30 Value: 8B FF 55
8B EC 83 EC 10 53 33 DB 39 1D B8 11 9E 3D 56 57 89 5D FC C7 45 F8 01 00 00 00 0F
|
success or wait |
1986937430 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986938588 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810064 Length: 10 Value: 8B FF 55 8B
EC E9 1A BF 13 3C
|
success or wait |
1986956978 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D94BF83 Length: 5 Value: E9 7E 83 63
C4
|
success or wait |
1986958091 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D94878D Length: 30 Value: 8B FF 55
8B EC 83 EC 10 53 33 DB 39 1D B8 11 9E 3D 56 57 89 5D F8 89 5D FC 0F 84 C3 65 04
|
success or wait |
1986959814 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986960355 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 181006E Length: 10 Value: 8B FF 55 8B
EC E9 1A 87 13 3C
|
success or wait |
1986960651 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 3D94878D Length: 5 Value: E9 A0 BB 63
C4
|
success or wait |
1986961444 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 71AB3E2B Length: 30 Value: 8B FF 55
8B EC 51 81 3D 50 40 AC 71 29 2C AB 71 56 0F 84 BC 4F 00 00 E8 3A E8 FF FF 85 C0
|
success or wait |
1986962289 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986962827 |
| Memory written |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810078 Length: 10 Value: 8B FF 55 8B
EC E9 AE 3D 2A 70
|
success or wait |
1986963123 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 71AB4C27 Length: 30 Value: 8B FF 55
8B EC 83 EC 10 56 57 33 FF 81 3D 50 40 AC 71 29 2C AB 71 0F 84 25 6A 00 00 8D 45
|
success or wait |
1986964752 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986965289 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 71AB68FA Length: 30 Value: 8B FF 55
8B EC 51 51 81 3D 50 40 AC 71 29 2C AB 71 56 0F 84 CD 4D 00 00 8D 45 F8 50 E8 98
|
success or wait |
1986967214 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986967751 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E41ECA3 Length: 30 Value: B8 D7 11
00 00 BA 00 03 FE 7F FF 12 C2 0C 00 90 90 90 90 90 6A 2F 6A 01 E8 EE 97 FF FF 6A
|
success or wait |
1986969981 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986970519 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E41FE6E Length: 30 Value: B8 2E 12
00 00 BA 00 03 FE 7F FF 12 C2 04 00 33 FF 47 83 7D E4 FF 0F 85 AC AC FF FF C7 45
|
success or wait |
1986972740 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986973279 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E428D20 Length: 30 Value: 6A 14 68
90 8D 42 7E E8 94 F8 FE FF E8 0B F9 FE FF 83 3D 8C 10 47 7E 00 75 08 85 C0 0F 84
|
success or wait |
1986975486 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986976022 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E42C17E Length: 30 Value: 6A 14 68
F0 C1 42 7E E8 36 C4 FE FF E8 AD C4 FE FF 83 3D 8C 10 47 7E 00 75 08 85 C0 0F 84
|
success or wait |
1986978294 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986978829 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E423D3A Length: 30 Value: 8B FF 55
8B EC 8B 4D 08 E8 99 47 FF FF 85 C0 74 11 6A 00 FF 75 14 FF 75 10 FF 75 0C 50 E8
|
success or wait |
1986981047 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986981583 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E43E577 Length: 30 Value: 8B FF 55
8B EC 8B 4D 08 E8 5C 9F FD FF 85 C0 74 11 6A 01 FF 75 14 FF 75 10 FF 75 0C 50 E8
|
success or wait |
1986998395 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1986998936 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E430833 Length: 30 Value: 8B FF 55
8B EC 6A 00 FF 75 18 FF 75 14 FF 75 10 FF 75 0C FF 75 08 E8 09 00 00 00 5D C2 14
|
success or wait |
1987001145 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987001684 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E44F965 Length: 30 Value: 8B FF 55
8B EC 6A 01 FF 75 18 FF 75 14 FF 75 10 FF 75 0C FF 75 08 E8 D7 0E FE FF 5D C2 14
|
success or wait |
1987003732 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987004270 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E430A47 Length: 30 Value: 8B FF 55
8B EC 6A 00 FF 75 14 FF 75 10 FF 75 0C FF 75 08 E8 09 00 00 00 5D C2 10 00 90 90
|
success or wait |
1987006472 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987007009 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E44F9B4 Length: 30 Value: 8B FF 55
8B EC 6A 01 FF 75 14 FF 75 10 FF 75 0C FF 75 08 E8 9C 10 FE FF 5D C2 10 00 90 90
|
success or wait |
1987009009 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987009545 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E42A01E Length: 30 Value: 8B FF 55
8B EC 6A 00 FF 75 18 FF 75 14 FF 75 10 FF 75 0C FF 75 08 E8 89 FF FF FF 5D C2 14
|
success or wait |
1987011701 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987012236 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E42A97D Length: 30 Value: 8B FF 55
8B EC 6A 01 FF 75 18 FF 75 14 FF 75 10 FF 75 0C FF 75 08 E8 2A F6 FF FF 5D C2 14
|
success or wait |
1987014441 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987014978 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E41A39A Length: 30 Value: 8B FF 55
8B EC 83 EC 30 8B 45 08 56 57 6A 09 59 8D 70 04 8B 00 8D 7D D8 F3 A5 89 45 D4 33
|
success or wait |
1987017324 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987017862 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E42EA5E Length: 30 Value: 8B FF 55
8B EC 83 EC 30 8B 45 08 56 57 6A 09 59 8D 70 04 8B 00 8D 7D D8 F3 A5 89 45 D4 33
|
success or wait |
1987020068 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987020605 |
| Memory read |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 7E41AF7F Length: 30 Value: 8B FF 55
8B EC 8B 45 08 83 38 30 0F 85 0B E7 02 00 68 00 01 00 00 6A 00 6A 00 50 E8 C5 F1
|
success or wait |
1987022926 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987023461 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987026225 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987029129 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987031995 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987034759 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987037568 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987040701 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987043566 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987046254 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987048942 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987051721 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987054411 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987056982 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987059717 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987062716 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987065598 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987068406 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987071094 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987073897 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987076581 |
| Memory attributes changed |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 1810000 Length: 1000 New Protection:
page execute and read and write New Protection: page execute and read and write
|
success or wait |
1987079385 |
| System info queried |
Type: ProcessInformation |
success or wait |
1987087255 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 1820000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1987093957 |
| Thread created |
PID: 1636 TID: 3996 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
1987215155 |
| Mutant created |
Name: \BaseNamedObjects\Global\{366BFE45-C6D8-191D-185B-81F8EE8A3A3D} |
success or wait |
1987216933 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\4 Name: Okmaykid
|
object name not found |
1987217436 |
| System info queried |
Type: ProcessInformation |
success or wait |
1987220073 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 1820000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1987227488 |
| Section loaded |
Path: C:\WINDOWS\system32\mswsock.dll Access: write and read and execute Type: commit
Baseaddress: 29D0000 Size: 245760 Protection: execute Mapped to pid: own pid
|
success or wait |
1987228627 |
| Section loaded |
Path: C:\WINDOWS\system32\mswsock.dll Access: write and read and execute Type: commit
Baseaddress: 29D0000 Size: 245760 Protection: execute Mapped to pid: own pid
|
success or wait |
1987230697 |
| Section loaded |
Path: C:\WINDOWS\system32\mswsock.dll Access: query and write and read and execute
Type: image Baseaddress: 71A50000 Size: 258048 Protection: read write Mapped to pid:
own pid
|
success or wait |
1987235100 |
| Section loaded |
Path: \KnownDlls\hnetcfg.dll Access: write and read and execute Type: unknown Baseaddress:
71A50000 Size: 258048 Protection: read write Mapped to pid: own pid
|
object name not found |
1987250770 |
| Section loaded |
Path: C:\WINDOWS\system32\hnetcfg.dll Access: query and write and read and execute
Type: image Baseaddress: 662B0000 Size: 360448 Protection: read write Mapped to pid:
own pid
|
success or wait |
1987252381 |
| Section loaded |
Path: C:\WINDOWS\system32\wshtcpip.dll Access: write and read and execute Type: commit
Baseaddress: 1820000 Size: 20480 Protection: execute Mapped to pid: own pid
|
success or wait |
1987277919 |
| Section loaded |
Path: C:\WINDOWS\system32\wshtcpip.dll Access: write and read and execute Type: commit
Baseaddress: 1820000 Size: 20480 Protection: execute Mapped to pid: own pid
|
success or wait |
1987282627 |
| Section loaded |
Path: C:\WINDOWS\system32\wshtcpip.dll Access: query and write and read and execute
Type: image Baseaddress: 71A90000 Size: 32768 Protection: read write Mapped to pid:
own pid
|
success or wait |
1987284637 |
| Mutant created |
Name: \BaseNamedObjects\Global\{50BFCA5C-F2C1-7FC9-185B-81F8EE8A3A3D} |
success or wait |
1987384007 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\4 Name: Okmaykid
|
object name not found |
1987386765 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Giid
Name: Okmaykid Type: Binary Data: 96 8D 31 C9 C5 75 08 F8 84 53 9B D1 F4 B9 61 28
10 B5 F1 08 71 3F 43 D6 C5 E1 62 1A C6 5B 19 DC CC D6 C6 9D C6 B3 0A 3C 08 2E 18 33
00 4D E7 0B 36 BD B7 A3 BD 92 EA 03 1F E4 1B C7 16 2B 45 CA B5 08 9E BA 6B 0D 91 DA
05 B1 6F 8F BD 44 64 5A BF 72 4F 66 A5 9E C5 70 A4 30 85 A9 DA E1 B0 C2 84 42 08 3E
FA A7 EC BB C8 A3 E1 74 73 02 2C 20 4D 52 81 9C
|
success or wait |
1987387912 |
| Thread created |
PID: 1636 TID: 3984 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
1987475269 |
| Mutant created |
Name: \BaseNamedObjects\Global\{366BFE4A-C6D7-191D-185B-81F8EE8A3A3D} |
success or wait |
1987477010 |
| System info queried |
Type: ProcessInformation |
success or wait |
1987478199 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 1820000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1987486067 |
| Thread created |
PID: 1636 TID: 3988 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
1987609525 |
| Mutant created |
Name: \BaseNamedObjects\Global\{D2C7FACE-C253-FDB1-185B-81F8EE8A3A3D} |
success or wait |
1987611283 |
| System info queried |
Type: ProcessInformation |
success or wait |
1987615144 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 19E0000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1987621898 |
| Section loaded |
Path: \KnownDlls\RASAPI32.dll Access: write and read and execute Type: unknown Baseaddress:
19E0000 Size: 12288 Protection: read write Mapped to pid: own pid
|
object name not found |
1987669698 |
| Section loaded |
Path: C:\WINDOWS\system32\rasapi32.dll Access: query and write and read and execute
Type: image Baseaddress: 76EE0000 Size: 245760 Protection: read write Mapped to pid:
own pid
|
success or wait |
1987671516 |
| Section loaded |
Path: \KnownDlls\rasman.dll Access: write and read and execute Type: unknown Baseaddress:
76EE0000 Size: 245760 Protection: read write Mapped to pid: own pid
|
object name not found |
1987680681 |
| Section loaded |
Path: C:\WINDOWS\system32\rasman.dll Access: query and write and read and execute
Type: image Baseaddress: 76E90000 Size: 73728 Protection: read write Mapped to pid:
own pid
|
success or wait |
1987682440 |
| Section loaded |
Path: \KnownDlls\TAPI32.dll Access: write and read and execute Type: unknown Baseaddress:
76E90000 Size: 73728 Protection: read write Mapped to pid: own pid
|
object name not found |
1987696550 |
| Section loaded |
Path: C:\WINDOWS\system32\tapi32.dll Access: query and write and read and execute
Type: image Baseaddress: 76EB0000 Size: 192512 Protection: read write Mapped to pid:
own pid
|
success or wait |
1987698341 |
| Section loaded |
Path: C:\WINDOWS\system32\tapi32.dll Access: read Type: commit Baseaddress: 2A50000
Size: 184320 Protection: readonly Mapped to pid: own pid
|
success or wait |
1987719420 |
| Section loaded |
Path: \KnownDlls\msapsspc.dll Access: write and read and execute Type: unknown Baseaddress:
2A50000 Size: 184320 Protection: readonly Mapped to pid: own pid
|
object name not found |
1988025411 |
| Section loaded |
Path: C:\WINDOWS\system32\msapsspc.dll Access: query and write and read and execute
Type: image Baseaddress: 71E50000 Size: 86016 Protection: read write Mapped to pid:
own pid
|
success or wait |
1988030803 |
| Section loaded |
Path: \KnownDlls\MSVCRT40.dll Access: write and read and execute Type: unknown Baseaddress:
71E50000 Size: 86016 Protection: read write Mapped to pid: own pid
|
object name not found |
1988035816 |
| Section loaded |
Path: C:\WINDOWS\system32\msvcrt40.dll Access: query and write and read and execute
Type: image Baseaddress: 78080000 Size: 69632 Protection: read write Mapped to pid:
own pid
|
success or wait |
1988045172 |
| Section loaded |
Path: \KnownDlls\sensapi.dll Access: write and read and execute Type: unknown Baseaddress:
78080000 Size: 69632 Protection: read write Mapped to pid: own pid
|
object name not found |
1988093173 |
| Section loaded |
Path: C:\WINDOWS\system32\sensapi.dll Access: query and write and read and execute
Type: image Baseaddress: 722B0000 Size: 20480 Protection: read write Mapped to pid:
own pid
|
success or wait |
1988095050 |
| Section loaded |
Path: \KnownDlls\schannel.dll Access: write and read and execute Type: unknown Baseaddress:
722B0000 Size: 20480 Protection: read write Mapped to pid: own pid
|
object name not found |
1988111808 |
| Section loaded |
Path: C:\WINDOWS\system32\schannel.dll Access: query and write and read and execute
Type: image Baseaddress: 767F0000 Size: 163840 Protection: read write Mapped to pid:
own pid
|
success or wait |
1988113563 |
| Section loaded |
Path: \BaseNamedObjects\SENS Information Cache Access: read Type: unknown Baseaddress:
19D0000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
1988144915 |
| Section loaded |
Path: \KnownDlls\digest.dll Access: write and read and execute Type: unknown Baseaddress:
19D0000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
object name not found |
1988145302 |
| Section loaded |
Path: C:\WINDOWS\system32\digest.dll Access: query and write and read and execute
Type: image Baseaddress: 75B00000 Size: 86016 Protection: read write Mapped to pid:
own pid
|
success or wait |
1988153125 |
| Section loaded |
Path: \KnownDlls\msnsspc.dll Access: write and read and execute Type: unknown Baseaddress:
75B00000 Size: 86016 Protection: read write Mapped to pid: own pid
|
object name not found |
1988196748 |
| Section loaded |
Path: C:\WINDOWS\system32\msnsspc.dll Access: query and write and read and execute
Type: image Baseaddress: 747B0000 Size: 290816 Protection: read write Mapped to pid:
own pid
|
success or wait |
1988202891 |
| Section loaded |
Path: \KnownDlls\MSVCRT40.dll Access: write and read and execute Type: unknown Baseaddress:
747B0000 Size: 290816 Protection: read write Mapped to pid: own pid
|
object name not found |
1988213069 |
| Section loaded |
Path: C:\WINDOWS\system32\msvcrt40.dll Access: query and write and read and execute
Type: image Baseaddress: 78080000 Size: 69632 Protection: read write Mapped to pid:
own pid
|
success or wait |
1988214672 |
| Thread created |
PID: 1636 TID: 4012 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
1988234319 |
| System info queried |
Type: ProcessInformation |
success or wait |
1988240059 |
| Mutant created |
Name: \BaseNamedObjects\Global\{3A87297E-11E3-15F1-185B-81F8EE8A3A3D} |
success or wait |
1988241691 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Giid
Name: Ebci
|
object name not found |
1988252111 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 2AD0000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1988252361 |
| Section loaded |
Path: \KnownDlls\rasadhlp.dll Access: write and read and execute Type: unknown Baseaddress:
2AD0000 Size: 12288 Protection: read write Mapped to pid: own pid
|
object name not found |
1988267152 |
| Section loaded |
Path: C:\WINDOWS\system32\rasadhlp.dll Access: query and write and read and execute
Type: image Baseaddress: 76FC0000 Size: 24576 Protection: read write Mapped to pid:
own pid
|
success or wait |
1988274562 |
| Section loaded |
Path: C:\WINDOWS\system32\msv1_0.dll Access: write and read and execute Type: commit
Baseaddress: 2A90000 Size: 139264 Protection: execute Mapped to pid: own pid
|
success or wait |
1988294136 |
| Section loaded |
Path: C:\WINDOWS\system32\msv1_0.dll Access: write and read and execute Type: commit
Baseaddress: 2A90000 Size: 139264 Protection: execute Mapped to pid: own pid
|
success or wait |
1988301712 |
| Section loaded |
Path: C:\WINDOWS\system32\msv1_0.dll Access: query and write and read and execute
Type: image Baseaddress: 77C70000 Size: 151552 Protection: read write Mapped to pid:
own pid
|
success or wait |
1988308253 |
| Section loaded |
Path: \KnownDlls\cryptdll.dll Access: write and read and execute Type: unknown Baseaddress:
77C70000 Size: 151552 Protection: read write Mapped to pid: own pid
|
object name not found |
1988319463 |
| Section loaded |
Path: C:\WINDOWS\system32\cryptdll.dll Access: query and write and read and execute
Type: image Baseaddress: 76790000 Size: 49152 Protection: read write Mapped to pid:
own pid
|
success or wait |
1988321246 |
| Section loaded |
Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_IETldCache_index.dat_262144
Access: write Type: unknown Baseaddress: 76790000 Size: 49152 Protection: read write
Mapped to pid: own pid
|
object name not found |
1988393748 |
| Section loaded |
Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_IETldCache_index.dat_262144
Access: query and write and read Type: commit Baseaddress: 2A90000 Size: 262144 Protection:
read write Mapped to pid: own pid
|
success or wait |
1988397358 |
| Section loaded |
Path: \KnownDlls\DNSAPI.dll Access: write and read and execute Type: unknown Baseaddress:
2A90000 Size: 262144 Protection: read write Mapped to pid: own pid
|
object name not found |
1988441393 |
| Section loaded |
Path: C:\WINDOWS\system32\dnsapi.dll Access: query and write and read and execute
Type: image Baseaddress: 76F20000 Size: 159744 Protection: read write Mapped to pid:
own pid
|
success or wait |
1988446269 |
| Thread created |
PID: 1636 TID: 4016 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
1988602559 |
| Mutant created |
Name: \BaseNamedObjects\Global\{3A87297F-11E2-15F1-185B-81F8EE8A3A3D} |
success or wait |
1988605905 |
| File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Qiokze\pauz.sei Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988607960 |
| System info queried |
Type: ProcessInformation |
success or wait |
1988608277 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 2B10000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1988610797 |
| Mutant created |
Name: \BaseNamedObjects\Global\{C5C44599-7D04-EAB2-185B-81F8EE8A3A3D} |
success or wait |
1988612085 |
| File moved |
New path: TRUE Path: C:\Documents and Settings\Administrator\Application Data\Qiokze\pauz.sei |
success or wait |
1988612668 |
| Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters Name: Ebci |
object name not found |
1988619875 |
| Thread created |
PID: 1636 TID: 4020 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
1988665501 |
| Mutant created |
Name: \BaseNamedObjects\Local\{5B619F6A-A7F7-7417-185B-81F8EE8A3A3D} |
success or wait |
1988666214 |
| System info queried |
Type: ProcessInformation |
success or wait |
1988666668 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 2B50000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1988669192 |
| Thread created |
PID: 1636 TID: 4024 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
1988716865 |
| Mutant created |
Name: \BaseNamedObjects\Global\{50BFCA5C-F2C1-7FC9-185B-81F8EE8A3A3D} |
success or wait |
1988718374 |
| Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters Name: Okmaykid |
success or wait |
1988718545 |
| Mutant created |
Name: \BaseNamedObjects\Local\{5B619F69-A7F4-7417-185B-81F8EE8A3A3D} |
success or wait |
1988718896 |
| Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters Name: Okmaykid |
success or wait |
1988720378 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ad.wsod[2].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988723838 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988731982 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ad.wsod[2].txt
Offset: none Length: 222 Value: 75 0A 34 64 64 61 36 36 61 37 30 64 38 61 62 0A 61
64 2E 77 73 6F 64 2E 63 6F 6D 2F 0A 32 31 34 37 34 38 34 36 37 32 0A 33 30 38 39 30
39 33 31 32 30 0A 33 30 31 35 39 32 38 30 0A 32 30 33 37 32 36 35 35 36 38 0A 33 30
31 35 33 30 34 32 0A 2A 0A 69 5F 31 0A 33 33 3A 39 36 37 3A 35 35 35 3A 30 3A 30
|
success or wait |
1988732139 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@adobe[1].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988732903 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988733319 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@adobe[1].txt Offset:
none Length: 232 Value: 6D 62 6F 78 0A 63 68 65 63 6B 23 74 72 75 65 23 31 33 30 32
32 37 39 33 35 36 7C 73 65 73 73 69 6F 6E 23 31 33 30 32 32 37 39 32 34 30 39 31 38
2D 39 35 32 36 31 35 23 31 33 30 32 32 38 31 31 35 36 0A 61 64 6F 62 65 2E 63 6F 6D
2F 0A 31 36 30 30 0A 31 38 34 39 37 36 38 34 34 38 0A 33 30 31 34 34 30
|
success or wait |
1988733421 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@adobe[2].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988734146 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988734563 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@adobe[2].txt Offset:
none Length: 232 Value: 6D 62 6F 78 0A 63 68 65 63 6B 23 74 72 75 65 23 31 33 32 31
30 31 31 39 36 32 7C 73 65 73 73 69 6F 6E 23 31 33 32 31 30 31 31 39 30 31 36 37 39
2D 32 31 30 36 33 34 23 31 33 32 31 30 31 33 37 36 32 0A 61 64 6F 62 65 2E 63 6F 6D
2F 0A 31 36 30 30 0A 32 39 31 31 31 35 33 34 30 38 0A 33 30 31 38 37 36
|
success or wait |
1988734669 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[1].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988735391 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988736403 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[1].txt Offset:
none Length: 102 Value: 4D 55 49 44 0A 39 37 41 30 45 44 32 45 45 39 33 35 34 37 33
44 38 37 46 43 37 45 37 30 37 32 35 45 45 30 35 37 0A 61 74 64 6D 74 2E 63 6F 6D 2F
0A 32 31 34 37 34 38 34 36 37 32 0A 33 32 38 35 30 36 31 36 33 32 0A 33 30 31 38 34
33 38 33 0A 32 37 31 36 30 36 31 36 30 30 0A 33 30 31 34 34 31 35 30 0A
|
success or wait |
1988736509 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988737134 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988738160 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt Offset:
none Length: 101 Value: 4D 55 49 44 0A 37 32 44 35 36 35 34 38 34 31 37 31 34 45 38
32 42 39 33 39 31 41 42 33 35 41 32 31 37 34 42 30 0A 61 74 64 6D 74 2E 63 6F 6D 2F
0A 32 31 34 37 34 38 34 36 37 32 0A 33 39 30 34 31 37 36 36 34 0A 33 30 31 38 34 32
34 31 0A 34 31 31 33 33 31 34 39 32 38 0A 33 30 31 34 34 30 30 37 0A 2A
|
success or wait |
1988738265 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[3].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988738889 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988739309 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[3].txt Offset:
none Length: 191 Value: 4D 55 49 44 0A 32 34 30 44 42 43 38 44 38 34 42 30 36 38 42
35 33 37 45 44 42 44 37 36 38 30 42 30 36 38 30 42 0A 61 74 64 6D 74 2E 63 6F 6D 2F
0A 32 31 34 37 34 38 34 36 37 32 0A 33 34 37 35 38 30 30 31 39 32 0A 33 30 31 39 33
32 37 33 0A 32 34 33 35 32 36 34 37 35 32 0A 33 30 31 35 33 30 33 38 0A
|
success or wait |
1988739414 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@bing[1].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988740093 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988741101 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@bing[1].txt Offset:
none Length: 204 Value: 53 52 43 48 44 0A 4D 53 3D 31 37 38 33 35 38 30 26 44 3D 31
37 38 33 35 35 32 26 41 46 3D 4E 4F 46 4F 52 4D 0A 62 69 6E 67 2E 63 6F 6D 2F 0A 32
31 34 37 34 38 34 36 37 32 0A 32 32 38 32 37 36 36 30 38 30 0A 33 30 32 39 39 38 39
35 0A 32 30 35 38 32 30 35 35 36 38 0A 33 30 31 35 33 30 34 32 0A 2A 0A
|
success or wait |
1988741208 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@bing[2].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988741930 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988742962 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@bing[2].txt Offset:
none Length: 291 Value: 4D 55 49 44 0A 37 32 44 35 36 35 34 38 34 31 37 31 34 45 38
32 42 39 33 39 31 41 42 33 35 41 32 31 37 34 42 30 0A 62 69 6E 67 2E 63 6F 6D 2F 0A
31 30 32 34 0A 33 39 30 34 31 37 36 36 34 0A 33 30 31 38 34 32 34 31 0A 34 31 31 34
34 30 34 39 32 38 0A 33 30 31 34 34 30 30 37 0A 2A 0A 53 52 43 48 44 0A
|
success or wait |
1988743069 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.bing[1].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988743805 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988744857 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.bing[1].txt
Offset: none Length: 69 Value: 41 4E 4F 4E 43 48 4B 0A 30 0A 63 2E 62 69 6E 67 2E
63 6F 6D 2F 0A 31 30 32 34 0A 31 39 34 34 33 35 38 31 34 34 0A 33 30 31 34 34 36 31
31 0A 34 31 31 34 34 30 34 39 32 38 0A 33 30 31 34 34 30 30 37 0A 2A 0A
|
success or wait |
1988744963 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[1].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988745577 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988746885 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[1].txt Offset:
none Length: 68 Value: 41 4E 4F 4E 43 48 4B 0A 30 0A 63 2E 6D 73 6E 2E 63 6F 6D 2F
0A 31 30 32 34 0A 31 39 32 34 33 35 38 31 34 34 0A 33 30 31 34 34 36 31 31 0A 34 30
38 37 30 36 34 39 32 38 0A 33 30 31 34 34 30 30 37 0A 2A 0A
|
success or wait |
1988746991 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[2].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988747647 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988748973 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[2].txt Offset:
none Length: 67 Value: 41 4E 4F 4E 43 48 4B 0A 30 0A 63 2E 6D 73 6E 2E 63 6F 6D 2F
0A 31 30 32 34 0A 35 36 34 30 33 34 38 31 36 0A 33 30 31 34 34 37 35 34 0A 32 37 33
34 38 31 31 36 30 30 0A 33 30 31 34 34 31 35 30 0A 2A 0A
|
success or wait |
1988749091 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[3].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988749700 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988750121 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[3].txt Offset:
none Length: 67 Value: 41 4E 4F 4E 43 48 4B 0A 30 0A 63 2E 6D 73 6E 2E 63 6F 6D 2F
0A 31 30 32 34 0A 37 35 34 37 37 33 33 37 36 0A 33 30 31 35 33 36 34 34 0A 32 34 35
33 38 35 34 37 35 32 0A 33 30 31 35 33 30 33 38 0A 2A 0A
|
success or wait |
1988750226 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ch.msn[1].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988750831 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988751847 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ch.msn[1].txt
Offset: none Length: 83 Value: 50 4F 50 55 50 43 48 45 43 4B 0A 31 33 30 32 33 36
35 36 33 31 36 36 38 0A 63 68 2E 6D 73 6E 2E 63 6F 6D 2F 0A 31 30 38 38 0A 34 39 31
32 31 31 31 33 36 0A 33 30 31 34 34 32 30 39 0A 34 30 38 31 32 38 34 39 32 38 0A 33
30 31 34 34 30 30 37 0A 2A 0A
|
success or wait |
1988751953 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988752643 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988753670 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
Offset: none Length: 122 Value: 69 64 0A 63 38 32 63 64 65 37 33 37 30 30 30 30 65
31 7C 7C 74 3D 31 33 30 36 31 36 30 34 33 35 7C 65 74 3D 37 33 30 7C 63 73 3D 79 67
31 65 38 31 65 2D 0A 64 6F 75 62 6C 65 63 6C 69 63 6B 2E 6E 65 74 2F 0A 32 31 34 37
34 38 34 36 37 32 0A 32 32 35 32 37 36 36 30 38 30 0A 33 30 32 39 39 38 39 35 0A
|
success or wait |
1988753777 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ivwbox[2].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988754409 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988754831 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ivwbox[2].txt
Offset: none Length: 88 Value: 69 30 30 0A 30 31 37 62 34 64 61 30 32 33 39 36 65
62 35 31 30 30 30 36 0A 69 76 77 62 6F 78 2E 64 65 2F 0A 32 31 34 37 34 38 34 36 37
32 0A 33 36 35 36 30 35 35 30 34 0A 33 30 32 31 37 35 37 36 0A 32 36 39 34 34 39 31
36 30 30 0A 33 30 31 34 34 31 35 30 0A 2A 0A
|
success or wait |
1988754936 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@live[1].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988755559 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988756572 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@live[1].txt Offset:
none Length: 99 Value: 4D 55 49 44 0A 37 32 44 35 36 35 34 38 34 31 37 31 34 45 38
32 42 39 33 39 31 41 42 33 35 41 32 31 37 34 42 30 0A 6C 69 76 65 2E 63 6F 6D 2F 0A
32 31 34 37 34 38 34 37 35 32 0A 32 30 34 38 33 32 37 36 38 0A 33 30 38 35 39 32 31
37 0A 33 34 36 39 33 37 36 33 32 0A 33 30 31 34 34 30 30 38 0A 2A 0A
|
success or wait |
1988756678 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@live[2].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988757307 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988758323 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@live[2].txt Offset:
none Length: 100 Value: 4D 55 49 44 0A 32 34 30 44 42 43 38 44 38 34 42 30 36 38 42
35 33 37 45 44 42 44 37 36 38 30 42 30 36 38 30 42 0A 6C 69 76 65 2E 63 6F 6D 2F 0A
32 31 34 37 34 38 34 37 35 32 0A 32 30 34 38 33 32 37 36 38 0A 33 30 38 35 39 32 31
37 0A 32 35 34 31 33 35 34 37 35 32 0A 33 30 31 35 33 30 33 38 0A 2A 0A
|
success or wait |
1988758429 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[1].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988759053 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988760103 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[1].txt
Offset: none Length: 108 Value: 4D 43 31 0A 56 3D 33 26 47 55 49 44 3D 64 34 62 32
32 37 62 34 35 61 38 36 34 61 63 39 38 65 33 36 61 39 34 63 64 61 39 64 64 36 35 61
0A 6D 69 63 72 6F 73 6F 66 74 2E 63 6F 6D 2F 0A 31 30 32 34 0A 33 37 39 39 39 37 33
38 38 38 0A 33 30 39 31 34 38 37 32 0A 34 30 34 34 37 31 34 39 32 38 0A 33 30 31
|
success or wait |
1988760222 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[2].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988760846 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988761926 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[2].txt
Offset: none Length: 108 Value: 4D 43 31 0A 56 3D 33 26 47 55 49 44 3D 62 30 37 65
34 37 39 62 30 37 66 36 34 65 62 30 39 66 62 62 65 64 36 66 38 66 62 31 36 66 64 33
0A 6D 69 63 72 6F 73 6F 66 74 2E 63 6F 6D 2F 0A 31 30 32 34 0A 33 37 39 39 39 37 33
38 38 38 0A 33 30 39 31 34 38 37 32 0A 32 35 34 31 38 34 31 36 30 30 0A 33 30 31
|
success or wait |
1988762031 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[3].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988762696 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988763124 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[3].txt
Offset: none Length: 108 Value: 4D 43 31 0A 56 3D 33 26 47 55 49 44 3D 39 35 61 30
63 63 36 61 31 63 39 38 34 39 64 33 61 65 30 32 31 35 37 34 31 33 62 35 38 65 36 61
0A 6D 69 63 72 6F 73 6F 66 74 2E 63 6F 6D 2F 0A 31 30 32 34 0A 33 37 39 39 39 37 33
38 38 38 0A 33 30 39 31 34 38 37 32 0A 32 31 37 31 30 34 34 37 35 32 0A 33 30 31
|
success or wait |
1988763230 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@msn[1].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988763910 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988764943 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@msn[1].txt Offset:
none Length: 455 Value: 4D 43 31 0A 56 3D 33 26 47 55 49 44 3D 36 64 61 34 34 66 64
61 33 33 65 61 34 61 32 39 38 34 65 66 64 30 66 33 34 66 32 30 38 34 35 35 0A 6D 73
6E 2E 63 6F 6D 2F 0A 31 30 32 34 0A 31 33 30 38 32 34 31 39 32 0A 33 30 39 31 34 38
39 38 0A 34 30 34 39 35 36 34 39 32 38 0A 33 30 31 34 34 30 30 37 0A 2A
|
success or wait |
1988765050 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@msn[2].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988765908 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988766335 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@msn[2].txt Offset:
none Length: 387 Value: 4D 43 31 0A 56 3D 33 26 47 55 49 44 3D 34 64 33 30 63 39 34
63 62 30 62 35 34 62 31 35 62 36 30 65 35 39 37 38 33 62 35 32 32 64 38 62 0A 6D 73
6E 2E 63 6F 6D 2F 0A 31 30 32 34 0A 31 33 30 38 32 34 31 39 32 0A 33 30 39 31 34 38
39 38 0A 32 35 35 37 34 36 31 36 30 30 0A 33 30 31 34 34 31 35 30 0A 2A
|
success or wait |
1988766441 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@msn[3].txt Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988767254 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988768288 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@msn[3].txt Offset:
none Length: 457 Value: 4D 43 31 0A 56 3D 33 26 47 55 49 44 3D 38 35 62 63 63 31 63
34 31 37 65 31 34 34 63 62 61 33 61 62 39 62 65 65 62 61 36 62 62 35 32 32 0A 6D 73
6E 2E 63 6F 6D 2F 0A 31 30 32 34 0A 31 33 30 38 32 34 31 39 32 0A 33 30 39 31 34 38
39 38 0A 32 32 31 34 37 39 34 37 35 32 0A 33 30 31 35 33 30 33 38 0A 2A
|
success or wait |
1988768394 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@rad.msn[2].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988769228 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988770252 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@rad.msn[2].txt
Offset: none Length: 690 Value: 46 43 30 30 0A 46 42 3D 0A 72 61 64 2E 6D 73 6E 2E
63 6F 6D 2F 0A 39 32 31 36 0A 33 38 30 32 31 31 32 30 30 30 0A 33 30 32 39 39 38 37
35 0A 32 33 39 33 38 35 34 37 35 32 0A 33 30 31 35 33 30 33 38 0A 2A 0A 46 43 30 31
0A 46 42 3D 0A 72 61 64 2E 6D 73 6E 2E 63 6F 6D 2F 0A 39 32 31 36 0A 33 38 30 32
|
success or wait |
1988770359 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@scorecardresearch[1].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988771924 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988772361 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@scorecardresearch[1].txt
Offset: none Length: 115 Value: 55 49 44 0A 32 39 30 36 32 66 37 32 2D 39 35 2E 31
30 30 2E 32 34 39 2E 31 33 30 2D 31 33 30 32 33 34 30 35 30 36 0A 73 63 6F 72 65 63
61 72 64 72 65 73 65 61 72 63 68 2E 63 6F 6D 2F 0A 32 31 34 37 34 38 34 36 37 32 0A
32 34 30 31 38 39 36 37 30 34 0A 33 30 32 39 31 30 30 31 0A 32 36 36 30 35 39 31
|
success or wait |
1988772467 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@scorecardresearch[2].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988772829 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988774014 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@scorecardresearch[2].txt
Offset: none Length: 113 Value: 55 49 44 0A 31 61 37 62 62 64 63 38 2D 32 31 32 2E
32 34 33 2E 31 35 32 2E 31 36 30 2D 31 33 30 32 32 37 39 32 33 30 0A 73 63 6F 72 65
63 61 72 64 72 65 73 65 61 72 63 68 2E 63 6F 6D 2F 0A 32 31 34 37 34 38 34 36 37 32
0A 37 37 32 35 32 37 33 36 0A 33 30 32 39 30 38 35 39 0A 33 32 37 37 31 37 36 33
|
success or wait |
1988774121 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@scorecardresearch[4].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988774936 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988775373 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@scorecardresearch[4].txt
Offset: none Length: 112 Value: 55 49 44 0A 62 39 32 34 35 38 31 2D 36 35 2E 31 39
39 2E 36 33 2E 32 35 2D 31 33 30 36 31 35 38 37 34 37 0A 73 63 6F 72 65 63 61 72 64
72 65 73 65 61 72 63 68 2E 63 6F 6D 2F 0A 32 31 34 37 34 38 34 36 37 32 0A 32 32 33
32 37 36 36 30 38 30 0A 33 30 32 39 39 38 39 35 0A 32 30 30 31 34 38 35 35 36 38
|
success or wait |
1988775479 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@wemfbox[2].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988776108 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988777129 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@wemfbox[2].txt
Offset: none Length: 90 Value: 69 30 30 0A 37 35 34 39 34 64 39 66 33 34 33 64 32
64 62 36 30 30 30 31 0A 77 65 6D 66 62 6F 78 2E 63 68 2F 0A 32 31 34 37 34 38 34 36
37 32 0A 33 38 31 32 32 32 30 30 33 32 0A 33 30 32 39 30 38 35 38 0A 34 30 38 30 36
35 34 39 32 38 0A 33 30 31 34 34 30 30 37 0A 2A 0A
|
success or wait |
1988777236 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@www.bing[1].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988777862 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988778935 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@www.bing[1].txt
Offset: none Length: 111 Value: 53 52 43 48 55 49 44 0A 56 3D 32 26 47 55 49 44 3D
34 45 46 44 37 36 44 38 33 37 43 33 34 42 31 43 39 37 44 44 42 30 38 41 36 44 46 37
30 44 45 43 0A 77 77 77 2E 62 69 6E 67 2E 63 6F 6D 2F 0A 31 35 33 36 0A 33 38 35 32
32 32 30 30 33 32 0A 33 30 32 39 30 38 35 38 0A 34 30 39 38 31 35 34 39 32 38 0A
|
success or wait |
1988779042 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@www.bing[2].txt
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: false
|
success or wait |
1988779705 |
| Memory allocated |
PID: 1636 Path: C:\WINDOWS\explorer.exe Base: 2B50000 Length: 294E9C8 Allocation Type:
null Protection: page read and write
|
success or wait |
1988780760 |
| File read |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@www.bing[2].txt
Offset: none Length: 117 Value: 53 52 43 48 55 49 44 0A 56 3D 32 26 47 55 49 44 3D
42 42 35 44 31 42 30 35 36 35 30 34 34 41 45 43 42 37 45 44 41 35 35 38 37 30 44 39
39 38 39 34 0A 77 77 77 2E 62 69 6E 67 2E 63 6F 6D 2F 0A 32 31 34 37 34 38 34 36 37
32 0A 32 35 36 32 36 33 35 32 36 34 0A 33 30 32 39 39 38 39 31 0A 32 33 35 38 35
|
success or wait |
1988780867 |
| System info queried |
Type: CurrentTimeZoneInformation |
success or wait |
1988782402 |
| Mutant created |
Name: \BaseNamedObjects\Global\{C5C44599-7D04-EAB2-185B-81F8EE8A3A3D} |
success or wait |
1988783177 |
| Privilege adjusted |
Privilege: Security On or off: on |
success or wait |
1988785156 |
| File created |
Path: C:\Documents and Settings\Administrator\Application Data\Qiokze\pauz.sei Access:
read attributes and synchronize and generic read and generic write Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: false
|
success or wait |
1988786910 |
| File other operation |
Disposition: PositionInformation Data : Offset: 0 Path: C:\Documents and Settings\Administrator\Application
Data\Qiokze\pauz.sei
|
success or wait |
1988787689 |
| Section loaded |
Path: C:\WINDOWS\system32\rsaenh.dll Access: query and read Type: commit Baseaddress:
2B50000 Size: 208896 Protection: readonly Mapped to pid: own pid
|
success or wait |
1988790271 |
| Section loaded |
Path: C:\WINDOWS\system32\rsaenh.dll Access: query and read Type: commit Baseaddress:
2B50000 Size: 208896 Protection: readonly Mapped to pid: own pid
|
success or wait |
1988791747 |
| Section loaded |
Path: \KnownDlls\rsaenh.dll Access: write and read and execute Type: unknown Baseaddress:
2B50000 Size: 208896 Protection: readonly Mapped to pid: own pid
|
object name not found |
1989151045 |
| Section loaded |
Path: C:\WINDOWS\system32\rsaenh.dll Access: query and write and read and execute
Type: image Baseaddress: 68000000 Size: 221184 Protection: read write Mapped to pid:
own pid
|
success or wait |
1989159788 |
| Section loaded |
Path: C:\WINDOWS\system32\rsaenh.dll Access: query and read Type: commit Baseaddress:
2B50000 Size: 208896 Protection: readonly Mapped to pid: own pid
|
success or wait |
1989177670 |
| File other operation |
Disposition: PositionInformation Data : Offset: 0 Path: C:\Documents and Settings\Administrator\Application
Data\Qiokze\pauz.sei
|
success or wait |
1989410696 |
| File other operation |
Disposition: PositionInformation Data : Offset: 0 Path: C:\Documents and Settings\Administrator\Application
Data\Qiokze\pauz.sei
|
success or wait |
1989410801 |
| File other operation |
Disposition: PositionInformation Data : Offset: 0 Path: C:\Documents and Settings\Administrator\Application
Data\Qiokze\pauz.sei
|
success or wait |
1989410895 |
| File write |
Path: C:\Documents and Settings\Administrator\Application Data\Qiokze\pauz.sei Offset:
none Length: 5 Value: 3E C9 07 4F 00
|
success or wait |
1989410992 |
| File write |
Path: C:\Documents and Settings\Administrator\Application Data\Qiokze\pauz.sei Offset:
none Length: 2623 Value: A7 7C 90 C9 22 56 2F F9 40 3C 90 C5 A3 70 CA 24 B8 36 1D
E6 A0 E4 98 0D 1E 3A B9 C1 17 8A C8 0D CD FE 7A B8 8C 5C 4E 10 3D 0D AD B6 E5 FE 11
67 49 E5 F2 78 E5 CA B0 59 41 BA 45 99 4C 71 1F 90 E6 53 C5 E3 2B 6A F6 BD 62 D6 0A
EA DC 25 05 3B DA 17 2A 03 31 83 0F F4 3B 88 3D 11 62 59 0A 78 3A FC B6 80
|
success or wait |
1989412571 |
| File other operation |
Disposition: PositionInformation Data : Offset: 0 Path: C:\Documents and Settings\Administrator\Application
Data\Qiokze\pauz.sei
|
success or wait |
1989416410 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ad.wsod[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989419513 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008000000000000000
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ad.wsod[2].txt
|
success or wait |
1989419862 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ad.wsod[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989420304 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ad.wsod[2].txt |
success or wait |
1989420648 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@adobe[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989421263 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008000000000000000
Path: C:\Documents and Settings\Administrator\Cookies\administrator@adobe[1].txt
|
success or wait |
1989421623 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@adobe[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989422101 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@adobe[1].txt |
success or wait |
1989422442 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@adobe[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989423033 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008000000000000000
Path: C:\Documents and Settings\Administrator\Cookies\administrator@adobe[2].txt
|
success or wait |
1989423373 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@adobe[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989423814 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@adobe[2].txt |
success or wait |
1989424207 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989424803 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008000000000000000
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[1].txt
|
success or wait |
1989425491 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989425906 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[1].txt |
success or wait |
1989426246 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989426869 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008000000000000000
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
|
success or wait |
1989427211 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989427655 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt |
success or wait |
1989428345 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[3].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989428945 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008000000000000000
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[3].txt
|
success or wait |
1989429286 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[3].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989429729 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[3].txt |
success or wait |
1989430068 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@bing[1].txt Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
1989430665 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008000000000000000
Path: C:\Documents and Settings\Administrator\Cookies\administrator@bing[1].txt
|
success or wait |
1989431007 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@bing[1].txt Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
1989431481 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@bing[1].txt |
success or wait |
1989431822 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@bing[2].txt Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
1989432423 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008000000000000000
Path: C:\Documents and Settings\Administrator\Cookies\administrator@bing[2].txt
|
success or wait |
1989432763 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@bing[2].txt Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
1989433205 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@bing[2].txt |
success or wait |
1989433561 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.bing[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989434161 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008000000000000000
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.bing[1].txt
|
success or wait |
1989434519 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.bing[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989434961 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.bing[1].txt |
success or wait |
1989435301 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989435899 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008000000000000000
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[1].txt
|
success or wait |
1989436241 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989436714 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[1].txt |
success or wait |
1989437055 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989437654 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008000000000000000
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[2].txt
|
success or wait |
1989437995 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989438434 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[2].txt |
success or wait |
1989438774 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[3].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989439370 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008000000000000000
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[3].txt
|
success or wait |
1989439711 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[3].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989440148 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@c.msn[3].txt |
success or wait |
1989440489 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ch.msn[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989441190 |
| File other operation |
Disposition: BasicInformation Data : 00000000000000000000000000000000000000000000000000000000000000008000000000000000
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ch.msn[1].txt
|
success or wait |
1989441533 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ch.msn[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989441966 |
| File deleted |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ch.msn[1].txt |
success or wait |
1989442313 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989442955 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989443751 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
1989449834 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ivwbox[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989451819 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@ivwbox[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989452580 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@live[1].txt Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
1989453586 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@live[1].txt Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
1989454341 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@live[2].txt Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
1989455247 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@live[2].txt Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
1989456002 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989456908 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989457698 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989458602 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989459356 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[3].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989460314 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[3].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989461374 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@msn[1].txt Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
1989462295 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@msn[1].txt Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
1989463081 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@msn[2].txt Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
1989464380 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@msn[2].txt Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
1989465139 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@msn[3].txt Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
1989466044 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@msn[3].txt Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
1989466797 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@rad.msn[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989467734 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@rad.msn[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989468487 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@scorecardresearch[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989469735 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@scorecardresearch[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989470502 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@scorecardresearch[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989471424 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@scorecardresearch[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989472275 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@scorecardresearch[4].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989473330 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@scorecardresearch[4].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989474094 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@wemfbox[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989475133 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@wemfbox[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989475937 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@www.bing[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989476856 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@www.bing[1].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989477609 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@www.bing[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989478632 |
| File opened |
Path: C:\Documents and Settings\Administrator\Cookies\administrator@www.bing[2].txt
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point
|
success or wait |
1989479386 |
| Section loaded |
Path: C:\WINDOWS\system32\msoeacct.dll Access: write and read and execute Type: commit
Baseaddress: 2B50000 Size: 253952 Protection: execute Mapped to pid: own pid
|
success or wait |
1989521533 |
| Section loaded |
Path: C:\WINDOWS\system32\msoeacct.dll Access: write and read and execute Type: commit
Baseaddress: 2B50000 Size: 253952 Protection: execute Mapped to pid: own pid
|
success or wait |
1989523906 |
| Section loaded |
Path: C:\WINDOWS\system32\msoeacct.dll Access: query and write and read and execute
Type: image Baseaddress: 68810000 Size: 270336 Protection: read write Mapped to pid:
own pid
|
success or wait |
1989524810 |
| Section loaded |
Path: \KnownDlls\MSOERT2.dll Access: write and read and execute Type: unknown Baseaddress:
68810000 Size: 270336 Protection: read write Mapped to pid: own pid
|
object name not found |
1989526714 |
| Section loaded |
Path: C:\WINDOWS\system32\msoert2.dll Access: query and write and read and execute
Type: image Baseaddress: 76880000 Size: 139264 Protection: read write Mapped to pid:
own pid
|
success or wait |
1989528707 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit
Baseaddress: 2B60000 Size: 4096 Protection: execute Mapped to pid: own pid
|
success or wait |
1989544751 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress:
2B60000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
1989545829 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: 2B60000
Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
1989546779 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit
Baseaddress: 2B80000 Size: 4096 Protection: execute Mapped to pid: own pid
|
success or wait |
1989563244 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress:
2B80000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
1989564303 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: 2B80000
Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
1989565270 |
| Section loaded |
Path: C:\WINDOWS\system32\acctres.dll Access: write and read and execute Type: commit
Baseaddress: 2B80000 Size: 65536 Protection: execute Mapped to pid: own pid
|
success or wait |
1989580280 |
| Section loaded |
Path: C:\WINDOWS\system32\acctres.dll Access: write and read and execute Type: commit
Baseaddress: 2B80000 Size: 65536 Protection: execute Mapped to pid: own pid
|
success or wait |
1989582234 |
| Section loaded |
Path: C:\WINDOWS\system32\acctres.dll Access: query and write and read and execute
Type: image Baseaddress: 71780000 Size: 73728 Protection: read write Mapped to pid:
own pid
|
success or wait |
1989583295 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Internet
Account Manager\Accounts Name: NULL
|
success or wait |
1989611396 |
| Section loaded |
Path: C:\Program Files\Common Files\System\wab32.dll Access: write and read and execute
Type: commit Baseaddress: 2BA0000 Size: 512000 Protection: execute Mapped to pid:
own pid
|
success or wait |
1989615001 |
| Section loaded |
Path: C:\Program Files\Common Files\System\wab32.dll Access: write and read and execute
Type: commit Baseaddress: 2BA0000 Size: 512000 Protection: execute Mapped to pid:
own pid
|
success or wait |
1989616679 |
| Section loaded |
Path: C:\Program Files\Common Files\System\wab32.dll Access: query and write and read
and execute Type: image Baseaddress: 470D0000 Size: 528384 Protection: read write
Mapped to pid: own pid
|
success or wait |
1989617501 |
| Section loaded |
Path: C:\Program Files\Common Files\System\wab32res.dll Access: write and read and
execute Type: commit Baseaddress: 2BA0000 Size: 249856 Protection: execute Mapped
to pid: own pid
|
success or wait |
1989626034 |
| Section loaded |
Path: C:\Program Files\Common Files\System\wab32res.dll Access: write and read and
execute Type: commit Baseaddress: 2BA0000 Size: 249856 Protection: execute Mapped
to pid: own pid
|
success or wait |
1989627733 |
| Section loaded |
Path: C:\Program Files\Common Files\System\wab32res.dll Access: query and write and
read and execute Type: image Baseaddress: 35F40000 Size: 258048 Protection: read write
Mapped to pid: own pid
|
success or wait |
1989628625 |
| System info queried |
Type: ProcessInformation |
success or wait |
1989741685 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 2B80000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1989744223 |
| Section loaded |
Path: C:\WINDOWS\system32\msident.dll Access: write and read and execute Type: commit
Baseaddress: 2B80000 Size: 53248 Protection: execute Mapped to pid: own pid
|
success or wait |
1989817399 |
| Section loaded |
Path: C:\WINDOWS\system32\msident.dll Access: write and read and execute Type: commit
Baseaddress: 2B80000 Size: 53248 Protection: execute Mapped to pid: own pid
|
success or wait |
1989819268 |
| Section loaded |
Path: C:\WINDOWS\system32\msident.dll Access: query and write and read and execute
Type: image Baseaddress: 608A0000 Size: 61440 Protection: read write Mapped to pid:
own pid
|
success or wait |
1989820296 |
| Section loaded |
Path: C:\WINDOWS\system32\msident.dll Access: read Type: commit Baseaddress: 2B80000
Size: 53248 Protection: readonly Mapped to pid: own pid
|
success or wait |
1989827459 |
| Section loaded |
Path: C:\WINDOWS\system32\msidntld.dll Access: write and read and execute Type: commit
Baseaddress: 2B80000 Size: 16384 Protection: execute Mapped to pid: own pid
|
success or wait |
1989844568 |
| Section loaded |
Path: C:\WINDOWS\system32\msidntld.dll Access: write and read and execute Type: commit
Baseaddress: 2B80000 Size: 16384 Protection: execute Mapped to pid: own pid
|
success or wait |
1989849446 |
| Section loaded |
Path: C:\WINDOWS\system32\msidntld.dll Access: query and write and read and execute
Type: image Baseaddress: 60890000 Size: 24576 Protection: read write Mapped to pid:
own pid
|
success or wait |
1989850652 |
| System info queried |
Type: ProcessInformation |
success or wait |
1989859291 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 2BE0000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1989862173 |
| Section loaded |
Path: \KnownDlls\PSTOREC.DLL Access: write and read and execute Type: unknown Baseaddress:
2BE0000 Size: 12288 Protection: read write Mapped to pid: own pid
|
object name not found |
1989866440 |
| Section loaded |
Path: C:\WINDOWS\system32\pstorec.dll Access: query and write and read and execute
Type: image Baseaddress: 5E0C0000 Size: 53248 Protection: read write Mapped to pid:
own pid
|
success or wait |
1989868416 |
| Section loaded |
Path: C:\Program Files\Outlook Express\msoe.dll Access: write and read and execute
Type: commit Baseaddress: 2C70000 Size: 1318912 Protection: execute Mapped to pid:
own pid
|
success or wait |
1989926876 |
| Section loaded |
Path: C:\Program Files\Outlook Express\msoe.dll Access: write and read and execute
Type: commit Baseaddress: 2C70000 Size: 1318912 Protection: execute Mapped to pid:
own pid
|
success or wait |
1989929403 |
| Section loaded |
Path: C:\Program Files\Outlook Express\msoe.dll Access: query and write and read and
execute Type: image Baseaddress: 60330000 Size: 1347584 Protection: read write Mapped
to pid: own pid
|
success or wait |
1989930374 |
| Section loaded |
Path: \KnownDlls\INETCOMM.dll Access: write and read and execute Type: unknown Baseaddress:
60330000 Size: 1347584 Protection: read write Mapped to pid: own pid
|
object name not found |
1989937959 |
| Section loaded |
Path: C:\WINDOWS\system32\inetcomm.dll Access: query and write and read and execute
Type: image Baseaddress: 76150000 Size: 712704 Protection: read write Mapped to pid:
own pid
|
success or wait |
1989939986 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
1990277613 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit
Baseaddress: 2BE0000 Size: 4096 Protection: execute Mapped to pid: own pid
|
success or wait |
1990509018 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress:
2BE0000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
1990510127 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: 2BE0000
Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
1990516082 |
| Section loaded |
Path: C:\WINDOWS\system32\inetres.dll Access: write and read and execute Type: commit
Baseaddress: 2BF0000 Size: 49152 Protection: execute Mapped to pid: own pid
|
success or wait |
1990562375 |
| Section loaded |
Path: C:\WINDOWS\system32\inetres.dll Access: write and read and execute Type: commit
Baseaddress: 2BE0000 Size: 49152 Protection: execute Mapped to pid: own pid
|
success or wait |
1990572440 |
| Section loaded |
Path: C:\WINDOWS\system32\inetres.dll Access: query and write and read and execute
Type: image Baseaddress: 2BF0000 Size: 57344 Protection: read write Mapped to pid:
own pid
|
conflicting addresses |
1990575656 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit
Baseaddress: 2C70000 Size: 4096 Protection: execute Mapped to pid: own pid
|
success or wait |
1990645314 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress:
2C70000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
1990648485 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: 2C70000
Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
1990655685 |
| Section loaded |
Path: C:\Program Files\Outlook Express\msoeres.dll Access: write and read and execute
Type: commit Baseaddress: 2C90000 Size: 2482176 Protection: execute Mapped to pid:
own pid
|
success or wait |
1990707462 |
| Section loaded |
Path: C:\Program Files\Outlook Express\msoeres.dll Access: write and read and execute
Type: commit Baseaddress: 2C90000 Size: 2482176 Protection: execute Mapped to pid:
own pid
|
success or wait |
1990716750 |
| Section loaded |
Path: C:\Program Files\Outlook Express\msoeres.dll Access: query and write and read
and execute Type: image Baseaddress: 2C90000 Size: 2486272 Protection: read write
Mapped to pid: own pid
|
conflicting addresses |
1990720162 |
| Section loaded |
Path: C:\Program Files\Common Files\System\directdb.dll Access: write and read and
execute Type: commit Baseaddress: 2EF0000 Size: 90112 Protection: execute Mapped to
pid: own pid
|
success or wait |
1990806877 |
| Section loaded |
Path: C:\Program Files\Common Files\System\directdb.dll Access: write and read and
execute Type: commit Baseaddress: 2EF0000 Size: 90112 Protection: execute Mapped to
pid: own pid
|
success or wait |
1990811387 |
| Section loaded |
Path: C:\Program Files\Common Files\System\directdb.dll Access: query and write and
read and execute Type: image Baseaddress: 6CDF0000 Size: 102400 Protection: read write
Mapped to pid: own pid
|
success or wait |
1990814134 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
1990959212 |
| Section loaded |
Path: \BaseNamedObjects\microsoft_thor_folder_notifyinfo_mappedfile Access: query
and write and read Type: commit Baseaddress: 2C70000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
1991000695 |
| System info queried |
Type: ProcessInformation |
success or wait |
1991004068 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 2F30000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1991010793 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
1991689238 |
| Section loaded |
Path: \NLS\NlsSectionCP20127 Access: read Type: unknown Baseaddress: 2F30000 Size:
69632 Protection: readonly Mapped to pid: own pid
|
success or wait |
1992023893 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: E8 C1 69 AB 94 52 1E 42 DD C3 DA FA EB 82 38 2A B0
03 29 3A 73 7F 61 22 EC 5F 7B E6 1F F6 F6 81 FE 5D B8 7D 34 14 36 02 95 58 0C 87 50
BC 83 6D DF 05 38 CE BC 67 16 7D 31 6E 30 C4 6E 8C 79 D4 89 44 F5 FC 05 4C CC 6A 75
74 38 5E 51 74 C5 E3 7A 6D 52 F7 F8 3C 52 43 7E CE B5 41 E0 E8 B0 C8 0D B9 6D 80
|
success or wait |
1992345188 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
1992441373 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: 4B A0 43 33 C1 56 F2 0D 6D 52 6F D7 8D 83 39 5D C1
F9 66 58 E3 98 C7 F3 71 C2 06 68 82 AF 9D 81 FF BE 63 E1 5F A8 52 D2 90 C3 E9 24 3D
78 5F 5D 79 66 A8 56 C3 F2 73 44 CF E3 1E 10 22 3A CC 01 66 54 46 51 88 FA 51 47 33
1C 46 77 81 CC A8 08 1C 68 AA A3 A2 49 1E 71 ED B4 08 B0 D9 BF FE 80 A5 A4 E0 5E
|
success or wait |
1992542998 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: AD 0F E4 12 EE 04 3B C8 AB 15 36 28 0D 06 3B 69 EE
2C 34 F2 B3 4F F9 F3 E9 08 DE AD DF B9 81 B3 8B A0 AD 09 9B FE 6A 6A 2C 25 4A 46 90
80 F1 7A 5E CE 5A 09 5C 0A 51 0B D0 10 EA 6A AB DF AF 4A 51 89 6E BB 3B 58 74 5F 1E
5B 74 DA 80 AA 25 47 3B 6E AF AE E5 A5 79 4E 8A EF 85 43 27 0B A1 99 F1 53 BD AD
|
success or wait |
1992547803 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: 40 7A AA FC DC 6F 3E FD A6 8D F1 9E 4D 06 D4 91 0E
F6 DF BE 36 13 0E C4 87 9F CC AD BC FA C4 B3 7D 98 B6 30 8E A3 CB 3C 56 8D AD 7D CD
E4 9B 60 6C B4 0B DE 81 11 A6 60 25 10 A9 B5 A4 67 DD 5B 28 D1 CF 5E AD AF 85 88 49
2A 72 F6 11 20 D3 A0 36 42 9A B4 20 69 22 FD 97 B3 EB 12 54 17 66 09 E7 99 79 B4
|
success or wait |
1992550143 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: 69 0A 5D 0F E8 28 EF D7 83 3F D5 75 BB 9E B2 D6 1E
AB 97 EB C2 FD A9 AA 75 FF 38 73 9F 6E F6 93 64 69 0D 8E 6F 8F 20 72 19 86 E9 9D BF
5A 51 91 56 D2 82 06 3A EB E5 3F BF C8 D7 D5 BE F5 ED 95 12 F1 7F CF A4 41 CF 62 94
06 A1 E1 C8 F7 70 32 0A E9 5B CA CC CD EC 60 E4 22 99 22 D4 56 96 38 EB 55 42 97
|
success or wait |
1992746103 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: 06 E6 19 3F F2 33 1F 1F 6E 49 0C 0F BB 9D 5B B0 7B
AF AF 26 F2 57 DB 20 4C 9F 88 97 15 B1 77 C8 7A 04 D9 06 C8 77 42 58 16 4B CA F6 87
57 6B 22 61 AC 13 88 B4 D6 0A 4D 35 9C F3 E1 75 40 D0 6C 9F 65 27 7F 56 1C 67 C9 FF
08 21 A7 D0 88 D0 87 B0 C7 CB 4F 2A 32 DA 07 C4 F3 32 9D E1 AF 47 11 B7 86 1D 26
|
success or wait |
1992749014 |
| System info queried |
Type: ProcessInformation |
success or wait |
1992793032 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: F5 0A 07 02 C0 AD 24 83 3D ED 6B 4A EB 83 BA 5E 31
C1 6A 1F 83 E6 CB 3C 91 E1 9B FA 32 AD 28 4D BC D6 4B EF D1 E2 13 83 C3 4D 11 94 AA
3F 75 87 FC EB 0B 01 DC 20 C0 71 44 74 D8 BF CB 6B 24 CD B0 A4 58 6D C2 8B 7E C5 09
4E 3F F1 B0 C2 23 B4 54 92 9A 21 EA 50 BB 3A 96 14 06 D2 D2 3C 6F F9 D8 EC 83 EE
|
success or wait |
1992799817 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 2FC0000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1992801824 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: 99 21 0E BB BA 67 24 15 C4 64 3C 37 3D 6C 54 0B 5A
CF FB C6 AC 08 5C 2C 48 C2 7D F6 DE 31 94 AE EA C8 39 B6 06 07 60 63 D4 89 B0 9F 07
53 24 95 12 99 B1 6C A3 0C 8B 73 D5 78 07 8B A1 BB 93 3E 35 3E A8 04 03 F0 A1 92 CA
8B 6F 35 EE BE 33 99 2A 81 23 2D 0F 24 40 0F CA 8C 06 42 D1 E1 19 22 48 4F D4 E4
|
success or wait |
1992900646 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: 64 86 61 BB EB F4 CF 9F 97 BF 46 C0 FF F4 19 94 0A
0C 2C 70 41 F3 3F A1 3A 02 E2 32 66 48 39 4C EB 9B 1E 99 D7 79 0F 60 6F C5 1E 58 12
2B 7A 79 AF 0C F0 D5 E9 40 45 1F BC D7 9B A1 DA DB 1B 9A A9 14 1E 42 32 ED 88 A4 FC
F1 09 B5 45 26 FC 3B 96 18 25 E2 2D D8 1D 82 69 0F 29 8D 7A 23 60 6C A1 9E E0 CA
|
success or wait |
1992967609 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_folders.dbx_directdbshare
Access: query and write and read and execute and
extend size Type: unknown Baseaddress:
2FC0000 Size: 12288 Protection: read write
Mapped to pid: own pid
|
object name not found |
1992985862 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_folders.dbx_directdbshare
Access: query and write and read Type: commit
Baseaddress: 2FC0000 Size: 28672 Protection:
read write Mapped to pid: own pid
|
success or wait |
1992986329 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_folders.dbx_directdbfilemap
Access: query and write and read and execute and
extend size Type: unknown Baseaddress:
2FC0000 Size: 28672 Protection: read write
Mapped to pid: own pid
|
object name not found |
1992987764 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_folders.dbx_directdbfilemap
Access: query and write and read Type: commit
Baseaddress: 2FD0000 Size: 12288 Protection:
read write Mapped to pid: own pid
|
success or wait |
1992988224 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_folders.dbx_directdbfilemap
Access: query and write and read and execute and
extend size Type: unknown Baseaddress:
2FD0000 Size: 12288 Protection: read write
Mapped to pid: own pid
|
object name not found |
1992996648 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_folders.dbx_directdbfilemap
Access: query and write and read Type: commit
Baseaddress: 2FE0000 Size: 77824 Protection:
read write Mapped to pid: own pid
|
success or wait |
1992997136 |
| Section loaded |
Path: \BaseNamedObjects\c:_documents and settings_administrator_local settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook express_inbox.dbx_directdbshare
Access: query and write and read and execute and extend size Type: unknown Baseaddress:
2FE0000 Size: 77824 Protection: read write Mapped to pid: own pid
|
object name not found |
1993028901 |
| Section loaded |
Path: \BaseNamedObjects\c:_documents and settings_administrator_local settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook express_inbox.dbx_directdbshare
Access: query and write and read Type: commit Baseaddress: 3010000 Size: 28672 Protection:
read write Mapped to pid: own pid
|
success or wait |
1993029386 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_inbox.dbx_directdbfilemap
Access: query and write and read and execute and
extend size Type: unknown Baseaddress:
3010000 Size: 28672 Protection: read write
Mapped to pid: own pid
|
object name not found |
1993030864 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_inbox.dbx_directdbfilemap
Access: query and write and read Type: commit
Baseaddress: 3020000 Size: 12288 Protection:
read write Mapped to pid: own pid
|
success or wait |
1993031344 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_inbox.dbx_directdbfilemap
Access: query and write and read and execute and
extend size Type: unknown Baseaddress:
3020000 Size: 12288 Protection: read write
Mapped to pid: own pid
|
object name not found |
1993042693 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_inbox.dbx_directdbfilemap
Access: query and write and read Type: commit
Baseaddress: 3030000 Size: 77824 Protection:
read write Mapped to pid: own pid
|
success or wait |
1993043217 |
| Section loaded |
Path: C:\Program Files\Common Files\System\wab32.dll Access: write and read and execute
Type: commit Baseaddress: 3050000 Size: 512000 Protection: execute Mapped to pid:
own pid
|
success or wait |
1993045686 |
| Section loaded |
Path: C:\Program Files\Common Files\System\wab32.dll Access: write and read and execute
Type: commit Baseaddress: 3050000 Size: 512000 Protection: execute Mapped to pid:
own pid
|
success or wait |
1993046565 |
| Section loaded |
Path: C:\Program Files\Common Files\System\wab32.dll Access: query and write and read
and execute Type: image Baseaddress: 470D0000 Size: 528384 Protection: read write
Mapped to pid: own pid
|
success or wait |
1993048493 |
| Section loaded |
Path: C:\Program Files\Common Files\System\wab32res.dll Access: write and read and
execute Type: commit Baseaddress: 3050000 Size: 249856 Protection: execute Mapped
to pid: own pid
|
success or wait |
1993059979 |
| Section loaded |
Path: C:\Program Files\Common Files\System\wab32res.dll Access: write and read and
execute Type: commit Baseaddress: 3050000 Size: 249856 Protection: execute Mapped
to pid: own pid
|
success or wait |
1993062698 |
| Section loaded |
Path: C:\Program Files\Common Files\System\wab32res.dll Access: query and write and
read and execute Type: image Baseaddress: 35F40000 Size: 258048 Protection: read write
Mapped to pid: own pid
|
success or wait |
1993065504 |
| System info queried |
Type: ProcessInformation |
success or wait |
1993083891 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 30D0000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1993091206 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
1993139700 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: 6C 75 A2 8D 31 72 F1 A3 5E 50 ED 39 53 3A 83 BF F9
58 E0 29 83 C5 0A 41 63 38 AF C6 91 CA FA 77 BC 31 B9 46 77 6F 84 DE 5A 3B A7 53 97
1A C5 71 97 B1 0B 98 AC 9A 1E BC B8 CF 89 C0 CB 33 50 E5 23 BC 00 CE FC FB A5 24 2E
E5 B2 72 29 36 24 41 36 66 56 C0 12 5C 7E 95 9A B5 D4 FC 7A 5F 20 6E 87 79 F9 E9
|
success or wait |
1993158508 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: 55 DF FB 34 21 8E 82 F1 05 A9 DD 6A 09 2C 6C 26 C3
FE 6A 49 3D E4 4E 7E C5 95 D4 28 23 C1 88 3B 1A EC A4 2C 06 3E 00 C0 B3 EF B5 2B F4
4E 8B 88 56 59 A4 7C 94 F7 E4 17 68 95 CF 66 DB 38 4E C2 A1 F8 32 BA B2 66 BE 23 92
07 E9 2F 72 AB 96 14 FF A0 2E AA EF 4C 56 A9 15 5B 33 91 B2 9A 78 B7 19 A9 3D 3A
|
success or wait |
1993228423 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: 47 16 31 87 DF 4B C8 C1 6E C4 05 8B EC BB 28 A3 3F
2B 4B 09 56 28 69 C3 99 C5 5D 06 F8 85 2E E5 F0 40 A4 C4 47 BF 20 D0 14 70 87 C4 DF
41 7D 63 6F 5A 4C 81 DA B4 C6 4B F3 10 75 C9 16 77 CF 1B 99 60 08 4B 0E 2B D6 67 C0
1A 54 23 93 3F F3 8A 6D 4B 1E BF 28 F0 89 72 42 30 E8 46 C7 0A E3 84 59 1B CB 89
|
success or wait |
1993247261 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: F0 BB 4A AD BD 92 DF 03 56 3C C6 19 5D 67 A4 EB F6
05 92 85 D1 8E 97 0D EA E0 E1 56 BC A4 F5 39 30 89 FB 69 D3 1C BC 0E 35 72 4F 8C 60
CC F7 A8 D5 36 3D AF 44 68 46 05 65 3B C1 9A 20 83 79 0D A5 3D DE 63 47 83 83 5C 9C
5A C7 BC 93 7E 0E A6 89 7F 5E D3 D8 6F 11 2B 84 BD 58 9A 0C 97 09 3C 22 27 84 DF
|
success or wait |
1993403227 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: E0 7A AB 29 B6 64 36 09 DC 1C D2 4A 01 94 5D 59 3E
54 E3 69 EA 14 20 AB 88 7C 09 41 6D 20 90 2B 01 41 8B 3D 69 FE 00 11 C3 D7 38 CB 5A
69 08 7C 14 4F 7C 5C 2B BD 43 33 3F 0C 57 95 D3 B2 2B 28 CE F3 8D B1 22 AD 0A FC C2
4A 43 48 15 C3 C1 3C 63 A4 05 F6 BB 26 16 0B 87 8F 39 B9 5A A0 B7 41 22 DF 59 EF
|
success or wait |
1993413014 |
| Section loaded |
Path: C:\WINDOWS\system32\mshtml.dll Access: write and read and execute Type: commit
Baseaddress: 30F0000 Size: 5963776 Protection: execute Mapped to pid: own pid
|
success or wait |
1993500750 |
| Section loaded |
Path: C:\WINDOWS\system32\mshtml.dll Access: write and read and execute Type: commit
Baseaddress: 30F0000 Size: 5963776 Protection: execute Mapped to pid: own pid
|
success or wait |
1993505483 |
| Section loaded |
Path: C:\WINDOWS\system32\mshtml.dll Access: query and write and read and execute
Type: image Baseaddress: 3CEA0000 Size: 5976064 Protection: read write Mapped to pid:
own pid
|
success or wait |
1993508554 |
| Section loaded |
Path: \KnownDlls\msls31.dll Access: write and read and execute Type: unknown Baseaddress:
3CEA0000 Size: 5976064 Protection: read write Mapped to pid: own pid
|
object name not found |
1993526913 |
| Section loaded |
Path: C:\WINDOWS\system32\msls31.dll Access: query and write and read and execute
Type: image Baseaddress: 30F0000 Size: 167936 Protection: read write Mapped to pid:
own pid
|
conflicting addresses |
1993531176 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: 97 2B F4 DB 30 C7 B2 CF 0A 5C 73 23 48 93 F9 EB 95
0A 71 FC 03 53 82 D6 5E D8 E0 CA D1 01 93 46 AE 54 9D E3 A3 27 13 17 4A B4 26 08 EE
F3 94 0D A1 4A 83 36 39 FA 0E 64 DD 21 7C 40 B3 68 B6 62 2E D7 47 F8 30 4E 78 5F C5
8E 45 2C B6 7C B5 5C 13 72 A6 5C ED DC 8D 09 FD E6 1C 98 41 3F B2 4D 7C 3D 98 52
|
success or wait |
1993541289 |
| Section loaded |
Path: \BaseNamedObjects\#MSHTML#PERF#00000664 Access: write Type: unknown Baseaddress:
30F0000 Size: 167936 Protection: read write Mapped to pid: own pid
|
object name not found |
1993614831 |
| System info queried |
Type: ProcessInformation |
success or wait |
1993622127 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: E4 53 3B CB C0 3B D0 3D 6F 73 3A 50 80 15 EB 8C F7
D2 57 CE 71 89 06 57 D1 01 AA 74 3D CA 2B 8E 04 08 1D 6D 3D A4 60 39 3A 84 24 C4 43
58 1E CB 56 E3 67 F1 3F 44 E7 B8 7D 93 00 04 5A 1A 7F E5 D7 12 BF 2D D9 59 C9 EF C3
24 95 36 08 EB E4 DF 91 A4 28 53 08 DB EE 2D 41 39 81 BE 3E 9A 81 E8 DE 58 DB 3F
|
success or wait |
1993637066 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 3160000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1993641116 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: 1F B1 4D 5A F6 09 0F E7 6D 47 FC DC 0A 33 7C B7 3B
DC DC 41 E0 72 B6 AE 39 0F DD A0 69 48 92 E4 4C 24 C7 C3 6C FD C0 A2 FC EF 53 DD BC
14 01 48 4A 99 E6 AE 6E FE A9 2B 3E 4D 63 09 09 9A BE E9 3D D0 BF 0F DF 1C CF 78 0D
50 72 87 2B D1 FB 5E 60 28 11 B2 1B D3 BB 0F 34 13 23 00 9A 4C 24 14 A8 77 03 43
|
success or wait |
1993862495 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
1993872773 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: C6 11 BD 48 D2 BF 05 A0 B4 A0 92 93 52 56 2F 88 C5
E2 F8 64 B1 09 8D DA 73 2B C8 1C 9F FB 67 76 CB 6C 86 92 FD 23 94 F4 90 97 7D C1 DB
EE E5 21 5F A6 6F F1 24 48 47 46 76 13 FC ED 9E 7C 77 B5 DA E2 19 1E CD B7 D3 DA A2
06 55 67 E9 7D 1B E7 88 7B 3B 98 02 0B 8B 2D E3 B1 D6 71 C0 2A 31 EA 52 60 6A D4
|
success or wait |
1993895561 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: 45 86 E2 26 84 33 7B BD DA 94 CB 05 CB 8E 38 E1 1A
1B DE 83 EE 83 4E C9 E1 6E BB 27 08 B4 DE E0 D2 79 B7 1C 08 B5 14 03 42 DB C2 DD 3B
CF 52 BF 5F 38 91 41 49 C0 8F C8 22 A2 F9 B4 11 65 1C 14 45 7B B5 72 41 F9 FD 4B E5
32 08 4B 2B 6D 3E 26 37 A4 CC B7 14 34 C3 63 21 21 88 F3 96 51 8F D3 42 F5 EA 44
|
success or wait |
1993936557 |
| System info queried |
Type: ProcessInformation |
success or wait |
1993964782 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 31A0000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1993972378 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: E5 62 4D 93 43 E1 F9 4D 0E 85 91 3C 76 5A 00 74 E3
0C 35 EC DA 89 05 37 DA C7 8F A4 CC F9 24 DB 1F 41 F3 72 D3 20 A2 40 0C CD 3B 0A D4
1E 74 5D F2 32 D9 72 61 4B 93 12 4F 80 3D 55 CC 2E DC 84 3F 57 24 BF 22 C3 EB 32 2D
50 FA ED B9 0C 68 41 8F 95 83 72 5D C8 4F 72 9E 19 B3 48 7F CC 9D A3 02 1A 3F F7
|
success or wait |
1994009624 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: 79 45 F7 35 5A CC E9 5E 7B C6 CD 62 EA 48 85 12 E5
21 ED 74 83 A2 25 AD ED A8 0D DF E0 13 E9 99 CC 88 D8 E7 FB 6C 54 71 C4 67 7F 06 3A
78 B0 85 3D 22 CA 97 70 52 0A F6 2B 6E 67 AE 28 74 C1 99 96 07 82 E4 55 C7 E3 B9 B7
4A 93 76 9D 27 78 50 F3 FB 65 AB E4 D6 C9 04 A4 EA E4 FA 9E A1 E7 7D 7C 2F 8E F1
|
success or wait |
1994015149 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: F0 5E E3 6E FE 69 0C FF 5C A3 90 11 C8 13 B5 D0 62
A1 31 D5 43 DE 59 86 E0 9D 5E EF E4 AB BF 02 0E D1 F7 FE CC DD 16 E1 7B AB B3 8A CE
1B E1 B4 38 4F 6C 56 D5 4C F6 C2 52 4A 54 DC D8 96 CC 7E 66 18 3D B4 78 14 39 AB 58
36 29 17 29 50 8B D7 3C B7 20 A1 74 F5 0F B8 1C 34 43 B4 5A A2 F7 BA 08 97 0D 6F
|
success or wait |
1994053967 |
| System info queried |
Type: ProcessInformation |
success or wait |
1994135371 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 31E0000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1994138036 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: 75 C6 03 D3 5E 26 EE 7B 44 60 57 30 0C BC 13 BA 64
80 EF 96 96 BD 44 9A F2 B1 16 E5 D3 A0 93 E7 6C 1F 40 6A 9E 12 57 A2 6C 4D 9B B5 F7
79 45 CA 19 05 2A 69 D6 15 12 D9 D2 03 52 C3 D3 84 82 58 A2 76 07 37 72 90 FF 08 F5
99 D8 F1 3C B7 4F 7F 3A FC 74 9D 13 A4 1C D7 15 8A DD 06 B9 73 0E 06 9F 39 65 01
|
success or wait |
1994150802 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: AE 8B F3 EC EC 9A BF BC 8C 2E 61 D2 36 44 41 85 C2
34 10 70 09 23 9A 76 2F 07 EC FD 89 BE B0 DB C5 A5 96 6A CC 13 F7 4A CE 2B 88 D4 4E
37 D2 28 0E E9 92 6D 49 59 0E 6E 69 65 95 6A 1F CB C6 16 EA 3D F2 C7 DA 8F 1F 22 AE
BB 5E 11 9C D0 F8 BB FC D5 6E F5 74 18 48 5B 99 81 0F 81 9E 01 C5 69 FA 9B C2 E6
|
success or wait |
1994189667 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 4096 Value: C1 37 E5 67 CB 5E 73 D8 5B 88 F8 C7 95 4E 72 59 D5
95 AC 28 B9 2D 5E CE 6E 7B 87 E8 20 75 95 16 6C 0A D4 9F 3F 4E 01 0B 8D 99 16 A6 2A
6F B4 36 62 33 E6 61 4B CF D8 86 87 18 82 95 4E A5 2B D2 8F 12 9D 09 5C 4E 74 C4 1B
A9 38 21 A3 BA 1B FB 8D D5 35 AF 17 4E A3 76 CA DC 22 37 1A 08 C0 4F 49 1C 50 3D
|
success or wait |
1994431778 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\profi[1].bin
Offset: none Length: 3090 Value: 3D DA 00 B7 2C F6 EF 92 FD B5 B9 ED 86 86 47 E7 E3
8E D9 08 D5 5F B3 C6 54 ED 57 A0 E1 31 51 2B 54 BD 62 13 D0 06 7B 2A 0A 3A 35 67 C5
36 B7 40 FE B3 27 0F 87 CF 90 15 2F FC 1E 9A 32 62 5D B0 1E 9E 32 F7 F7 01 70 F8 9C
6F 74 73 4A 2E 1A 68 DF EC 83 31 E8 55 6E 79 CC 1F 30 AC 04 05 BD 18 0F C9 DE 91
|
success or wait |
1994434495 |
| System info queried |
Type: ProcessInformation |
success or wait |
1994480782 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 3220000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1994483433 |
| Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\OUTLLIB.DLL Access: write and read
and execute Type: commit Baseaddress: 3220000 Size: 7569408 Protection: execute Mapped
to pid: own pid
|
success or wait |
1994589590 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
1994591695 |
| Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\OUTLLIB.DLL Access: query and read
Type: commit Baseaddress: 3220000 Size: 7569408 Protection: readonly Mapped to pid:
own pid
|
success or wait |
1994592415 |
| Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\OUTLLIB.DLL Access: write and read
and execute Type: commit Baseaddress: 3220000 Size: 7569408 Protection: execute Mapped
to pid: own pid
|
success or wait |
1994605873 |
| Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\OUTLLIB.DLL Access: query and read
Type: commit Baseaddress: 3220000 Size: 7569408 Protection: readonly Mapped to pid:
own pid
|
success or wait |
1994607073 |
| Section loaded |
Path: \BaseNamedObjects\Local\!PrivacIE!SharedMem!Counter Access: query and write
and read Type: commit Baseaddress: 3220000 Size: 4096 Protection: read write Mapped
to pid: own pid
|
success or wait |
1994629270 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Giid
Name: Ebci Type: Binary Data: C9 AB 5E 55 DA 26 82 2F 4E DD F6 8A BA 2B AF D4 47 12
B4 F7 9C 4E 33 A6 B5 91 12 6A 9D 00 42 87 D5 EF DB 53 1E AA 37 10 99 7C 93 77 F5 53
4F E1 FD 38 2F A5 38 17 6F 96 8E 75 8A 56 83 BE D0 5F 29 9C 0A 2C DF F7 6B 20 FF 4B
95 65 73 8A AA 94 55 98 A5 8C 27 68 47 82 6C D7 4D 11 0B 51 6E 6F 59 F0 C8 8A 60 5E
7A 40 1C 04 2D D4 B6 B7 B6 C9 D0 AE 0F 66 CA 58 7E BA D8 4E CD CD FA 72 AB EF 1D 4E
BC FE 49 E0 42 E6 10 4E B9 32 BC 54 2E 85 67 35 6A 2F 0A 3F E4 EE 44 4A EA 0A 00 A9
D9 22 37 85 0A CB 44 F8 15 DE CC 30 09 E9 DA 51 9E 03 68 43 21 DA 03 5F 95 7C 82 EF
40 9B D0 18 D3 C0 64 77 45 34 E1 72 F3 F4 52 2E C7 6B 38 EB 29 18 FC DE 3F 7C A0 75
48 3D 5C 7C CB AF 2D A0 B1 DE 00 B5 4A 9C 1F DD AF 0C 18 C5 60 C5 9C 57 A7 B8 1A 08
F9 0E 45 D8 BB 3D FC 4B F6 A6 22 53 3A 5D 0C B5 FA 68 81 DB 5D 01 DF D1 5A D0 0A 3B
10 56 01 92 82 0B CE 33 E2 DA 7C D2 3C 76 16 5A 14 15 D8 53 CA 3C EE 68 46 1C 3F 34
62 67 71 09 FB D8 28 DE 8F AD 50 62 09 5B 77 A7 F4 B1 7E 2E E2 5C 53 93 D6 B7 C2 73
1B D0 8C FE E4 6D CD DB 97 F3 8F AB A4 62 A2 E1 E4 03 13 8B CA AE 83 54 B4 23 98 0C
A7 0C 77 71 67 32 28 F4 0B 2F 6A 49 B9 EF 36 23 D8 E4 9B 67 6A F3 AF 57 D0 B8 B4 72
11 7B DD 25 03 9B 23 D7 CC 82 37 1B 74 55 0E 5E 8E A7 68 B5 6D 79 62 5E 33 0A E1 1E
DE 02 2D ED F2 13 45 19 E3 CA 1F 50 3B 36 80 3F BA 70 11 E0 17 19 AB 4F 89 D8 38 78
86 85 CD 0D 09 18 80 19 3B D9 4B D6 B7 DA 3D E1 38 A8 91 44 51 62 F2 55 16 A7 9A 8F
AF 12 7A 5B 72 1C BA 80 C5 FD 5A 72 0D 7E 5D 4B C1 E9 EA EB F8 2F E9 40 99 1D BD 65
F6 FA D6 D0 A6 5A 28 FE 1C 75 00 CB 81 0E 3E D0 CA 2E 6B 1D 8D DF 86 A5 E4 A5 39 9B
8E 0C 21 92 33 F6 43 39 E0 48 0E 74 11 CC F2 B0 17 C4 D0 57 52 79 9D 18 37 D4 FE C2
3C 2A 6A AC BF DE 04 C8 86 A5 98 16 F1 D4 99 00 FB 8B D3 51 72 D4 A8 B3 BB A0 F7 C2
14 8F 97 D7 F2 3D 43 AC 25 BD 6B 20 34 6C 46 AD 47 E7 1C 63 E7 53 1A 02 AF 45 39 62
96 DB 2A 70 C1 B8 B3 B6 C5 C9 CE 3A A9 41 CD 90 BF 1F C6 94 A7 43 A3 65 01 D8 F5 54
96 46 EE 35 E7 DE 44 DC 12 45 03 C2 99 59 27 62 08 C7 AC 98 C8 C7 0B BF CD E9 73 DD
0F D4 4D 5B 14 09 F5 14 FA 41 03 4E 09 8B 2A 3A 2E 1C DB D4 9F 5C 95 7F 2C D7 33 28
EA 8B 82 F5 8A 33 DC 0F DE 60 66 F0 FE D8 26 69 4C 6F 16 DF EA 02 0C CB 6E 63 38 C4
F5 CE B5 DA 3F 8B 5F DD CC 4E 2C 85 C3 B9 51 BC 6D 17 1D A3 2E 23 1E 41 39 BD 07 FF
64 53 02 97 B6 D7 C8 DF D0 0E DC 3B F6 1F A0 AA 2F BE DB 75 78 61 66 6B CD 9E 41 40
F0 7B A7 F4 A3 F5 34 6B 8A A2 7A 01 AF 8B 1D 93 91 62 FA 8C 92 B1 9C 25 98 6D 21 C9
F7 EC 3E C2 9D 4E 8C 8B 71 D1 84 9E 68 D2 EC A3 4F CC 0F 65 38 D2 F7 11 61 58 04 20
4B 9F A8 19 0C 25 2F BE DD 17 53 35 BD D8 4C 3C B3 38 C7 BA E9 D0 25 80 9C 7F A6 B7
B8 12 E8 6B A6 E5 4F F7 A2 22 23 27 A4 93 A0 CA 1B 0B 74 D3 CB F5 2B 87 E0 40 9D E8
BD 81 29 59 C5 7D 4C 07 31 CE A4 99 5B DD 12 AA D6 B9 50 95 1D D3 A5 D4 D2 4D 47 55
5F 39 79 7C A4 26 00 EF EF 85 9C 43 F3 03 CC EE 26 F3 90 D5 93 62 52 4F 16 F9 37 89
0F B1 88 FA 5B 71 79 C6 DC E9 7F 79 27 59 D8 98 AA 85 67 DA 4C 5C 99 D5 E6 99 54 94
31 D6 08 15 9F 50 C4 22 51 9D 01 2E B2 60 F0 EF AE FC D8 10 E1 D4 DE BD 2B 82 2A 29
EF 68 AA 78 44 0E 19 B3 88 B6 03 0E B7 2E 76 58 12 1A D7 5B 30 22 95 E9 F0 66 58 C3
D2 F6 6C 69 83 C5 35 80 FC 56 2C 5E 28 23 C4 0C B0 F3 3B EA E1 3B DF B4 B4 28 E7 56
A0 F6 90 57 EF 19 AC EC 15 BD 7B 31 95 BC C8 9E 89 5D AF 19 62 92 BC E4 CE E5 D0 0F
22 72 A6 04 C1 6E F6 E2 10 EB 0A 7D 04 0E DE 1E E1 B2 9C 82 69 56 69 4F 27 4C A0 FF
D6 52 30 E9 3E 33 60 27 2E A8 57 26 E9 6E 9A 4E 04 94 E4 9F C7 5B 1C 09 6F 61 36 78
8F C7 3A A7 A6 A9 C2 B2 A9 F2 D0 BA 24 12 46 2E AD 0B 34 01 79 ED C8 E6 41 10 FE 58
58 C9 8D A4 9A B0 16 B1 00 EF 98 B9 6C C9 44 A7 90 0D 63 93 4E 2E 46 49 08 FF 26 17
8C 7B 08 40 25 29 81 3A 5C 75 04 92 EC B8 3A 40 7B C8 EA F7 6B FC B3 7D 01 A6 7C A6
4D 28 4D 5A 9D 92 1A 59 79 F5 89 AE 3B 72 FE 99 2A 93 E7 BB 04 A3 6C 31 17 15 76 CE
9E 2A 9C 8C 47 28 23 AB 14 7F 27 3C C2 57 AF D3 A2 B4 7D EF E0 57 CA 32 94 FA F4 E1
1D 19 FE BA 6B 3C 7E 14 F6 EB 4A 32 DA 65 35 82 A0 0B 5E D2 32 EB BD 06 7A 0E B6 26
85 D5 A1 22 80 05 82 D1 3B C5 52 83 A8 F0 8C 35 AE 11 4A 1B 39 34 2B 3B C0 D8 31 C1
0B AE 21 50 47 96 90 76 AD 9F EB 83 9B 12 90 C3 C3 B6 81 E0 DB 01 EC AD 06 66 CE BE
63 AC A5 6A F2 90 6D 4A 24 34 B0 B7 24 73 F4 CE A3 28 BF 58 BD A2 8E 25 CA 0D FF 45
5E 1D 33 5B 4D B0 11 A6 B6 88 12 AE EF 7D EA B1 FE FD 98 3C B7 AF 89 A7 9C 98 8B BE
58 AE 02 43 35 22 72 28 96 50 00 1A 7E 81 EE 91 3E 6B 3D 6F BF B7 D3 BC 7B 84 DB 15
A8 5C 87 F4 EF 5E EA 60 80 A9 33 CE E1 16 2C 1F C1 3E 52 F9 12 06 4F 34 F9 E1 74 9F
3D 70 10 5F 0C 16 1A 52 0F 12 E7 E9 B1 A7 A4 64 3B 82 27 83 79 44 90 DA 81 45 3E 67
3A 65 A8 E4 9E B7 8D 8D 5D 7A 28 13 64 09 64 8B F0 FF 3C 54 AB 6F 65 FA F2 E8 27 10
FF 39 4E 4A D4 63 21 69 1A F7 97 98 F0 67 BC CE 43 86 E1 41 E6 71 E1 29 88 3D 3D 2F
CD 30 1D 2A F2 DD 47 A6 AB CF AF 45 96 3A D8 27 C8 5F 53 AC 8E 76 FE 56 6C 7D 5A 2F
08 15 A7 B6 3C 00 31 E8 63 6F 78 F4 2D 4B 20 DF 27 7B 6C C5 58 02 32 29 93 D2 58 F2
89 84 A8 3E 75 DE 27 FF 89 09 EC 47 F7 6D D3 02 9E 82 E3 27 22 62 F1 C0 06 40 AF 0E
18 C9 EB 8F 70 DA 1B 4B 22 79 23 E1 B3 04 26 9D AC 15 DE 4C 1A 05 17 16 3B BF F4 5C
98 F0 63 77 F2 74 E1 3F F5 60 AB 03 67 4C DB 42 38 A8 60 83 FE 62 44 92 D6 C6 5A A4
F6 2C 5F 16 FE 1B 56 2D 17 74 A3 90 E8 AB 5C 27 38 A1 1C 94 74 8C 14 7A D9 89 E2 69
91 7C 82 42 F1 0B 81 1D 2A 72 8F 21 E2 11 F1 BA 60 92 AE 87 54 4B 30 EB A0 A9 AF 6E
74 60 78 E9 56 C3 DA 75 E8 D6 6A 6A 8C CE D2 C8 46 43 C5 E2 CA D1 2D 79 5B 98 3D D1
58 D3 7A 03 E4 2C 56 1B D2 AA 74 59 17 98 47 D3 76 91 7B ED C1 D3 75 1D 15 8C C7 88
DB CB CF E8 AE 7C 34 99 54 B2 3B 51 6E 7F 05 41 C1 58 98 33 74 89 12 FE 9A 52 D7 B1
4F 58 CA 10 F2 7E 03 40 1E 09 D1 83 CB 4A 40 2B E0 6D C4 5C F1 BA EF 2B 30 6E 4A 59
39 01 20 9A A5 72 F6 D2 45 DF BC 9D 42 47 03 BA BB EC 2C 09 62 97 4C F4 F2 F4 4B A0
E8 67 82 FF BE 89 52 F1 D9 F1 74 55 11 23 A2 5C F6 B3 74 F8 14 87 73 91 C4 63 64 85
C0 6D C0 0B ED 71 E8 65 F0 C2 8E 44 AD DE EB 28 2F 67 A9 8B 9F FF C7 AC BD CF 79 4A
DE C2 4A 9B 51 F7 3B F1 F2 D7 C6 BE 7F 29 71 7B 85 D7 B1 75 E2 11 33 1C 17 56 21 C0
F2 76 47 02 2E 40 81 84 50 B5 BE E2 24 60 35 17 25 C9 DD 41 87 51 20 61 55 B7 D7 7A
9D 23 0E 4F B4 A9 7C 2D C8 83 98 07 B1 4D 54 AB 8E 83 33 D9 04 EF EE 1D E2 2D A8 CC
98 5E 0B BD 80 9F 4C A4 09 75 94 16 86 F0 2A 9B 1C D8 1D C8 86 AE 84 2F 06 DE 60 08
68 93 B9 A3 75 92 9A FC EC D0 02 F7 77 0C 82 EF 49 65 9F 0B D3 FB 0D 20 4B BC B7 DB
98 20 9F 19 EF D1 B3 9A F0 E5 83 4C 4F AD CC 1D A9 3A EE E5 79 4F 70 82 44 7A 7F 29
E3 B1 E5 81 86 35 B2 24 19 8D 9C 52 DC AB 44 20 F4 FA 51 00 0C 6C C0 62 7C 29 5A AA
DE 54 DA 24 A1 76 26 3E 57 17 EE 48 A8 58 4A 47 35 70 D1 BB DC 9A 9E D6 5C B8 53 3C
35 5C 45 2A 7B BD 7C 1F 17 90 E6 48 00 B9 4E 89 49 B9 32 3E 22 30 73 ED 65 BA 5C 21
44 26 B0 45 78 F3 FA 81 A8 BB C6 8D 51 ED C5 45 50 CA E8 F2 F1 C9 D1 AB F2 59 EB 46
61 ED E9 5E 33 88 BC 39 99 48 EE CE 58 6D 62 74 88 E5 71 E8 FB 26 31 86 05 28 18 1A
7B 66 10 81 9C 1E E5 64 79 5A 47 EA D8 84 96 A7 5D E5 78 BC 98 68 D4 3D 0B 81 28 EB
2E 4B 73 DC 32 9D E9 DA 24 BE AE 6C 7A F9 E0 8C D9 C5 1C BF B1 DC 2F 65 94 E0 A9 0D
53 C0 11 5E 6D 5B BF 09 1E 60 7B C7 8D 3E 8A FA 2B D7 9F 77 9D 12 DB 07 74 25 18 94
3F DB 17 E0 43 86 6B 4B B5 03 E5 08 D2 13 D4 EB 79 4B 23 94 41 2C BD A0 24 5A C4 30
79 0D C3 6B 7B 81 DD F5 34 BC 5E CA 58 87 57 06 91 A9 50 80 DE 6E FE 95 3E 36 64 7C
F5 71 50 6D 0C 7E EB B9 B8 13 AC 65 99 76 4A 26 E2 64 52 C6 42 2B 38 28 1F E1 D7 BB
B6 39 73 3D 25 C8 1B 63 B6 22 F7 6F EC A8 79 F1 90 CE 4A AE 55 C5 8D 89 E7 F5 A6 36
3A 25 A8 D4 E5 64 37 26 CB 16 BE 57 B9 DB E6 EA 81 3A A9 7B 91 F7 6B 8A 27 0A AA AF
F4 6A D1 59 17 F0 D1 CE BC 3D E8 BD 88 30 92 66 08 AA 48 D8 EF 5E DF AE A7 ED 9F 59
20 DC 2C 3E DA 53 D4 CB 6A C5 ED 8F B9 EC B0 E5 69 59 64 9E 8A E3 AD 9E ED D3 C1 FA
F3 78 FE 15 94 B3 76 97 E7 AE 90 16 94 06 2D B2 52 E0 96 96 98 E2 7F 94 71 F7 EB 5D
0F 47 60 C0 86 B9 A8 6B 87 C5 E3 A0 94 37 6B 63 A2 B0 A0 4B 38 D6 D1 9E 2B 9F 6E 5A
6A 5B CC E9 E2 69 90 1E 93 2C 11 65 7D 95 E0 46 05 4B 6D 6B 3D F6 55 1A C4 47 69 A6
BC 39 5B 6B 9E 60 01 37 FD BB E1 B7 CD BA 36 DA 05 D8 04 F7 34 4B C1 6C E5 C9 A0 6A
86 A6 66 43 FF 75 08 08 03 CF 10 A5 83 1E F9 B1 93 8F C8 9A CC 65 07 51 B8 4D 5E C4
DE 84 B7 A2 69 13 DF 39 23 C6 18 32 B7 8D D5 89 0B 82 08 22 9E 10 14 8D 51 B5 84 61
DC C9 55 16 15 54 99 45 CA 64 02 86 50 23 8A ED 36 7F F6 25 72 17 A4 A8 F1 2B 7E AD
2E DE 6C 17 1E 77 40 13 57 48 92 3B B5 4E A6 EA AA 60 DB 6C 9B B4 58 53 62 46 2A 8F
20 C5 D7 A9 0D 5F 70 64 BE 45 89 3D ED 7C 4A 19 5A BD F7 0A 70 50 B1 3A 6D C8 98 51
54 45 3F D0 72 E5 67 5C ED A7 51 B8 6D 39 06 E5 05 0F A5 65 D7 30 49 A2 13 6E A3 E3
F9 83 5B 90 71 26 AF F8 CA 66 27 DA 9D 5F AC A6 AE CF 1B C5 B9 41 C9 95 79 9D 1D 55
FC 27 3D 6E 66 46 72 60 3B 28 D9 F1 DA ED EF 97 FB E1 BA FD 11 51 D1 EC 8E 1C 29 C7
12 1A 16 0B 39 8B 5B 3E FB 9E 8F 43 C0 0B F4 1A A8 A1 43 11 DA D4 53 AC FA CA 0B 6E
00 B5 F7 57 E1 6C 5B 4C EA 1B 3D CF E6 1B 54 DF 55 3F AA EA 44 6D 02 64 20 CD 78 F4
B6 C5 FF 82 8A B4 68 D5 2C 2A C4 94 6E 0C 8B B6 51 64 15 A6 9E D4 BB 2B 78 54 E1 51
78 94 0F AB 18 83 37 E8 62 12 74 8D E3 C2 61 46 D2 D9 6D 92 86 31 4C 34 D7 97 07 64
3B 9A BB 07 FE 7A C6 2F 29 AC 22 13 FC 0F 25 46 6D 2D 9B 4B 48 B8 DB 99 F7 6F 6D F8
2F B4 DF BD 38 A5 F6 84 A7 6B 17 77 22 F6 41 B9 8C CF F6 8B 2C F0 8E A6 98 4B 9C 67
31 1C 0E 36 A4 12 04 63 3D A6 B7 8E 33 8F E3 A1 90 8C 5D ED 70 E8 96 08 A5 CE 1D 08
FC 6C D7 F2 03 17 8F 05 F9 D6 83 C7 BE 8F 72 30 A0 C7 A0 AB 17 84 D8 03 D1 14 20 AB
F4 09 06 5D FF 64 9F CE CA EC 5F 39 60 84 15 A7 70 D8 CF 82 A0 A6 DD 13 0E 9A F0 F9
D4 AB E0 F5 F6 F7 60 26 70 36 06 18 23 D4 96 06 D2 58 AD 97 C7 48 28 27 91 B7 81 8A
2E 5B 7E 04 74 9A 4E 73 AB 1E 16 36 6A 9B F0 74 BA A1 62 C7 37 9E B8 0D 13 50 17 09
53 29 8A E1 26 CE 2C 23 C6 BF A0 01 42 C0 67 84 81 94 74 F5 C4 66 A3 1E EC 3A B0 B1
C8 17 BF E5 DC EB 60 CC F1 94 90 6D 80 2E 9A 78 36 01 AE 4A CD 3D F8 D6 34 27 DC 06
12 18 A0 F3 0C 3B 1E 73 EC 54 5E A9 06 D5 F0 8A 2A B1 13 CF 8D 0C B4 FC 71 8D 8F 67
44 97 56 0D C8 2E FD 5F 69 51 B4 42 D7 75 4F 54 F0 F7 A1 6D F6 0B 9A 76 57 16 47 6F
12 CB A7 BB DA 36 C3 62 45 01 3B 89 AD A5 DA 87 56 CB 68 38 1E 06 C3 AC 2A 90 38 26
2D 0E 84 04 08 A4 E1 D9 9E 8C 78 E4 DB EA A4 6F BF F8 4F 10 93 1F DC F8 84 7F 5A CB
62 B6 4E 3A 16 E0 CE 4D 19 91 05 2B D6 54 F4 CF 4F 3B C8 B0 E0 AE EA B1 1F 3A 89 40
52 AF 07 D6 70 AF 0E 51 55 5F 1F D2 C0 B9 F9 ED 83 11 77 EB E8 5E 3A C6 F0 12 67 24
E5 2E C7 56 87 A9 44 8E 5A 92 F2 FD B1 49 F8 DD 1D 7C 3D E1 5C B2 B0 31 28 21 1B 8D
F1 F6 FD 1E 8D B2 35 50 7C D3 A1 5C 8B 81 7B 52 FF 3B 9A 00 A2 FA 4D 82 B7 6C 4A 16
65 64 BF C8 62 08 C9 4B 09 3F 5C 7D DB 65 1F 9A 29 45 57 DB DD 50 01 40 37 EB 60 B9
5A 2E CA 0F F6 B8 E3 95 EF 95 F1 EC 61 3D F2 71 8A 75 F1 67 B9 EB 20 52 E3 83 56 E8
94 E2 55 F2 2C 57 7B 31 06 89 B2 25 9B B5 38 3E B9 A7 8B 95 CD 19 1F 7E B5 6D 07 0E
5D 43 88 8A 81 FD 90 27 08 5E F2 11 39 20 9D 34 48 6B F9 8F F3 A0 7D 13 76 5F 15 C8
59 7B 9E AD 05 0B EB 3C 16 60 F5 C4 BA 26 00 1A 13 E4 11 94 2C 79 2A 7C 61 E6 16 AD
FA 8B 86 1E 0A 44 89 1A BD 37 45 0B AB 43 3C 6F D5 87 D5 FF A5 EF 97 6F 96 89 4F 15
40 4B BC 92 E5 31 44 23 48 7C AF F5 EC 6B 42 37 85 4D B6 A8 A7 54 9F 03 3A 9A BE 97
DD 36 91 16 5A A3 40 A9 C7 F0 75 7A 68 FE CD 5D D5 8F F7 43 C5 88 87 9A E5 BA DD B3
4E 42 35 96 79 E7 66 82 58 E9 5D 0C 37 D1 DE 1C C2 29 F9 B4 C3 D7 F4 82 D5 8D 17 CC
FA 7B CC 71 7D 04 F5 56 75 92 68 A1 B0 F3 7C FD E4 B9 E9 DD B0 88 78 E9 87 A2 1A 7E
50 A2 08 1F 97 F7 05 68 AE 5F 71 45 69 3D F8 BB 10 DF D5 F2 65 F8 1D 8A FA 75 6B 72
41 E2 CD 28 06 EE A7 84 FF 8C 0B F7 46 A9 8F D0 E1 9F B2 BB C5 1C 1A FF D4 FC 9D 8D
8D DE EC C1 C0 E6 CA 29 3F 2B 87 BA 75 C6 92 9B 78 DD 88 F0 3F EA CC 79 A8 30 55 CF
97 42 1A FE 97 FB 22 92 0E 09 A3 36 1F 08 2F 2C 28 D9 30 9B 13 1B A2 A2 78 F6 AC E4
75 A0 6F FE 89 A4 08 5B F7 BF 1A 99 17 86 77 74 14 28 DC 28 FD 16 BE DF E7 F8 E3 09
96 1A 7A B6 64 C8 56 9A E9 16 D4 F5 A6 84 EF F3 FE 97 36 CA 90 CA A4 44 37 06 43 A5
D2 23 CE 6A FE CE 78 2A CB 3B D3 2E 67 36 9F B0 89 61 28 DF F8 76 06 2C D8 A6 E7 58
C0 C7 68 01 A8 46 AA 1B 1A 42 DF B9 2E 22 36 2C 42 57 B1 3E 69 12 E5 6E 04 01 14 80
9B E7 BC 15 C9 EB 31 DB B7 25 C0 DB 8D 59 12 91 D3 B3 46 A8 D6 D7 65 63 10 51 4A D8
BD 96 08 24 36 E0 F2 64 6B DA 5B D1 59 38 BB B1 54 66 4C AC 24 0C F7 EF C9 8F EA 65
25 58 79 64 6B 90 EE 0A 1B 2D A1 30 7A 2D 41 23 72 F6 E7 27 99 9E 12 1E 07 1E 4E E8
0B 64 34 5E D6 AE 78 BB DF 06 C6 79 D4 3C 7E FA 17 C8 AA 09 F9 DF E3 06 A3 F4 B9 82
72 98 31 5C C6 E4 D1 C4 DD 14 B9 A2 F8 B3 9E D7 F1 43
|
success or wait |
1994762873 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Giid
Name: Ebci
|
buffer overflow |
1994764678 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit
Baseaddress: 3120000 Size: 4096 Protection: execute Mapped to pid: own pid
|
success or wait |
1994765672 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress:
3120000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
1994766656 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Giid
Name: Ebci
|
buffer overflow |
1994767570 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Giid
Name: Ebci
|
success or wait |
1994767932 |
| Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: 3120000
Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
1994774996 |
| Section loaded |
Path: \KnownDlls\PSAPI.DLL Access: write and read and execute Type: unknown Baseaddress:
3120000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
object name not found |
1994788880 |
| Section loaded |
Path: C:\WINDOWS\system32\psapi.dll Access: query and write and read and execute Type:
image Baseaddress: 76BF0000 Size: 45056 Protection: read write Mapped to pid: own
pid
|
success or wait |
1994790043 |
| Section loaded |
Path: \NLS\NlsSectionCP28591 Access: read Type: unknown Baseaddress: 76BF0000 Size:
45056 Protection: read write Mapped to pid: own pid
|
object name not found |
1994942394 |
| System info queried |
Type: CurrentTimeZoneInformation |
success or wait |
1994945006 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_inbox.dbx_directdbfilemap
Access: query and write and read and execute and
extend size Type: unknown Baseaddress:
76BF0000 Size: 45056 Protection: read write
Mapped to pid: own pid
|
object name not found |
1994954529 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_inbox.dbx_directdbfilemap
Access: query and write and read Type: commit
Baseaddress: 3160000 Size: 143360 Protection:
read write Mapped to pid: own pid
|
success or wait |
1994954717 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_offline.dbx_directdbshare
Access: query and write and read and execute and
extend size Type: unknown Baseaddress:
3160000 Size: 143360 Protection: read write
Mapped to pid: own pid
|
object name not found |
1994958200 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_offline.dbx_directdbshare
Access: query and write and read Type: commit
Baseaddress: 3010000 Size: 28672 Protection:
read write Mapped to pid: own pid
|
success or wait |
1994958362 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_offline.dbx_directdbfilemap
Access: query and write and read and execute and
extend size Type: unknown Baseaddress:
3010000 Size: 28672 Protection: read write
Mapped to pid: own pid
|
object name not found |
1994958859 |
| Section loaded |
Path:
\BaseNamedObjects\c:_documents and settings_administrator_local
settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook
express_offline.dbx_directdbfilemap
Access: query and write and read Type: commit
Baseaddress: 3020000 Size: 12288 Protection:
read write Mapped to pid: own pid
|
success or wait |
1994959018 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
1995317676 |
| Section loaded |
Path: \BaseNamedObjects\c:_documents and settings_administrator_local settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook express_sent
items.dbx_directdbshare Access: query and write and read and execute and extend size
Type: unknown Baseaddress: 3020000 Size: 12288 Protection: read write Mapped to pid:
own pid
|
object name not found |
1995446729 |
| Section loaded |
Path: \BaseNamedObjects\c:_documents and settings_administrator_local settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook express_sent
items.dbx_directdbshare Access: query and write and read Type: commit Baseaddress:
3040000 Size: 28672 Protection: read write Mapped to pid: own pid
|
success or wait |
1995446898 |
| Section loaded |
Path: \BaseNamedObjects\c:_documents and settings_administrator_local settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook express_sent
items.dbx_directdbfilemap Access: query and write and read and execute and extend
size Type: unknown Baseaddress: 3040000 Size: 28672 Protection: read write Mapped
to pid: own pid
|
object name not found |
1995447388 |
| Section loaded |
Path: \BaseNamedObjects\c:_documents and settings_administrator_local settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook express_sent
items.dbx_directdbfilemap Access: query and write and read Type: commit Baseaddress:
30D0000 Size: 12288 Protection: read write Mapped to pid: own pid
|
success or wait |
1995447555 |
| Section loaded |
Path: \BaseNamedObjects\c:_documents and settings_administrator_local settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook express_sent
items.dbx_directdbfilemap Access: query and write and read and execute and extend
size Type: unknown Baseaddress: 30D0000 Size: 12288 Protection: read write Mapped
to pid: own pid
|
object name not found |
1995451036 |
| Section loaded |
Path: \BaseNamedObjects\c:_documents and settings_administrator_local settings_application
data_identities_{5223274d-42a6-41c5-9e78-3a6606a65e5e}_microsoft_outlook express_sent
items.dbx_directdbfilemap Access: query and write and read Type: commit Baseaddress:
3120000 Size: 77824 Protection: read write Mapped to pid: own pid
|
success or wait |
1995451215 |
| Section loaded |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\MPS56.tmp Access: query and write and read
and execute and extend size Type: commit Baseaddress: 2EF0000 Size: 180224 Protection:
readonly Mapped to pid: own pid
|
success or wait |
1995580440 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
1997202606 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Giid
Name: Okmaykid Type: Binary Data: 96 8D 31 C9 C5 75 08 F8 84 53 9B D1 F4 B9 61 28
10 B5 F1 08 71 3F 43 D6 C5 E1 62 1A C6 5B 19 DC CC D6 C6 9D C6 B3 0A 3C 08 2E 18 33
00 4D BE 0B 36 BD B7 A3 BD 92 EA 03 1F E4 1B C7 16 2B 45 CA B5 08 9E BA 6B 0D 91 DA
05 B1 6F 8F BD 44 64 5A BF 72 4F 66 A5 9E C5 70 A4 30 85 A9 DA E1 B0 C2 84 42 08 3E
FA A7 EC BB C8 A3 E1 74 73 02 2C 20 4D 52 81 9C
|
success or wait |
1997252386 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
1998978432 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
1999683387 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2001429679 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2002144313 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2002869721 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2003738153 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2004454005 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2005191672 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2005904722 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2006625665 |
| System info queried |
Type: ProcessInformation |
success or wait |
2006627402 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 2850000 Size:
16384 Protection: read write Mapped to pid: own pid
|
success or wait |
2006636894 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-C250-CCC334817706} |
success or wait |
2006639074 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-AE51-CCC358807706} |
success or wait |
2006640066 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-A252-CCC354837706} |
success or wait |
2006640980 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BA52-CCC34C837706} |
success or wait |
2006641942 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-6E52-CCC398837706} |
success or wait |
2006642950 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-7252-CCC384837706} |
success or wait |
2006643853 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BA53-CCC34C827706} |
success or wait |
2006644792 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0E53-CCC3F8827706} |
success or wait |
2006645735 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-DA54-CCC32C857706} |
success or wait |
2006646648 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-8A54-CCC37C857706} |
success or wait |
2006647587 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BE54-CCC348857706} |
success or wait |
2006648494 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1E55-CCC3E8847706} |
success or wait |
2006649406 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-E257-CCC314867706} |
object name exists |
2006650796 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0651-CCC3F0807706} |
success or wait |
2006651624 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-3A51-CCC3CC807706} |
success or wait |
2006652537 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0257-CCC3F4867706} |
success or wait |
2006653478 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-2A50-CCC3DC817706} |
object name exists |
2006654383 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1252-CCC3E4837706} |
success or wait |
2006655210 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-A654-CCC350857706} |
success or wait |
2006656144 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1657-CCC3E0867706} |
success or wait |
2006657052 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-7658-CCC380897706} |
success or wait |
2006658030 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1E58-CCC3E8897706} |
success or wait |
2006658963 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2007361087 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2008071514 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2008800135 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2009526616 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2010252569 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2010979912 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2011706984 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2012444636 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2013161229 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2013888338 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2014615952 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2015345366 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2016069403 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2016796712 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2017524007 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2018250916 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2018980766 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2019706094 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2020432285 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2021159128 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2021886076 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2022613319 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2023343357 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2024067719 |
| System info queried |
Type: ProcessInformation |
success or wait |
2024523244 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 2850000 Size:
16384 Protection: read write Mapped to pid: own pid
|
success or wait |
2024532162 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-C250-CCC334817706} |
success or wait |
2024534327 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-AE51-CCC358807706} |
success or wait |
2024535265 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-A252-CCC354837706} |
success or wait |
2024536168 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BA52-CCC34C837706} |
success or wait |
2024537030 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-6E52-CCC398837706} |
success or wait |
2024537907 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-7252-CCC384837706} |
success or wait |
2024538789 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BA53-CCC34C827706} |
success or wait |
2024539712 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0E53-CCC3F8827706} |
success or wait |
2024540740 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-DA54-CCC32C857706} |
success or wait |
2024541672 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-8A54-CCC37C857706} |
success or wait |
2024542555 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BE54-CCC348857706} |
success or wait |
2024543454 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1E55-CCC3E8847706} |
success or wait |
2024544356 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-E257-CCC314867706} |
object name exists |
2024545739 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0651-CCC3F0807706} |
success or wait |
2024546567 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-3A51-CCC3CC807706} |
success or wait |
2024547481 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0257-CCC3F4867706} |
success or wait |
2024548421 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-2A50-CCC3DC817706} |
object name exists |
2024549325 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1252-CCC3E4837706} |
success or wait |
2024550152 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-A654-CCC350857706} |
success or wait |
2024551084 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1657-CCC3E0867706} |
success or wait |
2024551992 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-7658-CCC380897706} |
success or wait |
2024552967 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1E58-CCC3E8897706} |
success or wait |
2024553901 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2024808328 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2025524364 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2026251598 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2026976086 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2027703212 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2028430198 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} Type: String Data: "C:\Documents and
Settings\Administrator\Application Data\Foluv\hianh.exe"
|
success or wait |
2029157316 |
| System info queried |
Type: ProcessInformation |
success or wait |
2042413728 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 2850000 Size:
16384 Protection: read write Mapped to pid: own pid
|
success or wait |
2042420351 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-C250-CCC334817706} |
success or wait |
2042422549 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-AE51-CCC358807706} |
success or wait |
2042423498 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-A252-CCC354837706} |
success or wait |
2042424419 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BA52-CCC34C837706} |
success or wait |
2042425301 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-6E52-CCC398837706} |
success or wait |
2042426196 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-7252-CCC384837706} |
success or wait |
2042427096 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BA53-CCC34C827706} |
success or wait |
2042428038 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0E53-CCC3F8827706} |
success or wait |
2042428987 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-DA54-CCC32C857706} |
success or wait |
2042429902 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-8A54-CCC37C857706} |
success or wait |
2042430849 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BE54-CCC348857706} |
success or wait |
2042431760 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1E55-CCC3E8847706} |
success or wait |
2042432676 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-E257-CCC314867706} |
object name exists |
2042434155 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0651-CCC3F0807706} |
success or wait |
2042434998 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-3A51-CCC3CC807706} |
success or wait |
2042435920 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0257-CCC3F4867706} |
success or wait |
2042436870 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-2A50-CCC3DC817706} |
object name exists |
2042437785 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1252-CCC3E4837706} |
success or wait |
2042438712 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-A654-CCC350857706} |
success or wait |
2042439667 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1657-CCC3E0867706} |
success or wait |
2042440633 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-7658-CCC380897706} |
success or wait |
2042441619 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1E58-CCC3E8897706} |
success or wait |
2042442563 |
| System info queried |
Type: ProcessInformation |
success or wait |
2061051004 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 2850000 Size:
16384 Protection: read write Mapped to pid: own pid
|
success or wait |
2061058345 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-C250-CCC334817706} |
success or wait |
2061060670 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-AE51-CCC358807706} |
success or wait |
2061061639 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-A252-CCC354837706} |
success or wait |
2061062576 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BA52-CCC34C837706} |
success or wait |
2061063464 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-6E52-CCC398837706} |
success or wait |
2061064365 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-7252-CCC384837706} |
success or wait |
2061065357 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BA53-CCC34C827706} |
success or wait |
2061066298 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0E53-CCC3F8827706} |
success or wait |
2061067237 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-DA54-CCC32C857706} |
success or wait |
2061068149 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-8A54-CCC37C857706} |
success or wait |
2061069091 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BE54-CCC348857706} |
success or wait |
2061069994 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1E55-CCC3E8847706} |
success or wait |
2061070913 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-E257-CCC314867706} |
object name exists |
2061072296 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0651-CCC3F0807706} |
success or wait |
2061073122 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-3A51-CCC3CC807706} |
success or wait |
2061074037 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0257-CCC3F4867706} |
success or wait |
2061074977 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-2A50-CCC3DC817706} |
object name exists |
2061075889 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1252-CCC3E4837706} |
success or wait |
2061076714 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-A654-CCC350857706} |
success or wait |
2061077648 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1657-CCC3E0867706} |
success or wait |
2061078558 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-7658-CCC380897706} |
success or wait |
2061079533 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1E58-CCC3E8897706} |
success or wait |
2061080468 |
| System info queried |
Type: ProcessInformation |
success or wait |
2078934097 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 2850000 Size:
16384 Protection: read write Mapped to pid: own pid
|
success or wait |
2078940708 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-C250-CCC334817706} |
success or wait |
2078942876 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-AE51-CCC358807706} |
success or wait |
2078943821 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-A252-CCC354837706} |
success or wait |
2078944736 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BA52-CCC34C837706} |
success or wait |
2078945606 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-6E52-CCC398837706} |
success or wait |
2078946496 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-7252-CCC384837706} |
success or wait |
2078947390 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BA53-CCC34C827706} |
success or wait |
2078948335 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0E53-CCC3F8827706} |
success or wait |
2078949271 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-DA54-CCC32C857706} |
success or wait |
2078950450 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-8A54-CCC37C857706} |
success or wait |
2078951475 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BE54-CCC348857706} |
success or wait |
2078952474 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1E55-CCC3E8847706} |
success or wait |
2078953387 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-E257-CCC314867706} |
object name exists |
2078954773 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0651-CCC3F0807706} |
success or wait |
2078955600 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-3A51-CCC3CC807706} |
success or wait |
2078956513 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0257-CCC3F4867706} |
success or wait |
2078957451 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-2A50-CCC3DC817706} |
object name exists |
2078958361 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1252-CCC3E4837706} |
success or wait |
2078959184 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-A654-CCC350857706} |
success or wait |
2078960115 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1657-CCC3E0867706} |
success or wait |
2078961023 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-7658-CCC380897706} |
success or wait |
2078961999 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1E58-CCC3E8897706} |
success or wait |
2078962938 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: Ebci
|
buffer overflow |
2095600713 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: Ebci
|
buffer overflow |
2095602284 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: Ebci
|
success or wait |
2095603330 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: Okmaykid
|
success or wait |
2095630106 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: Okmaykid
|
success or wait |
2095630625 |
| Section loaded |
Path: C:\WINDOWS\system32\winrnr.dll Access: write and read and execute Type: commit
Baseaddress: 2850000 Size: 20480 Protection: execute Mapped to pid: own pid
|
success or wait |
2095655662 |
| Section loaded |
Path: C:\WINDOWS\system32\winrnr.dll Access: write and read and execute Type: commit
Baseaddress: 2850000 Size: 20480 Protection: execute Mapped to pid: own pid
|
success or wait |
2095662174 |
| Section loaded |
Path: C:\WINDOWS\system32\winrnr.dll Access: query and write and read and execute
Type: image Baseaddress: 76FB0000 Size: 32768 Protection: read write Mapped to pid:
own pid
|
success or wait |
2095665571 |
| File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Qiokze\pauz.tmp Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: false
|
success or wait |
2095992509 |
| Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters Name: Ebci |
buffer overflow |
2095993693 |
| Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters Name: Ebci |
buffer overflow |
2095995183 |
| Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters Name: Ebci |
success or wait |
2095995862 |
| Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters Name: Okmaykid |
success or wait |
2096021623 |
| Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters Name: Okmaykid |
success or wait |
2096022140 |
| File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Qiokze\pauz.tmp Access:
read attributes and synchronize and generic read and generic write Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: false
|
success or wait |
2096023000 |
| File read |
Path: C:\Documents and Settings\Administrator\Application Data\Qiokze\pauz.tmp Offset:
none Length: 5 Value: 05 0D 8C 79 C9
|
end of file |
2096024795 |
| File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Qiokze\pauz.tmp Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
2096030099 |
| File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Qiokze\pauz.tmp Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
2096032077 |
| Section loaded |
Path: \KnownDlls\MPRAPI.dll Access: write and read and execute Type: unknown Baseaddress:
76FB0000 Size: 32768 Protection: read write Mapped to pid: own pid
|
object name not found |
2096224624 |
| Section loaded |
Path: C:\WINDOWS\system32\mprapi.dll Access: query and write and read and execute
Type: image Baseaddress: 76D40000 Size: 98304 Protection: read write Mapped to pid:
own pid
|
success or wait |
2096227069 |
| Section loaded |
Path: \KnownDlls\ACTIVEDS.dll Access: write and read and execute Type: unknown Baseaddress:
76D40000 Size: 98304 Protection: read write Mapped to pid: own pid
|
object name not found |
2096230550 |
| Section loaded |
Path: C:\WINDOWS\system32\activeds.dll Access: query and write and read and execute
Type: image Baseaddress: 77CC0000 Size: 204800 Protection: read write Mapped to pid:
own pid
|
success or wait |
2096233025 |
| Section loaded |
Path: \KnownDlls\adsldpc.dll Access: write and read and execute Type: unknown Baseaddress:
77CC0000 Size: 204800 Protection: read write Mapped to pid: own pid
|
object name not found |
2096237960 |
| Section loaded |
Path: C:\WINDOWS\system32\adsldpc.dll Access: query and write and read and execute
Type: image Baseaddress: 76E10000 Size: 151552 Protection: read write Mapped to pid:
own pid
|
success or wait |
2096241038 |
| System info queried |
Type: ProcessInformation |
success or wait |
2096831544 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 2850000 Size:
16384 Protection: read write Mapped to pid: own pid
|
success or wait |
2096838181 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-C250-CCC334817706} |
success or wait |
2096840348 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-AE51-CCC358807706} |
success or wait |
2096841200 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-A252-CCC354837706} |
success or wait |
2096842101 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BA52-CCC34C837706} |
success or wait |
2096842964 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-6E52-CCC398837706} |
success or wait |
2096843843 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-7252-CCC384837706} |
success or wait |
2096844722 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BA53-CCC34C827706} |
success or wait |
2096845644 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0E53-CCC3F8827706} |
success or wait |
2096846649 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-DA54-CCC32C857706} |
success or wait |
2096847561 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-8A54-CCC37C857706} |
success or wait |
2096848495 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-BE54-CCC348857706} |
success or wait |
2096849676 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1E55-CCC3E8847706} |
success or wait |
2096850587 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-E257-CCC314867706} |
object name exists |
2096852073 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0651-CCC3F0807706} |
success or wait |
2096852902 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-3A51-CCC3CC807706} |
success or wait |
2096853812 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-0257-CCC3F4867706} |
success or wait |
2096854749 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-2A50-CCC3DC817706} |
object name exists |
2096855655 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1252-CCC3E4837706} |
success or wait |
2096856480 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-A654-CCC350857706} |
success or wait |
2096857411 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1657-CCC3E0867706} |
success or wait |
2096858316 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-7658-CCC380897706} |
success or wait |
2096859290 |
| Mutant created |
Name: \BaseNamedObjects\Global\{5FEF9DAD-A530-7099-1E58-CCC3E8897706} |
success or wait |
2096860223 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\webhp[1].txt
Offset: none Length: 4096 Value: 3C 21 64 6F 63 74 79 70 65 20 68 74 6D 6C 3E 3C 68
74 6D 6C 3E 3C 68 65 61 64 3E 3C 6D 65 74 61 20 68 74 74 70 2D 65 71 75 69 76 3D 22
58 2D 55 41 2D 43 6F 6D 70 61 74 69 62 6C 65 22 20 63 6F 6E 74 65 6E 74 3D 22 49 45
3D 65 64 67 65 22 3E 3C 6D 65 74 61 20 68 74 74 70 2D 65 71 75 69 76 3D 22 63 6F
|
success or wait |
2097554074 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\webhp[1].txt
Offset: none Length: 4096 Value: 64 64 69 6E 67 3A 31 30 70 78 20 30 3B 70 6F 73 69
74 69 6F 6E 3A 72 65 6C 61 74 69 76 65 3B 7A 2D 69 6E 64 65 78 3A 32 3B 7A 6F 6F 6D
3A 31 7D 2E 67 62 74 7B 70 6F 73 69 74 69 6F 6E 3A 72 65 6C 61 74 69 76 65 3B 64 69
73 70 6C 61 79 3A 2D 6D 6F 7A 2D 69 6E 6C 69 6E 65 2D 62 6F 78 3B 64 69 73 70 6C
|
success or wait |
2097887029 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\webhp[1].txt
Offset: none Length: 4096 Value: 65 7B 66 6F 6E 74 2D 77 65 69 67 68 74 3A 62 6F 6C
64 7D 23 67 62 6D 70 70 7B 64 69 73 70 6C 61 79 3A 6E 6F 6E 65 7D 23 67 62 64 34 20
2E 67 62 6D 63 63 7B 6D 61 72 67 69 6E 2D 74 6F 70 3A 35 70 78 7D 2E 67 62 70 6D 63
7B 62 61 63 6B 67 72 6F 75 6E 64 3A 23 65 64 66 65 65 61 7D 2E 67 62 70 6D 63 20
|
success or wait |
2097893021 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\webhp[1].txt
Offset: none Length: 4096 Value: 61 74 69 6F 6E 3A 6E 6F 6E 65 7D 23 73 73 2D 62 6F
78 20 61 3A 68 6F 76 65 72 7B 62 61 63 6B 67 72 6F 75 6E 64 3A 23 34 44 39 30 46 45
3B 63 6F 6C 6F 72 3A 23 66 66 66 21 69 6D 70 6F 72 74 61 6E 74 7D 61 2E 73 73 2D 73
65 6C 65 63 74 65 64 7B 63 6F 6C 6F 72 3A 23 32 32 32 21 69 6D 70 6F 72 74 61 6E
|
success or wait |
2097939530 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\webhp[1].txt
Offset: none Length: 4096 Value: 67 72 6F 75 6E 64 2D 69 6D 61 67 65 3A 2D 6D 73 2D
6C 69 6E 65 61 72 2D 67 72 61 64 69 65 6E 74 28 74 6F 70 2C 23 64 64 34 62 33 39 2C
23 62 30 32 38 31 61 29 3B 66 69 6C 74 65 72 3A 70 72 6F 67 69 64 3A 44 58 49 6D 61
67 65 54 72 61 6E 73 66 6F 72 6D 2E 4D 69 63 72 6F 73 6F 66 74 2E 67 72 61 64 69
|
success or wait |
2097979549 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\webhp[1].txt
Offset: none Length: 4096 Value: 63 3D 61 3B 43 3D 63 2B 31 7D 2C 44 3D 5B 5D 2C 43
3D 30 3B 6E 28 22 6C 6F 67 67 65 72 22 2C 7B 69 6C 3A 42 2C 6D 6C 3A 41 7D 29 3B 76
61 72 20 46 3D 77 69 6E 64 6F 77 2E 67 62 61 72 2E 6C 6F 67 67 65 72 3B 76 61 72 20
47 3D 5F 74 76 66 28 22 30 2E 30 31 22 2C 31 2E 30 45 2D 34 29 2C 48 3D 30 3B 0A
|
success or wait |
2098020074 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\webhp[1].txt
Offset: none Length: 4096 Value: 2C 69 29 3B 57 28 61 2C 22 22 29 7D 7D 2C 4B 61 3D
66 75 6E 63 74 69 6F 6E 28 61 29 7B 74 72 79 7B 55 28 29 3B 76 61 72 20 62 3D 61 7C
7C 64 6F 63 75 6D 65 6E 74 2E 67 65 74 45 6C 65 6D 65 6E 74 42 79 49 64 28 54 29 3B
69 66 28 62 29 7B 57 28 62 2C 22 54 68 69 73 20 73 65 72 76 69 63 65 20 69 73 20
|
success or wait |
2098077499 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\webhp[1].txt
Offset: none Length: 4096 Value: 61 70 70 65 6E 64 43 68 69 6C 64 28 62 2E 63 6C 6F
6E 65 4E 6F 64 65 28 74 72 75 65 29 29 7D 63 61 74 63 68 28 65 29 7B 63 28 65 29 7D
7D 3B 61 2E 61 6F 6D 63 3D 66 3B 7D 63 61 74 63 68 28 65 29 7B 77 69 6E 64 6F 77 2E
67 62 61 72 26 26 67 62 61 72 2E 6C 6F 67 67 65 72 26 26 67 62 61 72 2E 6C 6F 67
|
success or wait |
2098086431 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\webhp[1].txt
Offset: none Length: 4096 Value: 69 64 3D 67 62 5F 32 35 20 68 72 65 66 3D 22 68 74
74 70 73 3A 2F 2F 64 6F 63 73 2E 67 6F 6F 67 6C 65 2E 63 6F 6D 2F 3F 74 61 62 3D 77
6F 22 20 6F 6E 63 6C 69 63 6B 3D 22 67 62 61 72 2E 6C 6F 67 67 65 72 2E 69 6C 28 31
2C 7B 74 3A 32 35 7D 29 22 3E 44 6F 63 75 6D 65 6E 74 73 3C 2F 61 3E 3C 2F 6C 69
|
success or wait |
2098098170 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\webhp[1].txt
Offset: none Length: 4096 Value: 3E 20 3C 2F 64 69 76 3E 20 3C 2F 74 64 3E 20 3C 2F
74 72 3E 20 3C 2F 74 61 62 6C 65 3E 20 3C 2F 74 64 3E 20 3C 74 64 3E 20 20 3C 64 69
76 20 63 6C 61 73 73 3D 22 6E 6F 6A 73 76 22 20 73 74 79 6C 65 3D 22 70 6F 73 69 74
69 6F 6E 3A 72 65 6C 61 74 69 76 65 3B 68 65 69 67 68 74 3A 33 30 70 78 22 20 69
|
success or wait |
2098172673 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\webhp[1].txt
Offset: none Length: 4096 Value: 6F 67 6C 65 2E 6D 73 67 26 26 67 6F 6F 67 6C 65 2E
6D 73 67 2E 73 65 6E 64 28 36 34 29 7D 66 75 6E 63 74 69 6F 6E 20 76 28 61 29 7B 76
61 72 20 62 3D 66 61 6C 73 65 3B 74 72 79 7B 62 3D 77 69 6E 64 6F 77 2E 65 78 74 65
72 6E 61 6C 2E 69 73 47 6F 6F 67 6C 65 48 6F 6D 65 50 61 67 65 28 29 7D 63 61 74
|
success or wait |
2098186233 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\webhp[1].txt
Offset: none Length: 4096 Value: 34 41 43 77 72 4D 4B 77 42 4F 41 41 73 4B 7A 42 30
4F 41 41 73 4B 7A 41 64 4F 41 41 73 4B 7A 42 63 4F 41 41 73 4B 7A 41 59 4F 41 41 73
4B 7A 41 6D 4F 41 41 73 67 41 4A 66 6B 41 4A 62 2F 4E 65 57 39 6F 41 64 45 79 6A 45
2E 6A 73 27 29 3B 67 6F 6F 67 6C 65 2E 78 6A 73 3D 31 7D 28 66 75 6E 63 74 69 6F
|
success or wait |
2098192718 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\webhp[1].txt
Offset: none Length: 2852 Value: 39 32 2C 7B 22 61 65 22 3A 74 72 75 65 2C 22 61 76
67 54 74 66 63 22 3A 32 30 30 30 2C 22 62 70 65 22 3A 66 61 6C 73 65 2C 22 62 72 62
61 22 3A 66 61 6C 73 65 2C 22 64 6C 65 6E 22 3A 32 34 2C 22 66 62 64 63 22 3A 35 30
30 2C 22 66 62 64 75 22 3A 33 30 30 30 2C 22 66 62 68 22 3A 74 72 75 65 2C 22 66
|
success or wait |
2098279799 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: Okmaykid
|
success or wait |
2098288198 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: Okmaykid
|
success or wait |
2098288730 |
| System info queried |
Type: CurrentTimeZoneInformation |
success or wait |
2098290402 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\red[1].htm
Offset: none Length: 93 Value: 28 3F DF CC 1A 3B 7B 91 90 86 C1 7C 38 88 CF A9 A5
C2 5C DF D9 49 56 15 DB 68 4C D1 02 EB EB 9C F4 35 B3 26 CF 10 3B F5 5E CD 6F 93 6B
5D 93 1D 8F 1B 26 D0 A2 79 08 73 26 79 27 D3 60 82 77 DA A3 78 7A 52 3A A7 8A A2 6F
A2 9A 37 E8 99 47 A9 76 0E 45 BF AD 73 00 0F 7B 90 A5 4D E9
|
success or wait |
2102707700 |
| System info queried |
Type: ProcessInformation |
success or wait |
2102719354 |
| Section loaded |
Path: none Access: query and write and read Type: commit Baseaddress: 2890000 Size:
12288 Protection: read write Mapped to pid: own pid
|
success or wait |
2102725970 |
| Thread created |
PID: 1636 TID: 772 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe Injected: false |
success or wait |
2102867804 |
| Mutant created |
Name: \BaseNamedObjects\Global\{C1D048FE-7063-EEA6-185B-81F8EE8A3A3D} |
success or wait |
2102869635 |
| Mutant created |
Name: \BaseNamedObjects\Global\{50BFCA5D-F2C0-7FC9-185B-81F8EE8A3A3D} |
success or wait |
2102870069 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Name: Isic
|
object name not found |
2102870591 |
| Key value set |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Giid
Name: Isic Type: Binary Data: 9F FB 8A 01 CE CB 89 99 78 8F 7A 24 04 EC BF 69 88 AB
89 AB 82 CC B0 25 36 12 91 E9 34 A9 EB 2E 57 1B F6 70 61 B9 F3 01 0E 38 7F 2B 4F B6
85 BD 81 0A 1D 97 0A 25 5D 94 98 63 9C 40 81 BC D2 5D 0F AC 89 8E EC 10 21 E4 E9 91
3B 00 C6 6B 24 D2
|
success or wait |
2102882638 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Giid
Name: Ebci
|
buffer overflow |
2102886080 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Giid
Name: Ebci
|
buffer overflow |
2102887554 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Giid
Name: Ebci
|
success or wait |
2102888079 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Giid
Name: Okmaykid
|
success or wait |
2102914337 |
| Key value queried |
Path: HKEY_USERS\S-1-5-21-507921405-1960408961-839522115-500\Software\Microsoft\Giid
Name: Okmaykid
|
success or wait |
2102914881 |
| File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JQ2FZ3JS\red[1].htm
Offset: none Length: 64 Value: 8C 75 87 84 27 E6 70 83 E6 84 3E 81 1E 7B E6 BD D9
9D EF 62 79 E9 F6 B5 7B C8 EC 71 A2 4B 4B 3C 4B 2F FD DD 66 CC 33 A9 FA 26 DE B4 F1
BE 2F 26 B5 21 1C EA 98 43 32 49 01 5E 00 F4 5A B8 4D E0
|
success or wait |
2105448184 |
| Thread delayed |
Time: 0 TID: 1906 |
success or wait |
2105657569 |
| Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography Name: {BD75E342-DBDF-9203-185B-81F8EE8A3A3D} |
object name not found |
2107458216 |
| File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Foluv\hianh.exe Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
2107460061 |
| File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Foluv\hianh.exe Access:
write attributes and synchronize Options: synchronous io non alert and open for backup
ident and open reparse point
|
success or wait |
2107461901 |
| File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Foluv Access: write
attributes and synchronize Options: synchronous io non alert and open for backup ident
and open reparse point
|
success or wait |
2107465608 |
| File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Foluv Access: write
attributes and synchronize Options: synchronous io non alert and open for backup ident
and open reparse point
|
success or wait |
2107467290 |
| File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Qiokze Access: write
attributes and synchronize Options: synchronous io non alert and open for backup ident
and open reparse point
|
success or wait |
2107475949 |
| File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Qiokze Access: write
attributes and synchronize Options: synchronous io non alert and open for backup ident
and open reparse point
|
success or wait |
2107477628 |
| File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp4d94e4d7.bat Access: read attributes and
synchronize and generic write Options: synchronous io non alert and non directory
file Attributes: normal Content Overwritten: false
|
success or wait |
2107486184 |
| File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp4d94e4d7.bat Access: read attributes and
synchronize and generic write Options: synchronous io non alert and non directory
file Attributes: normal Content Overwritten: false
|
success or wait |
2107490477 |
| File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp4d94e4d7.bat Offset: none Length: 392
Value: 40 65 63 68 6F 20 6F 66 66 0D 0A 3A 64 0D 0A 72 64 20 2F 53 20 2F 51 20 22
43 3A 5C 44 6F 63 75 6D 65 6E 74 73 20 61 6E 64 20 53 65 74 74 69 6E 67 73 5C 41 64
6D 69 6E 69 73 74 72 61 74 6F 72 5C 41 70 70 6C 69 63 61 74 69 6F 6E 20 44 61 74 61
5C 46 6F 6C 75 76 22 0D 0A 72 64 20 2F 53 20 2F 51 20 22
|
success or wait |
2107494768 |
| Section loaded |
Path: C:\WINDOWS\system32\cmd.exe Access: query and write and read and execute and
extend size Type: image Baseaddress: 2890000 Size: 12288 Protection: read write Mapped
to pid: own pid
|
success or wait |
2107497441 |
| Section loaded |
Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 3430000
Size: 1208320 Protection: readonly Mapped to pid: own pid
|
success or wait |
2107499194 |
| Section loaded |
Path: C:\WINDOWS\system32\cmd.exe Access: write and read and execute Type: commit
Baseaddress: 2890000 Size: 389120 Protection: execute Mapped to pid: own pid
|
success or wait |
2107509845 |
| Section loaded |
Path: C:\WINDOWS\system32\cmd.exe Access: query and read Type: commit Baseaddress:
2890000 Size: 389120 Protection: readonly Mapped to pid: own pid
|
success or wait |
2107512311 |
| Section loaded |
Path: C:\WINDOWS\system32\cmd.exe Access: write and read and execute Type: commit
Baseaddress: 2890000 Size: 389120 Protection: execute Mapped to pid: own pid
|
success or wait |
2107519907 |
| Section loaded |
Path: C:\WINDOWS\system32\cmd.exe Access: query and read Type: commit Baseaddress:
2890000 Size: 389120 Protection: readonly Mapped to pid: own pid
|
success or wait |
2107522411 |
| Section loaded |
Path: C:\WINDOWS\system32\cmd.exe Access: query and read Type: commit Baseaddress:
2890000 Size: 389120 Protection: readonly Mapped to pid: own pid
|
success or wait |
2107534810 |
| Process created |
PID: 604 Path: C:\WINDOWS\system32\cmd.exe Cmdline: C:\WINDOWS\system32\cmd.exe /c
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp4d94e4d7.bat Createflags: 0
|
success or wait |
2107537358 |