General Info

File name

Док-ты за прошлый месяц.rar

Full analysis
https://app.any.run/tasks/cb8a54f6-da7e-4d6b-9949-7774c42be9b7
Verdict
Malicious activity
Analysis date
5/15/2019, 14:52:28
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

rat

redaman

Indicators:

MIME:
application/x-rar
File info:
RAR archive data, v4, os: Win32
MD5

2ca3180144fe6218cf80dd6c400b8415

SHA1

46482d3b43b5dac8e67579ed0353892fd0862544

SHA256

eb99f2a6d97253d45b50c44bd46833deccf8548426c78b6fa55fc5bcca250c03

SSDEEP

6144:LELW3LTB9ZrSTSGAggBkm9i1xXOqG5yDx+iHl:GW3pGWGAmOif+ncF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • iexplore.exe (PID: 588)
  • iexplore.exe (PID: 2108)
  • explorer.exe (PID: 2036)
  • rundll32.exe (PID: 3280)
  • WinRAR.exe (PID: 928)
  • rundll32.exe (PID: 2972)
REDAMAN was detected
  • rundll32.exe (PID: 2972)
Application was dropped or rewritten from another process
  • Док-ты за прошлый месяц.exe (PID: 2908)
Changes the autorun value in the registry
  • Док-ты за прошлый месяц.exe (PID: 2908)
Changes settings of System certificates
  • rundll32.exe (PID: 2972)
Loads the Task Scheduler COM API
  • rundll32.exe (PID: 3280)
Executable content was dropped or overwritten
  • explorer.exe (PID: 2036)
  • rundll32.exe (PID: 3280)
  • WinRAR.exe (PID: 928)
  • Док-ты за прошлый месяц.exe (PID: 2908)
Starts Internet Explorer
  • explorer.exe (PID: 2036)
Connects to server without host name
  • rundll32.exe (PID: 2972)
Creates files in the program directory
  • rundll32.exe (PID: 3280)
Adds / modifies Windows certificates
  • rundll32.exe (PID: 2972)
Uses RUNDLL32.EXE to load library
  • Док-ты за прошлый месяц.exe (PID: 2908)
Reads Internet Cache Settings
  • explorer.exe (PID: 2036)
Creates files in the user directory
  • explorer.exe (PID: 2036)
Changes internet zones settings
  • iexplore.exe (PID: 2108)
Reads internet explorer settings
  • iexplore.exe (PID: 588)
Application launched itself
  • iexplore.exe (PID: 2108)
Creates files in the user directory
  • iexplore.exe (PID: 588)
Reads Internet Cache Settings
  • iexplore.exe (PID: 588)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.rar
|   RAR compressed archive (v-4.x) (58.3%)
.rar
|   RAR compressed archive (gen) (41.6%)
EXIF
ZIP
CompressedSize:
223204
UncompressedSize:
222560
OperatingSystem:
Win32
ModifyDate:
2019:05:15 15:48:00
PackingMethod:
Normal
ArchivedFileName:
???-?? ?? ??????? ?????.7z

Screenshots

Processes

Total processes
39
Monitored processes
8
Malicious processes
3
Suspicious processes
2

Behavior graph

+
start drop and start winrar.exe no specs winrar.exe док-ты за прошлый месяц.exe rundll32.exe #REDAMAN rundll32.exe explorer.exe iexplore.exe iexplore.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2036
CMD
C:\Windows\Explorer.EXE
Path
C:\Windows\explorer.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sndvolsso.dll
c:\windows\system32\hid.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\timedate.cpl
c:\windows\system32\atl.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\userenv.dll
c:\windows\system32\shacct.dll
c:\windows\system32\samlib.dll
c:\windows\system32\samcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\authui.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gameux.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\psapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\stobject.dll
c:\windows\system32\batmeter.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\es.dll
c:\windows\system32\prnfldr.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dxp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\syncreg.dll
c:\windows\ehome\ehsso.dll
c:\windows\system32\netshell.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\alttab.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\pnidui.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wwanapi.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\qagent.dll
c:\windows\system32\srchadmin.dll
c:\windows\system32\sxs.dll
c:\windows\system32\bthprops.cpl
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\synccenter.dll
c:\windows\system32\actioncenter.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\hgcpl.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\fxsst.dll
c:\windows\system32\fxsapi.dll
c:\windows\system32\fxsresm.dll
c:\windows\system32\wscinterop.dll
c:\windows\system32\wscapi.dll
c:\windows\system32\wscui.cpl
c:\windows\system32\werconcpl.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wercplsupport.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\hcproviders.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\devrtl.dll
c:\program files\common files\microsoft shared\office14\msoxev.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\mlang.dll
c:\windows\system32\msutb.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\zipfldr.dll
c:\program files\winrar\rarext.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\programdata\2401bf603c90\2702bc633f93.dat
c:\windows\system32\odbctrac.dll
c:\windows\system32\odbc32.dll
c:\windows\system32\odbcint.dll
c:\users\admin\desktop\док-ты за прошлый месяц.exe
c:\program files\internet explorer\iexplore.exe

PID
900
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Док-ты за прошлый месяц.rar"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.60.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll

PID
928
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Док-ты за прошлый месяц.7z"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.60.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\program files\winrar\7zxa.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\users\admin\appdata\local\temp\rar$exa928.28767\док-ты за прошлый месяц.exe
c:\programdata\2401bf603c90\2702bc633f93.dat
c:\windows\system32\odbctrac.dll
c:\windows\system32\odbc32.dll
c:\windows\system32\odbcint.dll
c:\windows\system32\atl.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll

PID
2908
CMD
"C:\Users\admin\AppData\Local\Temp\Rar$EXa928.28767\Док-ты за прошлый месяц.exe"
Path
C:\Users\admin\AppData\Local\Temp\Rar$EXa928.28767\Док-ты за прошлый месяц.exe
Indicators
Parent process
WinRAR.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Корпорация Майкрософт
Description
Самоизвлечение CAB-файлов Win32
Version
6.00.2900.5512 (xpsp.080413-2105)
Modules
Image
c:\users\admin\appdata\local\temp\rar$exa928.28767\док-ты за прошлый месяц.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\feclient.dll
c:\windows\system32\advpack.dll
c:\windows\system32\rundll32.exe

PID
3280
CMD
rundll32.exe 0024.dll,DllGetClassObject root 000000000000 Post Install program: <None>
Path
C:\Windows\system32\rundll32.exe
Indicators
Parent process
Док-ты за прошлый месяц.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows host process (Rundll32)
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\0024.dll
c:\windows\system32\odbctrac.dll
c:\windows\system32\odbc32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\odbcint.dll
c:\windows\system32\atl.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\winscard.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\xmllite.dll

PID
2972
CMD
rundll32.exe "C:\ProgramData\2401bf603c90\2702bc633f93.dat",DllGetClassObject root
Path
C:\Windows\system32\rundll32.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows host process (Rundll32)
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\programdata\2401bf603c90\2702bc633f93.dat
c:\windows\system32\odbctrac.dll
c:\windows\system32\odbc32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\odbcint.dll
c:\windows\system32\atl.dll
c:\windows\system32\version.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\winscard.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemdisp.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\sxs.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wtsapi32.dll

PID
2108
CMD
"C:\Program Files\Internet Explorer\iexplore.exe"
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\version.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mlang.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\programdata\2401bf603c90\2702bc633f93.dat
c:\windows\system32\odbctrac.dll
c:\windows\system32\odbc32.dll
c:\windows\system32\odbcint.dll
c:\windows\system32\atl.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\linkinfo.dll

PID
588
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2108 CREDAT:71937
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
No indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\msimtf.dll
c:\programdata\2401bf603c90\2702bc633f93.dat
c:\windows\system32\odbctrac.dll
c:\windows\system32\odbc32.dll
c:\windows\system32\odbcint.dll
c:\windows\system32\atl.dll

Registry activity

Total events
3011
Read events
2880
Write events
127
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
2036
explorer.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019032020190321
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList
a
WinRAR.exe
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList
MRUList
a
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
00000000000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
0000000005000000030000008DCB000003000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E72402
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
00000000000000000000000027090000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000000500000003000000B4D4000003000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E72402
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
00000000010000000000000027090000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF506AB1211D0BD50100000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000000600000003000000B4D4000003000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E72402
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.7z\OpenWithList
a
WinRAR.exe
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.7z\OpenWithList
MRUList
a
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.7z\OpenWithProgids
WinRAR
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
2
14043E043A042D0042044B0420003704300420003F0440043E0448043B044B04390420003C04350441044F0446042E0037007A000000B60036000000000000000000000014043E043A042D0042044B0420003704300420003F0440043E0448043B044B04390420003C04350441044F0446042E0037007A002E006C006E006B0000006A0008000400EFBE00000000000000002A0000000000000000000000000000000000000000000000000014043E043A042D0042044B0420003704300420003F0440043E0448043B044B04390420003C04350441044F0446042E0037007A002E006C006E006B0000004C000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.7z
0
14043E043A042D0042044B0420003704300420003F0440043E0448043B044B04390420003C04350441044F0446042E0037007A000000B60036000000000000000000000014043E043A042D0042044B0420003704300420003F0440043E0448043B044B04390420003C04350441044F0446042E0037007A002E006C006E006B0000006A0008000400EFBE00000000000000002A0000000000000000000000000000000000000000000000000014043E043A042D0042044B0420003704300420003F0440043E0448043B044B04390420003C04350441044F0446042E0037007A002E006C006E006B0000004C000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.7z
MRUListEx
00000000FFFFFFFF
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019051520190516
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019051520190516
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019051520190516
CachePrefix
:2019051520190516:
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019051520190516
CacheLimit
8192
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019051520190516
CacheOptions
11
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019051520190516
CacheRepair
0
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
MRUListEx
020000000100000000000000FFFFFFFF
2036
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
00000000010000000000000088540000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF506AB1211D0BD50100000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
0000000006000000030000001520010003000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E72402
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Zvpebfbsg.VagreargRkcybere.Qrsnhyg
00000000010000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF30DE0D301D0BD50100000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
0000000007000000030000001520010003000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E72402
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count
{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\GnfxOne\Vagrearg Rkcybere.yax
00000000010000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF30DE0D301D0BD50100000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count
HRZR_PGYFRFFVBA
000000000500000000000000040000000300000000000000030000007B00300031003300390044003400340045002D0036004100460045002D0034003900460032002D0038003600390030002D003300440041004600430041004500360046004600420038007D005C004100630063006500730073006F0072006900650073005C00530079007300740065006D00200054006F006F006C0073005C005400610073006B0020005300630068006500640075006C00650072002E006C006E006B0000006C006E006B0000003205EDE05F7793740800FEFFFFFFE72F6377822E6377B8F90876330200008600000043BA59720000000060ABD50220662100F8672100F8992D00987D210007000000A0D032055CD83205ECF83205EDE05F7793740800FEFFFFFFE72F6377822E6377B8F90876B5010000800000008FBA597202000000000000000000000068D13205399CF576C09A5003800200000000000039000000409D500333020000C09A500398D1320543190976F39C500348842A0086000000C09A500368952D0033020000B8F90876DF1E0000ABA43901B4D1320533AB6377ABD055CA000C00001027000013000000AD540200E8D13205F8AA6377AD540200ABA4390108D2320580D3DE0288D2320500000000A301000048D20000030B9F23F8D132058291097648D23205FCD1320527950976000000000CD8DE0224D23205CD9409760CD8DE02D0D2320580D3DE02E19409760000000080D3DE02D0D232052CD232050300000000000000030000007B00300031003300390044003400340045002D0036004100460045002D0034003900460032002D0038003600390030002D003300440041004600430041004500360046004600420038007D005C004100630063006500730073006F0072006900650073005C00530079007300740065006D00200054006F006F006C0073005C005400610073006B0020005300630068006500640075006C00650072002E006C006E006B0000006C006E006B0000003205EDE05F7793740800FEFFFFFFE72F6377822E6377B8F90876330200008600000043BA59720000000060ABD50220662100F8672100F8992D00987D210007000000A0D032055CD83205ECF83205EDE05F7793740800FEFFFFFFE72F6377822E6377B8F90876B5010000800000008FBA597202000000000000000000000068D13205399CF576C09A5003800200000000000039000000409D500333020000C09A500398D1320543190976F39C500348842A0086000000C09A500368952D0033020000B8F90876DF1E0000ABA43901B4D1320533AB6377ABD055CA000C00001027000013000000AD540200E8D13205F8AA6377AD540200ABA4390108D2320580D3DE0288D2320500000000A301000048D20000030B9F23F8D132058291097648D23205FCD1320527950976000000000CD8DE0224D23205CD9409760CD8DE02D0D2320580D3DE02E19409760000000080D3DE02D0D232052CD232050300000000000000030000007B00300031003300390044003400340045002D0036004100460045002D0034003900460032002D0038003600390030002D003300440041004600430041004500360046004600420038007D005C004100630063006500730073006F0072006900650073005C00530079007300740065006D00200054006F006F006C0073005C005400610073006B0020005300630068006500640075006C00650072002E006C006E006B0000006C006E006B0000003205EDE05F7793740800FEFFFFFFE72F6377822E6377B8F90876330200008600000043BA59720000000060ABD50220662100F8672100F8992D00987D210007000000A0D032055CD83205ECF83205EDE05F7793740800FEFFFFFFE72F6377822E6377B8F90876B5010000800000008FBA597202000000000000000000000068D13205399CF576C09A5003800200000000000039000000409D500333020000C09A500398D1320543190976F39C500348842A0086000000C09A500368952D0033020000B8F90876DF1E0000ABA43901B4D1320533AB6377ABD055CA000C00001027000013000000AD540200E8D13205F8AA6377AD540200ABA4390108D2320580D3DE0288D2320500000000A301000048D20000030B9F23F8D132058291097648D23205FCD1320527950976000000000CD8DE0224D23205CD9409760CD8DE02D0D2320580D3DE02E19409760000000080D3DE02D0D232052CD23205
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count
{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\GnfxOne\Vagrearg Rkcybere.yax
00000000010000000000000001000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF30DE0D301D0BD50100000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count
HRZR_PGYFRFFVBA
000000000500000000000000050000000300000000000000030000007B00300031003300390044003400340045002D0036004100460045002D0034003900460032002D0038003600390030002D003300440041004600430041004500360046004600420038007D005C004100630063006500730073006F0072006900650073005C00530079007300740065006D00200054006F006F006C0073005C005400610073006B0020005300630068006500640075006C00650072002E006C006E006B0000006C006E006B0000003205EDE05F7793740800FEFFFFFFE72F6377822E6377B8F90876330200008600000043BA59720000000060ABD50220662100F8672100F8992D00987D210007000000A0D032055CD83205ECF83205EDE05F7793740800FEFFFFFFE72F6377822E6377B8F90876B5010000800000008FBA597202000000000000000000000068D13205399CF576C09A5003800200000000000039000000409D500333020000C09A500398D1320543190976F39C500348842A0086000000C09A500368952D0033020000B8F90876DF1E0000ABA43901B4D1320533AB6377ABD055CA000C00001027000013000000AD540200E8D13205F8AA6377AD540200ABA4390108D2320580D3DE0288D2320500000000A301000048D20000030B9F23F8D132058291097648D23205FCD1320527950976000000000CD8DE0224D23205CD9409760CD8DE02D0D2320580D3DE02E19409760000000080D3DE02D0D232052CD232050300000000000000030000007B00300031003300390044003400340045002D0036004100460045002D0034003900460032002D0038003600390030002D003300440041004600430041004500360046004600420038007D005C004100630063006500730073006F0072006900650073005C00530079007300740065006D00200054006F006F006C0073005C005400610073006B0020005300630068006500640075006C00650072002E006C006E006B0000006C006E006B0000003205EDE05F7793740800FEFFFFFFE72F6377822E6377B8F90876330200008600000043BA59720000000060ABD50220662100F8672100F8992D00987D210007000000A0D032055CD83205ECF83205EDE05F7793740800FEFFFFFFE72F6377822E6377B8F90876B5010000800000008FBA597202000000000000000000000068D13205399CF576C09A5003800200000000000039000000409D500333020000C09A500398D1320543190976F39C500348842A0086000000C09A500368952D0033020000B8F90876DF1E0000ABA43901B4D1320533AB6377ABD055CA000C00001027000013000000AD540200E8D13205F8AA6377AD540200ABA4390108D2320580D3DE0288D2320500000000A301000048D20000030B9F23F8D132058291097648D23205FCD1320527950976000000000CD8DE0224D23205CD9409760CD8DE02D0D2320580D3DE02E19409760000000080D3DE02D0D232052CD232050300000000000000030000007B00300031003300390044003400340045002D0036004100460045002D0034003900460032002D0038003600390030002D003300440041004600430041004500360046004600420038007D005C004100630063006500730073006F0072006900650073005C00530079007300740065006D00200054006F006F006C0073005C005400610073006B0020005300630068006500640075006C00650072002E006C006E006B0000006C006E006B0000003205EDE05F7793740800FEFFFFFFE72F6377822E6377B8F90876330200008600000043BA59720000000060ABD50220662100F8672100F8992D00987D210007000000A0D032055CD83205ECF83205EDE05F7793740800FEFFFFFFE72F6377822E6377B8F90876B5010000800000008FBA597202000000000000000000000068D13205399CF576C09A5003800200000000000039000000409D500333020000C09A500398D1320543190976F39C500348842A0086000000C09A500368952D0033020000B8F90876DF1E0000ABA43901B4D1320533AB6377ABD055CA000C00001027000013000000AD540200E8D13205F8AA6377AD540200ABA4390108D2320580D3DE0288D2320500000000A301000048D20000030B9F23F8D132058291097648D23205FCD1320527950976000000000CD8DE0224D23205CD9409760CD8DE02D0D2320580D3DE02E19409760000000080D3DE02D0D232052CD23205
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Zvpebfbsg.VagreargRkcybere.Qrsnhyg
000000000100000000000000FA0D0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF30DE0D301D0BD50100000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
0000000007000000030000000F2E010003000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E72402
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
00000000010000000100000088540000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF506AB1211D0BD50100000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
0000000007000000040000000F2E010003000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E72402
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
900
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\AppData\Local\Temp\Док-ты за прошлый месяц.rar
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface
ShowPassword
0
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General
LastFolder
C:\Users\admin\AppData\Local\Temp
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
name
120
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
size
80
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
psize
80
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
type
120
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
mtime
100
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
crc
70
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_0
38000000730100000402000000000000D4D0C800000000000000000000000000600103000000000039000000B40200000000000001000000
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_1
38000000730100000500000000000000D4D0C8000000000000000000000000001A01040000000000160000002A0000000000000002000000
900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_2
38000000730100000400000000000000D4D0C800000000000000000000000000800205000000000016000000640000000000000003000000
928
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
928
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
928
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
928
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
1
C:\Users\admin\AppData\Local\Temp\Док-ты за прошлый месяц.rar
928
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\Desktop\Док-ты за прошлый месяц.7z
928
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
928
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
928
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
928
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
928
WinRAR.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
928
WinRAR.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2908
Док-ты за прошлый месяц.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
wextract_cleanup0
rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\"
3280
rundll32.exe
write
HKEY_CURRENT_USER\Software\1e3b855a06aa
41ecc984c611c3e873
4991A37F
3280
rundll32.exe
write
HKEY_CURRENT_USER\Software\1e3b855a06aa
41ecc984c611c3e873
AB0835E32110F3659C387573308140FC6F775EFA712534FC877C6E4851B9B06A49DF5AD91851504824150937FE8D552E099A0CDEA8B765E782A41CF4C67ECC040CA436E9F17BD40722379162268B0A7AC91FE3AE228AC950DF6B9BE547155A2E61741C315EB00A259E43075B889C0448
2972
rundll32.exe
write
HKEY_CURRENT_USER\Software\1e3b855a06aa
41ecc984c611c3e873
CD66926A
2972
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
2972
rundll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
0F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE09000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C01400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB5748501D00000001000000100000005B3B67000EEB80022E42605B6B3B72400B000000010000000E000000740068006100770074006500000003000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B812000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
2972
rundll32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
2972
rundll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13
Blob
040000000100000010000000410352DC0FF7501B16F0028EBA6F45C50F00000001000000140000005BCAA1C2780F0BCB5A90770451D96F38963F012D090000000100000042000000304006082B0601050507030406082B0601050507030106082B0601050507030206082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C6200000001000000200000000687260331A72403D909F105E69BCF0D32E1BD2493FFC6D9206D11BCD67707390B000000010000001E000000440053005400200052006F006F0074002000430041002000580033000000140000000100000014000000C4A7B1A47B2C71FADBE14B9075FFC415608589101D00000001000000100000004558D512EECB27464920897DE7B66053030000000100000014000000DAC9024F54D8F6DF94935FB1732638CA6AD77C131900000001000000100000006CF252FEC3E8F20996DE5D4DD9AEF42420000000010000004E0300003082034A30820232A003020102021044AFB080D6A327BA893039862EF8406B300D06092A864886F70D0101050500303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F74204341205833301E170D3030303933303231313231395A170D3231303933303134303131355A303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F7420434120583330820122300D06092A864886F70D01010105000382010F003082010A0282010100DFAFE99750088357B4CC6265F69082ECC7D32C6B30CA5BECD9C37DC740C118148BE0E83376492AE33F214993AC4E0EAF3E48CB65EEFCD3210F65D22AD9328F8CE5F777B0127BB595C089A3A9BAED732E7A0C063283A27E8A1430CD11A0E12A38B9790A31FD50BD8065DFB7516383C8E28861EA4B6181EC526BB9A2E24B1A289F48A39E0CDA098E3E172E1EDD20DF5BC62A8AAB2EBD70ADC50B1A25907472C57B6AAB34D63089FFE568137B540BC8D6AEEC5A9C921E3D64B38CC6DFBFC94170EC1672D526EC38553943D0FCFD185C40F197EBD59A9B8D1DBADA25B9C6D8DFC115023AABDA6EF13E2EF55C089C3CD68369E4109B192AB62957E3E53D9B9FF0025D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414C4A7B1A47B2C71FADBE14B9075FFC41560858910300D06092A864886F70D01010505000382010100A31A2C9B17005CA91EEE2866373ABF83C73F4BC309A095205DE3D95944D23E0D3EBD8A4BA0741FCE10829C741A1D7E981ADDCB134BB32044E491E9CCFC7DA5DB6AE5FEE6FDE04EDDB7003AB57049AFF2E5EB02F1D1028B19CB943A5E48C4181E58195F1E025AF00CF1B1ADA9DC59868B6EE991F586CAFAB96633AA595BCEE2A7167347CB2BCC99B03748CFE3564BF5CF0F0C723287C6F044BB53726D43F526489A5267B758ABFE67767178DB0DA256141339243185A2A8025A3047E1DD5007BC02099000EB6463609B16BC88C912E6D27D918BF93D328D65B4E97CB15776EAC5B62839BF15651CC8F677966A0A8D770BD8910B048E07DB29B60AEE9D82353510
2972
rundll32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13
2972
rundll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
190000000100000010000000DC73F9B71E16D51D26527D32B11A6A3D09000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C01400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB5748501D00000001000000100000005B3B67000EEB80022E42605B6B3B72400B000000010000000E000000740068006100770074006500000003000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B812000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
2972
rundll32.exe
write
HKEY_CURRENT_USER\Software\1e3b855a06aa
82052e428d7349e9fe4582a7
79AE7E7A9442256BD5B27FA2C03D31626C745B15B29581843E65FA33947F3F7C4CA5887FE7F1739A287D4A4075217738C2B5E828AF0373347F6BCA0A2E
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000071000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{6DC406FD-7710-11E9-B63D-5254004A04AF}
0
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
1
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E307050003000F000C0035001A009A03
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
1
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E307050003000F000C0035001A009A03
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
1
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E307050003000F000C0035001B007D00
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
26
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
1
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E307050003000F000C0035001B00AC00
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
105
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
1
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E307050003000F000C0035001B000A01
2108
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
59

Files activity

Executable files
5
Suspicious files
2
Text files
8
Unknown types
7

Dropped files

PID
Process
Filename
Type
2036
explorer.exe
C:\Users\admin\Desktop\Док-ты за прошлый месяц.exe
executable
MD5: a25304fa060e5efa79c0534ec140ac50
SHA256: 17fbc0dcf4150704b64fde0dceb0d37b081e423fb7acecc0133264f05fb19213
3280
rundll32.exe
C:\ProgramData\2401bf603c90\2702bc633f93.dat
executable
MD5: 3bf77a39c55440b597123bd960cd24f7
SHA256: 196e6568fa9ccddae001c9a6c21fa19122042cc890c0cfbf11f3d6ca1414d9a0
2908
Док-ты за прошлый месяц.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\0024.dll
executable
MD5: 3bf77a39c55440b597123bd960cd24f7
SHA256: 196e6568fa9ccddae001c9a6c21fa19122042cc890c0cfbf11f3d6ca1414d9a0
928
WinRAR.exe
C:\Users\admin\AppData\Local\Temp\Rar$EXa928.28767\Док-ты за прошлый месяц.exe
executable
MD5: a25304fa060e5efa79c0534ec140ac50
SHA256: 17fbc0dcf4150704b64fde0dceb0d37b081e423fb7acecc0133264f05fb19213
928
WinRAR.exe
C:\Users\admin\AppData\Local\Temp\Rar$DRa928.30357\Док-ты за прошлый месяц.exe
executable
MD5: a25304fa060e5efa79c0534ec140ac50
SHA256: 17fbc0dcf4150704b64fde0dceb0d37b081e423fb7acecc0133264f05fb19213
2108
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Feeds Cache\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
2108
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DF408AB536AF659F03.TMP
––
MD5:  ––
SHA256:  ––
2108
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DF16B190FEACB26400.TMP
––
MD5:  ––
SHA256:  ––
2108
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{6DC406FF-7710-11E9-B63D-5254004A04AF}.dat
––
MD5:  ––
SHA256:  ––
588
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat
dat
MD5: 2013900af8df4b6a503e181c585d6ad1
SHA256: 49cf87134b2884cc1cf9ba261e3492c4b2ef44f05dd7b02b60db2128714cb719
588
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5DOM4O88\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
588
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OS1CYDMG\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
588
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0F7GUNM0\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
588
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YL2O8DN4\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
900
WinRAR.exe
C:\Users\admin\AppData\Local\Temp\Rar$DRb900.27295\Док-ты за прошлый месяц.7z
compressed
MD5: 1b4bd44ebb031a3f723a1180333f546a
SHA256: ee08c8f219003c169b4da5a8d7cd8bb1271556d5d929a98b1d74944b37602fad
588
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
588
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
2108
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DF393CB16CBE88E977.TMP
––
MD5:  ––
SHA256:  ––
588
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
dat
MD5: d7a950fefd60dbaa01df2d85fefb3862
SHA256: 75d0b1743f61b76a35b1fedd32378837805de58d79fa950cb6e8164bfa72073a
588
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
dat
MD5: d7a950fefd60dbaa01df2d85fefb3862
SHA256: 75d0b1743f61b76a35b1fedd32378837805de58d79fa950cb6e8164bfa72073a
588
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Low\JavaDeployReg.log
text
MD5: 9c314708b4297f136b3e643039a05f73
SHA256: 0d31889075efb3a683d2c9c2f9e0c9c3278650d91637d7673691f3138dc7c57e
2108
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{6DC406FE-7710-11E9-B63D-5254004A04AF}.dat
––
MD5:  ––
SHA256:  ––
2036
explorer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019051520190516\index.dat
dat
MD5: 20fd08508484a3681a6c6b00f9677e2b
SHA256: c719f495a9d2471d571eb49404c88aa4e198a485d7aa103b69478e8f4eaad8ec
2036
explorer.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\Док-ты за прошлый месяц.7z.lnk
lnk
MD5: d2fdc1e9376ba5b0f823a2c8ef6e5f22
SHA256: 9acee8b4bd511aba2686104779d9af5bcd1531bd17b21f277342b365edfcfb33
2036
explorer.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\290532160612e071.automaticDestinations-ms
automaticdestinations-ms
MD5: 6089c1f09a3e026ec369c705b9db3a0e
SHA256: ac8079b486891f47634938865d776f730381d7ce213827fc9c9823cc24d30516
2036
explorer.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms
automaticdestinations-ms
MD5: 7433b4abe34af28484a8f6e04b8cca23
SHA256: 1c062fc2ba7aca164f30ffc099de033805b0e4115fbfca40d6deaff40ddb738e
2036
explorer.exe
C:\Users\admin\Desktop\Док-ты за прошлый месяц.7z
compressed
MD5: 1b4bd44ebb031a3f723a1180333f546a
SHA256: ee08c8f219003c169b4da5a8d7cd8bb1271556d5d929a98b1d74944b37602fad
2108
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6DC406FD-7710-11E9-B63D-5254004A04AF}.dat
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
1
TCP/UDP connections
4
DNS requests
3
Threats
3

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2972 rundll32.exe POST 200 195.123.228.208:80 http://195.123.228.208/index.php BG
binary
binary
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2972 rundll32.exe 162.243.211.124:443 Digital Ocean, Inc. US unknown
2972 rundll32.exe 188.165.200.156:53 OVH SAS FR suspicious
2972 rundll32.exe 195.123.228.208:80 ITL Company BG malicious
2108 iexplore.exe 204.79.197.200:80 Microsoft Corporation US whitelisted

DNS requests

Domain IP Reputation
namecoin.cyphrs.com 162.243.211.124
unknown
www.bing.com 204.79.197.200
13.107.21.200
whitelisted

Threats

PID Process Class Message
2972 rundll32.exe Potentially Bad Traffic ET CURRENT_EVENTS DNS Query Domain .bit
2972 rundll32.exe A Network Trojan was detected MALWARE [PTsecurity] Win32/Spy.RTM.N (Redaman)

1 ETPRO signatures available at the full report

Debug output strings

No debug info.